CSL Cybersecurity Governance & Risk Management 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring the financial consequences of a risk to a third party?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts financial liability to a third party, typically through cyber insurance or outsourcing.
Question 2: A CISO discovers a critical vulnerability but patching it would require a 12-hour system outage. Which governance document typically guides the escalation decision?
- Acceptable Use Policy
- Risk Appetite Statement (Correct answer)
- Data Classification Policy
- Incident Response Plan
Correct answer: Risk Appetite Statement
A Risk Appetite Statement defines the organization's tolerance for risk and guides decisions when trade-offs between risk and operations arise.
Question 3: What is the primary purpose of a Board-level Cybersecurity Committee?
- Performing technical vulnerability assessments
- Providing executive oversight and accountability for cyber risk (Correct answer)
- Managing day-to-day security operations
- Developing firewall rules and access controls
Correct answer: Providing executive oversight and accountability for cyber risk
Board-level committees ensure that cybersecurity is governed with appropriate executive accountability and strategic oversight.
Question 4: In the context of risk management, what does 'residual risk' mean?
- The risk that remains after all controls are applied (Correct answer)
- The initial risk before any controls are implemented
- The risk transferred to a third party
- The risk eliminated through avoidance
Correct answer: The risk that remains after all controls are applied
Residual risk is the remaining exposure after all mitigation controls have been applied to the inherent risk.
Question 5: Which framework specifically focuses on IT governance and aligns IT goals with business objectives?
- ISO 27001
- COBIT (Correct answer)
- NIST CSF
- PCI DSS
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is designed to align IT governance with enterprise business goals.
Question 6: A company operates in both the EU and US. Which governance challenge does this most directly create?
- Increased hardware procurement costs
- Conflicting regulatory compliance requirements across jurisdictions (Correct answer)
- Reduced employee productivity
- Higher software licensing fees
Correct answer: Conflicting regulatory compliance requirements across jurisdictions
Operating across jurisdictions creates compliance complexity because regulations like GDPR and CCPA may have conflicting or overlapping requirements.
Question 7: What is the role of a Data Protection Officer (DPO) under GDPR?
- To perform penetration testing on systems
- To oversee compliance with data protection regulations and act as liaison with regulators (Correct answer)
- To manage the organization's firewall infrastructure
- To approve all third-party vendor contracts
Correct answer: To oversee compliance with data protection regulations and act as liaison with regulators
Under GDPR, the DPO ensures the organization processes personal data lawfully and serves as the primary contact point with data protection authorities.
Which risk treatment option involves transferring the financial consequences of a risk to a third party?