CSC Governance, Risk Management & Policy Development 3 — Questions and Answers
Question 1: An organization is evaluating risks using a qualitative approach. Which method are they MOST likely using?
- Calculating Annual Loss Expectancy (ALE) in dollar amounts
- Assigning numeric probability and impact values in a formula
- Rating risks as High, Medium, or Low based on judgment (Correct answer)
- Using Monte Carlo simulations to model risk probability distributions
Correct answer: Rating risks as High, Medium, or Low based on judgment
Qualitative risk analysis uses descriptive ratings like High, Medium, or Low rather than precise numerical calculations.
Question 2: Which governance framework provides guidance specifically designed for IT governance and aligns IT goals with business objectives?
- ISO 27001
- COBIT (Correct answer)
- PCI DSS
- HIPAA
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is an IT governance framework that aligns IT with business goals.
Question 3: A newly hired CISO wants to develop a cybersecurity strategy aligned with business goals. What should be the FIRST step?
- Purchase and deploy new security tools
- Conduct a business impact analysis tied to security risks (Correct answer)
- Draft a new acceptable use policy
- Hire additional security staff
Correct answer: Conduct a business impact analysis tied to security risks
Understanding business impacts of security risks ensures that the cybersecurity strategy directly supports organizational objectives.
Question 4: What does the term 'residual risk' refer to?
- The risk that exists before any controls are applied
- The risk that remains after controls have been implemented (Correct answer)
- The risk transferred to a third party via insurance
- The risk identified but not yet assessed
Correct answer: The risk that remains after controls have been implemented
Residual risk is the level of risk that persists after security controls and mitigations have been applied.
Question 5: Which role is TYPICALLY responsible for approving an organization's information security policies?
- Security analyst
- System administrator
- Senior management or executive leadership (Correct answer)
- External auditor
Correct answer: Senior management or executive leadership
Information security policies require approval from senior management or executives to carry organizational authority and accountability.
Question 6: An organization wants to measure the effectiveness of its security controls on an ongoing basis. Which governance activity supports this?
- One-time penetration testing
- Continuous monitoring (Correct answer)
- Annual policy review
- Third-party vendor assessment
Correct answer: Continuous monitoring
Continuous monitoring provides ongoing visibility into control effectiveness and security posture rather than point-in-time snapshots.
Question 7: Which of the following BEST describes the relationship between a threat, a vulnerability, and a risk?
- Risk is the probability a threat exists; vulnerability is the impact
- A threat exploits a vulnerability to create risk (Correct answer)
- Vulnerability and threat are the same concept measured differently
- Risk equals the sum of all threats regardless of vulnerabilities
Correct answer: A threat exploits a vulnerability to create risk
Risk arises when a threat agent is capable of exploiting a vulnerability, potentially causing harm to an asset.
An organization is evaluating risks using a qualitative approach.
Which method are they MOST likely using?