CORES Technology & Cyber Risk Management 4 — Questions and Answers
Question 1: Under the NIST Cybersecurity Framework (CSF), which function focuses on developing organizational understanding to manage cybersecurity risk?
- Protect
- Identify (Correct answer)
- Detect
- Respond
Correct answer: Identify
The Identify function encompasses asset management, business environment, governance, risk assessment, and risk management strategy to establish foundational cyber risk understanding.
Question 2: A firm's CISO reports that 40% of employees clicked a simulated phishing link. From an operational risk perspective, what control improvement is MOST directly indicated?
- Implement multi-factor authentication on all external-facing systems
- Enhance security awareness training with more frequent and targeted phishing simulations (Correct answer)
- Deploy a next-generation firewall to filter malicious email attachments
- Engage a red team to conduct a full adversarial simulation
Correct answer: Enhance security awareness training with more frequent and targeted phishing simulations
A high phishing click rate indicates a human control gap; targeted security awareness training and repeated phishing simulations directly address this behavioral risk.
Question 3: Which of the following BEST describes 'cyber resilience' as distinct from 'cybersecurity'?
- Cyber resilience focuses solely on preventing breaches; cybersecurity focuses on recovery
- Cyber resilience encompasses the ability to anticipate, withstand, recover from, and adapt to cyber incidents (Correct answer)
- Cybersecurity is a broader term that includes all elements of cyber resilience
- Cyber resilience applies only to critical infrastructure sectors as defined by CISA
Correct answer: Cyber resilience encompasses the ability to anticipate, withstand, recover from, and adapt to cyber incidents
Cyber resilience extends beyond prevention to include operational continuity and adaptive capacity during and after cyber events, whereas cybersecurity primarily addresses protection.
Question 4: When classifying a data breach under operational risk loss event categories (Basel II/III), which category would typically apply?
- External Fraud (Correct answer)
- Clients, Products & Business Practices
- Execution, Delivery & Process Management
- Internal Fraud
Correct answer: External Fraud
Under Basel II/III taxonomy, cyber attacks by external actors resulting in unauthorized data access are classified under External Fraud.
Question 5: What is the purpose of a Software Bill of Materials (SBOM) in technology risk management?
- To document the total cost of software licenses in an IT environment
- To provide a detailed inventory of software components, enabling rapid identification of vulnerable dependencies (Correct answer)
- To track software development project milestones and deliverables
- To define approved software configurations for regulatory compliance
Correct answer: To provide a detailed inventory of software components, enabling rapid identification of vulnerable dependencies
An SBOM catalogs all components and dependencies in software, allowing organizations to quickly identify which systems are affected when a vulnerability is discovered in a component.
Question 6: A firm experiences a DDoS attack rendering its customer-facing portal unavailable for 6 hours. Which operational risk impact dimension is MOST directly affected?
- Legal and compliance fines
- Availability and service continuity (Correct answer)
- Confidentiality of customer data
- Integrity of transaction records
Correct answer: Availability and service continuity
A DDoS attack targets availability; the primary operational impact is the inability of customers and staff to access systems and services.
Question 7: In technology risk management, what does 'defense in depth' refer to?
- Using a single highly sophisticated security control to protect the most critical asset
- Implementing multiple layered security controls so that failure of one does not compromise the entire system (Correct answer)
- Conducting deep-dive penetration testing on all external systems annually
- Deploying advanced threat intelligence to pre-empt attacks before they occur
Correct answer: Implementing multiple layered security controls so that failure of one does not compromise the entire system
Defense in depth applies multiple overlapping security layers (network, endpoint, application, data) so that an attacker must defeat several independent controls to succeed.
Under the NIST Cybersecurity Framework (CSF), which function focuses on developing organizational understanding to manage cybersecurity risk?