CORES Technology & Cyber Risk Management 5 — Questions and Answers
Question 1: Which governance structure element is MOST important for ensuring effective cyber risk oversight at the board level?
- Requiring the CISO to hold a CISSP certification
- Establishing a board-level committee with defined cyber risk responsibilities and regular reporting cadence (Correct answer)
- Mandating that all board members complete annual cybersecurity training
- Ensuring the IT department reports directly to the board chair
Correct answer: Establishing a board-level committee with defined cyber risk responsibilities and regular reporting cadence
A dedicated board committee with clear mandates and regular cyber risk reporting ensures strategic-level oversight and accountability for technology risk.
Question 2: A firm's key risk indicator (KRI) for cyber risk shows the number of unpatched critical vulnerabilities trending upward for three consecutive months. What is the MOST appropriate escalation action?
- Adjust the KRI threshold upward to account for the trend
- Escalate to senior management and initiate an emergency patching program with defined remediation timelines (Correct answer)
- Document the trend in the risk register and review at the next quarterly meeting
- Terminate the contracts of IT staff responsible for patch management
Correct answer: Escalate to senior management and initiate an emergency patching program with defined remediation timelines
A sustained upward trend in a critical KRI signals deteriorating control effectiveness and requires immediate escalation and a time-bound remediation response.
Question 3: Under ISO/IEC 27005, the risk treatment option of 'risk avoidance' in a cyber context would BEST be illustrated by:
- Purchasing cyber liability insurance to transfer financial exposure
- Discontinuing a high-risk digital service that cannot be adequately secured (Correct answer)
- Implementing additional technical controls to reduce vulnerability exploitation
- Accepting residual risk after controls are applied as within risk appetite
Correct answer: Discontinuing a high-risk digital service that cannot be adequately secured
Risk avoidance means eliminating the risk by ceasing the activity that generates it; discontinuing an insecurable service removes the exposure entirely.
Question 4: What distinguishes an Advanced Persistent Threat (APT) from a typical opportunistic cyberattack?
- APTs exclusively target government systems; opportunistic attacks target private firms
- APTs involve prolonged, targeted intrusions by sophisticated actors seeking specific objectives over time (Correct answer)
- APTs always use zero-day exploits; opportunistic attacks use only known vulnerabilities
- APTs are conducted solely by nation-state actors with state-sponsored funding
Correct answer: APTs involve prolonged, targeted intrusions by sophisticated actors seeking specific objectives over time
APTs are characterized by their long dwell time, targeted nature, and persistence — attackers maintain covert access to achieve specific espionage or sabotage objectives.
Question 5: Which of the following is the PRIMARY objective of a cyber risk quantification program in an enterprise operational risk framework?
- To comply with SEC cybersecurity disclosure requirements
- To translate cyber risks into financial terms that enable risk-informed investment and prioritization decisions (Correct answer)
- To replace qualitative risk assessments with automated scanning tools
- To demonstrate to regulators that the firm has a mature cybersecurity posture
Correct answer: To translate cyber risks into financial terms that enable risk-informed investment and prioritization decisions
Cyber risk quantification converts technical risks into financial metrics, enabling executives and boards to make cost-benefit decisions on security investments and risk tolerance.
Question 6: A firm is assessing the cyber risk of a newly acquired subsidiary. Which approach BEST reflects sound operational risk management practice?
- Assume the subsidiary's controls match the parent's standards and proceed with integration
- Conduct a pre-integration cyber risk assessment to identify gaps before system integration (Correct answer)
- Require the subsidiary to achieve ISO 27001 certification within 30 days of acquisition
- Immediately migrate all subsidiary systems to the parent's cloud environment to apply enterprise controls
Correct answer: Conduct a pre-integration cyber risk assessment to identify gaps before system integration
A pre-integration assessment identifies inherited vulnerabilities and control gaps before connecting systems, preventing the parent from absorbing unknown cyber risks.
Question 7: In the context of operational risk and technology, what is 'shadow IT' and why does it present a risk management challenge?
- Backup IT systems maintained in a secondary data center outside corporate governance
- Technology assets and applications used by employees without formal IT approval or oversight (Correct answer)
- Cybersecurity monitoring tools that operate passively without generating alerts
- Legacy systems that are undocumented due to staff turnover and knowledge loss
Correct answer: Technology assets and applications used by employees without formal IT approval or oversight
Shadow IT refers to unauthorized technology use outside of IT governance, creating unmanaged vulnerabilities, data exposure, and compliance gaps that risk teams cannot see or control.
Which governance structure element is MOST important for ensuring effective cyber risk oversight at the board level?