CSC Security Risk Management 2 โ Questions and Answers
Question 1: Which risk treatment option involves sharing the financial impact of a risk with a third party, such as through insurance?
- Risk avoidance
- Risk transference (Correct answer)
- Risk acceptance
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, commonly through insurance or outsourcing contracts.
Question 2: A security consultant is performing a qualitative risk assessment. Which characteristic best describes this approach?
- Uses exact monetary values for asset losses
- Relies on subjective ratings such as High, Medium, and Low (Correct answer)
- Requires statistical historical loss data
- Calculates Annual Loss Expectancy in dollars
Correct answer: Relies on subjective ratings such as High, Medium, and Low
Qualitative risk assessments use descriptive scales and expert judgment rather than precise numerical monetary values.
Question 3: What does the term 'residual risk' refer to in security risk management?
- The risk eliminated by applying controls
- The risk that remains after controls have been implemented (Correct answer)
- The total risk before any mitigation
- The risk transferred to an insurer
Correct answer: The risk that remains after controls have been implemented
Residual risk is the remaining exposure after security controls have been applied to reduce the initial inherent risk.
Question 4: In a Business Impact Analysis (BIA), what is the PRIMARY purpose of identifying the Maximum Tolerable Downtime (MTD)?
- To calculate the cost of deploying backup systems
- To determine how long a process can be disrupted before causing unacceptable harm (Correct answer)
- To establish the Recovery Time Objective for all systems equally
- To rank cybersecurity threats by likelihood
Correct answer: To determine how long a process can be disrupted before causing unacceptable harm
MTD defines the longest period an organization can survive without a critical function before suffering irreversible damage, guiding recovery planning.
Question 5: Which formula correctly represents the calculation of Single Loss Expectancy (SLE)?
- SLE = Asset Value ร Annualized Rate of Occurrence
- SLE = Asset Value ร Exposure Factor (Correct answer)
- SLE = Annual Loss Expectancy รท Exposure Factor
- SLE = Threat Likelihood ร Vulnerability Severity
Correct answer: SLE = Asset Value ร Exposure Factor
SLE is calculated by multiplying the asset value by the exposure factor, which represents the percentage of the asset lost in a single incident.
Question 6: A security consultant recommends implementing defense-in-depth. Which risk management principle does this strategy BEST support?
- Risk avoidance by eliminating all attack surfaces
- Risk reduction by layering multiple compensating controls (Correct answer)
- Risk transference by distributing security responsibilities
- Risk acceptance because no single control is perfect
Correct answer: Risk reduction by layering multiple compensating controls
Defense-in-depth applies multiple overlapping security layers so that if one control fails, others continue to reduce risk.
Question 7: During a risk assessment, a consultant identifies a vulnerability with no known threat currently targeting it. What is the MOST appropriate action?
- Immediately remediate the vulnerability at any cost
- Document it, monitor for emerging threats, and prioritize based on potential impact (Correct answer)
- Ignore it since no active threat exists
- Transfer the risk to a managed security service provider
Correct answer: Document it, monitor for emerging threats, and prioritize based on potential impact
Even without an active threat, documenting and monitoring a vulnerability ensures it is addressed before it can be exploited if the threat landscape changes.
Which risk treatment option involves sharing the financial impact of a risk with a third party, such as through insurance?