CSC Security Risk Management 3 — Questions and Answers
Question 1: Which of the following BEST describes the concept of 'inherent risk'?
- The risk level after all controls are applied
- The risk level that exists before any controls are implemented (Correct answer)
- The risk accepted by senior management
- The risk introduced by third-party vendors
Correct answer: The risk level that exists before any controls are implemented
Inherent risk is the raw, unmitigated level of risk present in an environment before any security controls are in place.
Question 2: A CSC is asked to evaluate which assets require the most protection. Which criterion should carry the GREATEST weight in this determination?
- The physical size of the asset
- The criticality and value of the asset to organizational operations (Correct answer)
- The age of the hardware hosting the asset
- The number of users who access the asset daily
Correct answer: The criticality and value of the asset to organizational operations
Asset criticality and business value are the primary drivers for prioritizing protection efforts in a risk-based security program.
Question 3: What is the primary goal of a threat modeling exercise in the context of security risk management?
- To enumerate all software bugs in a system
- To identify potential threats, attack vectors, and prioritize mitigations early in design (Correct answer)
- To calculate the annual cost of security incidents
- To document regulatory compliance requirements
Correct answer: To identify potential threats, attack vectors, and prioritize mitigations early in design
Threat modeling systematically identifies threats and vulnerabilities during the design phase so that mitigations can be built in proactively.
Question 4: Which risk assessment framework is commonly used by US federal agencies and contractors and is published by NIST?
- ISO/IEC 27005
- OCTAVE
- RMF (SP 800-37) (Correct answer)
- FAIR (Factor Analysis of Information Risk)
Correct answer: RMF (SP 800-37)
NIST SP 800-37 defines the Risk Management Framework (RMF), which is mandatory for US federal information systems.
Question 5: A security consultant discovers that two different business units use the same critical server but neither owns accountability for its security. This BEST illustrates which risk management problem?
- Scope creep in risk assessments
- Lack of asset ownership leading to security governance gaps (Correct answer)
- Over-classification of information assets
- Excessive risk transference
Correct answer: Lack of asset ownership leading to security governance gaps
Without clearly assigned ownership, no one is accountable for protecting the asset, creating a governance gap that elevates risk.
Question 6: In quantitative risk analysis, what does an Annualized Rate of Occurrence (ARO) of 0.25 indicate?
- The threat is expected to occur four times per year
- The threat is expected to occur once every four years (Correct answer)
- The threat has a 25% severity rating
- The threat causes 25% asset loss per incident
Correct answer: The threat is expected to occur once every four years
An ARO of 0.25 means the threat event is expected to occur 0.25 times per year, or approximately once every four years.
Question 7: Which element distinguishes a risk register from a vulnerability assessment report?
- A risk register lists only technical vulnerabilities found by scanners
- A risk register tracks identified risks, their ratings, owners, and treatment status over time (Correct answer)
- A risk register is used exclusively during incident response
- A risk register is produced only by external auditors
Correct answer: A risk register tracks identified risks, their ratings, owners, and treatment status over time
A risk register is a living management document that records risks, their likelihood and impact ratings, responsible owners, and the status of treatment actions.
Which of the following BEST describes the concept of 'inherent risk'?