CySA+ Test Risk Assessment 3 — Questions and Answers
Question 1: A CySA+ analyst is using the FAIR (Factor Analysis of Information Risk) model. What does FAIR primarily focus on?
- Categorizing assets by sensitivity level
- Quantifying risk in financial terms using probability and magnitude (Correct answer)
- Creating a heat map of threat actors
- Defining qualitative risk tiers for compliance
Correct answer: Quantifying risk in financial terms using probability and magnitude
FAIR is a quantitative framework that models risk as a function of probable frequency and probable magnitude of loss events.
Question 2: During threat modeling, which technique involves working backward from a defined adverse outcome to identify contributing causes?
- Attack tree analysis
- Fault tree analysis (Correct answer)
- STRIDE modeling
- PASTA methodology
Correct answer: Fault tree analysis
Fault tree analysis starts with an undesired top-level event and traces backward through logical branches to identify root causes and contributing failures.
Question 3: An analyst discovers that a critical web application has a vulnerability with a CVSS base score of 9.1. Which factor would LOWER the environmental score for this system?
- The system stores PHI data
- The system is not internet-facing and sits behind multiple firewalls (Correct answer)
- The exploit code is publicly available
- The vulnerability requires no user interaction
Correct answer: The system is not internet-facing and sits behind multiple firewalls
Environmental scores account for existing mitigating controls; being isolated behind firewalls reduces the exploitability in the specific environment.
Question 4: Which risk concept describes the probability that a given threat will exploit a specific vulnerability within a defined time period?
- Exposure factor
- Threat likelihood (Correct answer)
- Asset value
- Control gap
Correct answer: Threat likelihood
Threat likelihood (also called probability) is the estimated chance that a threat event will occur and successfully exploit a vulnerability in a given timeframe.
Question 5: A security team is assessing supply chain risk. Which control BEST reduces third-party vendor risk?
- Requiring vendors to self-attest compliance annually
- Conducting periodic third-party security assessments and audits (Correct answer)
- Blocking all vendor remote access
- Moving all vendor contracts to fixed-price agreements
Correct answer: Conducting periodic third-party security assessments and audits
Periodic independent assessments and audits provide objective evidence of a vendor's security posture beyond self-attestation.
Question 6: In a risk assessment, the Exposure Factor (EF) is defined as:
- The total cost of recovering from an incident
- The percentage of an asset's value lost in a single threat event (Correct answer)
- The annualized frequency of a threat occurring
- The number of vulnerabilities per asset
Correct answer: The percentage of an asset's value lost in a single threat event
Exposure Factor is the percentage of an asset's value that would be lost if a specific threat successfully exploits a vulnerability.
Question 7: A risk analyst identifies that purchasing cyber liability insurance best addresses which risk treatment approach?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Cyber liability insurance transfers the financial consequences of a risk event to the insurance provider.
A CySA+ analyst is using the FAIR (Factor Analysis of Information Risk) model.
What does FAIR primarily focus on?