CSPM CSPM Risk Management & Compliance 2 — Questions and Answers
Question 1: A qualitative risk assessment differs from a quantitative risk assessment primarily because it:
- Uses numerical dollar values for all risks
- Relies on descriptive ratings such as High, Medium, and Low (Correct answer)
- Requires actuarial data and historical loss records
- Is mandated by PCI-DSS v4.0
Correct answer: Relies on descriptive ratings such as High, Medium, and Low
Qualitative risk assessments categorize risk using subjective descriptors rather than precise monetary figures, making them faster but less precise than quantitative methods.
Question 2: Under SOX Section 404, which of the following is a key security project management responsibility?
- Encrypting all customer credit card data
- Documenting and testing internal controls over financial reporting (Correct answer)
- Conducting annual penetration tests on web applications
- Maintaining HIPAA-compliant audit logs
Correct answer: Documenting and testing internal controls over financial reporting
SOX Section 404 requires management and external auditors to assess and report on the effectiveness of internal controls over financial reporting, including IT general controls.
Question 3: What is the primary purpose of a Statement of Applicability (SoA) in an ISO 27001 compliance project?
- To list all identified vulnerabilities in the environment
- To document which Annex A controls are applicable and whether they are implemented (Correct answer)
- To record penetration testing findings for auditors
- To define the project charter and scope boundaries
Correct answer: To document which Annex A controls are applicable and whether they are implemented
The SoA is an ISO 27001 requirement that maps each Annex A control to the organization, stating applicability, implementation status, and justification for exclusions.
Question 4: Which risk metric represents the maximum tolerable downtime for a system before business operations are critically impaired?
- Recovery Point Objective (RPO)
- Mean Time to Repair (MTTR)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable length of time a system can be offline following a disruption before causing unacceptable business impact.
Question 5: A CSPM professional is reviewing a third-party vendor's security posture. This activity is best categorized as:
- Internal risk audit
- Supply chain risk management (Correct answer)
- Threat modeling
- Business impact analysis
Correct answer: Supply chain risk management
Evaluating vendor security controls is a core supply chain risk management activity, ensuring third-party relationships do not introduce unacceptable risk to the organization.
Question 6: In the US, which sector-specific regulation requires annual independent security assessments for payment card processing environments?
- FISMA
- PCI-DSS (Correct answer)
- GLBA
- SOX
Correct answer: PCI-DSS
PCI-DSS (Payment Card Industry Data Security Standard) requires organizations processing cardholder data to undergo annual assessments by a Qualified Security Assessor (QSA) or complete a self-assessment questionnaire.
A qualitative risk assessment differs from a quantitative risk assessment primarily because it: