CSPM CSPM Risk Management & Compliance 1 — Questions and Answers
Question 1: In the CSPM framework, which risk management step involves identifying potential threats and their likelihood of occurrence?
- Risk acceptance
- Risk identification (Correct answer)
- Risk transfer
- Risk avoidance
Correct answer: Risk identification
Risk identification is the foundational step where potential threats, vulnerabilities, and their likelihood are catalogued before any response strategy is chosen.
Question 2: A security project manager is calculating the Annual Loss Expectancy (ALE) for a threat. Which formula is correct?
- ALE = ARO + SLE
- ALE = SLE × ARO (Correct answer)
- ALE = SLE / ARO
- ALE = ARO - SLE
Correct answer: ALE = SLE × ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), expressing the expected yearly financial loss from a specific threat.
Question 3: Which US federal regulation requires organizations handling electronic protected health information (ePHI) to conduct regular risk analyses?
- GLBA
- SOX
- HIPAA Security Rule (Correct answer)
- FERPA
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates covered entities and business associates to perform regular risk analyses to identify threats to ePHI confidentiality, integrity, and availability.
Question 4: What type of risk response strategy involves purchasing cyber insurance to offset potential financial losses?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to a third party, such as an insurer, rather than eliminating or reducing the underlying threat.
Question 5: In a CSPM context, a residual risk is best described as:
- The total risk before any controls are applied
- The risk remaining after security controls have been implemented (Correct answer)
- The risk transferred to a third-party vendor
- The risk accepted by executive leadership
Correct answer: The risk remaining after security controls have been implemented
Residual risk is the level of risk that persists after all planned security controls and mitigations have been put into place.
Question 6: Which compliance framework is most directly applicable to US federal government information systems security management?
- PCI-DSS
- ISO 27001
- NIST RMF (Correct answer)
- CIS Controls
Correct answer: NIST RMF
The NIST Risk Management Framework (RMF) is the mandated standard for US federal agencies to categorize, select, implement, assess, authorize, and monitor security controls.
In the CSPM framework, which risk management step involves identifying potential threats and their likelihood of occurrence?