CySA+ Test Risk Assessment 2 — Questions and Answers
Question 1: A security analyst is performing a risk assessment and needs to calculate the Annualized Loss Expectancy (ALE). Which formula is correct?
- ALE = SLE × ARO (Correct answer)
- ALE = SLE + ARO
- ALE = AV × EF × ARO
- ALE = SLE / ARO
Correct answer: ALE = SLE × ARO
ALE equals Single Loss Expectancy (SLE) multiplied by the Annualized Rate of Occurrence (ARO).
Question 2: During a risk assessment, a finding is classified as high likelihood but low impact. Which risk response is MOST appropriate?
- Accept the risk and document it
- Transfer the risk to a third party
- Implement low-cost mitigating controls (Correct answer)
- Immediately remediate with maximum resources
Correct answer: Implement low-cost mitigating controls
High-likelihood, low-impact risks are best addressed with proportionate, low-cost controls rather than expensive remediation or full acceptance.
Question 3: Which risk assessment methodology uses likelihood and impact ratings to produce a risk score matrix?
- OCTAVE
- FAIR
- Qualitative risk assessment (Correct answer)
- Monte Carlo simulation
Correct answer: Qualitative risk assessment
Qualitative risk assessment assigns descriptive ratings (e.g., High/Medium/Low) for likelihood and impact, plotted on a risk matrix.
Question 4: A company wants to quantify risk in financial terms to justify security spending to executives. Which approach is BEST suited?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Delphi technique
- Bow-tie analysis
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical monetary values to assets, losses, and probabilities, making it easier to justify budget to executives.
Question 5: What does the term 'residual risk' refer to in a risk management context?
- Risk that has been fully eliminated
- Risk remaining after controls have been applied (Correct answer)
- Risk transferred to an insurance provider
- Risk identified but not yet assessed
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after security controls and mitigations have been implemented.
Question 6: An organization accepts a risk without implementing additional controls. Which risk treatment strategy does this represent?
- Risk avoidance
- Risk mitigation
- Risk transference
- Risk acceptance (Correct answer)
Correct answer: Risk acceptance
Risk acceptance means acknowledging a risk and deliberately choosing not to implement additional controls, often when the cost of control exceeds the potential loss.
Question 7: Which document formally records identified risks, their likelihood, impact, owner, and current treatment status?
- Business Impact Analysis
- Risk register (Correct answer)
- System Security Plan
- Vulnerability scan report
Correct answer: Risk register
A risk register is the central document that tracks all identified risks along with their attributes, owners, and treatment plans.
A security analyst is performing a risk assessment and needs to calculate the Annualized Loss Expectancy (ALE).
Which formula is correct?