CRM Risk Management & Security 2 — Questions and Answers
Question 1: Which type of risk assessment methodology assigns numeric values to the likelihood and impact of threats to calculate an overall risk score?
- Qualitative assessment
- Quantitative assessment (Correct answer)
- Hybrid assessment
- Delphi assessment
Correct answer: Quantitative assessment
Quantitative risk assessment uses numeric values and formulas (such as ALE = ARO × SLE) to produce measurable risk scores.
Question 2: A records manager discovers that classified contracts are stored in an unlocked filing cabinet in a shared workspace. This situation primarily represents which category of risk?
- Operational risk (Correct answer)
- Strategic risk
- Reputational risk
- Compliance risk
Correct answer: Operational risk
Operational risk arises from failures in internal processes, people, or physical controls, such as inadequate physical security for records.
Question 3: Under NIST SP 800-60, what is the primary purpose of information type categorization?
- To assign retention schedules to records
- To determine the appropriate security category for federal information systems (Correct answer)
- To classify records by medium (paper vs. digital)
- To identify the originating agency of each record
Correct answer: To determine the appropriate security category for federal information systems
NIST SP 800-60 maps information types to security categories (confidentiality, integrity, availability) to guide federal information system security.
Question 4: Which control is specifically designed to limit the number of employees who can access highly sensitive personnel records?
- Separation of duties
- Need-to-know access (Correct answer)
- Mandatory vacation
- Job rotation
Correct answer: Need-to-know access
Need-to-know access restricts record access to only those individuals whose job functions require it, reducing unauthorized disclosure risk.
Question 5: A records security plan should address which of the following to protect records during a declared disaster?
- Marketing strategy for the organization
- Vital records protection and off-site storage (Correct answer)
- Employee performance appraisal criteria
- Budget forecasting for IT upgrades
Correct answer: Vital records protection and off-site storage
Vital records protection, including duplication and off-site storage, ensures critical records survive disasters and support business continuity.
Question 6: What is the recommended first step when an organization suspects a records-related data breach?
- Immediately notify the public via press release
- Contain the breach and assess the scope before further action (Correct answer)
- Delete all affected records to prevent further exposure
- Submit a regulatory filing within 24 hours
Correct answer: Contain the breach and assess the scope before further action
Incident response best practice requires containment and assessment of the breach scope before notifications or other remedial actions.
Question 7: Which document formally authorizes an organization's information security program and assigns high-level accountability to senior management?
- Security awareness training syllabus
- Information security policy (Correct answer)
- System security plan (SSP)
- Acceptable use agreement
Correct answer: Information security policy
An information security policy is a high-level management directive that establishes the program, assigns responsibility, and sets the tone for compliance.
Which type of risk assessment methodology assigns numeric values to the likelihood and impact of threats to calculate an overall risk score?