SC-100 Security Strategy & Risk Management — Questions and Answers
Question 1: What is the primary purpose of a cybersecurity strategy?
- To eliminate the need for IT personnel.
- To comply with every regulation.
- To improve physical security.
- To define a comprehensive defense and risk posture (Correct answer)
Correct answer: To define a comprehensive defense and risk posture
A cybersecurity strategy outlines an organization's overall approach to managing cyber risks and protecting its assets. It defines the goals, principles, and roadmap for security investments and operations, ensuring a coordinated and effective defense posture aligned with business objectives and risk tolerance.
Question 2: Which framework is commonly used for managing cybersecurity risk?
- CMMI
- NIST Cybersecurity Framework (Correct answer)
- Agile
- ITIL
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is a widely recognized and adopted framework that provides a common language and systematic approach for organizations to manage and reduce cybersecurity risk. It helps organizations understand, prioritize, and communicate cybersecurity activities, aligning them with business objectives. Other options like CMMI, Agile, and ITIL are not primarily focused on cybersecurity risk management.
Question 3: What is risk appetite in cybersecurity?
- The tendency to avoid all risks.
- The legal penalties for noncompliance.
- The amount of risk an organization is willing to tolerate (Correct answer)
- The list of known vulnerabilities.
Correct answer: The amount of risk an organization is willing to tolerate
Risk appetite defines the level of risk an organization is willing to accept or tolerate in pursuit of its strategic objectives. In cybersecurity, it's a crucial concept that guides decisions on security investments, control implementation, and incident response. Understanding an organization's risk appetite helps align cybersecurity measures with its overall business tolerance for potential cyber incidents.
Question 4: Why is threat modeling important in cybersecurity strategy?
- To purchase more software licenses.
- To meet annual training requirements.
- To reduce the number of employees.
- To proactively identify vulnerabilities and threats (Correct answer)
Correct answer: To proactively identify vulnerabilities and threats
Threat modeling is a structured process used to identify potential threats and vulnerabilities in systems, applications, or processes early in their design or development lifecycle. By proactively analyzing how an attacker might compromise a system, organizations can implement appropriate security controls before deployment. This helps reduce the attack surface and strengthen the overall security posture.
Question 5: What role does executive leadership play in cybersecurity?
- They perform network scans.
- They write all security policies.
- They are responsible for patch management.
- They support cybersecurity priorities and investments (Correct answer)
Correct answer: They support cybersecurity priorities and investments
Executive leadership plays a critical role in cybersecurity by setting the strategic direction, allocating necessary resources, and fostering a security-aware culture throughout the organization. Their support ensures that cybersecurity initiatives receive adequate funding and organizational backing. This top-down commitment is essential for the successful implementation and maintenance of a robust cybersecurity program.
Question 6: What is the benefit of aligning cybersecurity strategy with business goals?
- It reduces marketing costs.
- It guarantees zero cyber incidents.
- It ensures legal immunity.
- It supports mission-critical functions and reduces risk (Correct answer)
Correct answer: It supports mission-critical functions and reduces risk
Aligning cybersecurity strategy with business goals ensures that security efforts protect the assets and processes most vital to an organization's success and mission-critical functions. This strategic alignment helps prioritize security investments where they will have the greatest impact on business continuity and risk reduction. It transforms cybersecurity from a mere cost center into a strategic enabler for organizational objectives.
Question 7: What does a risk register include?
- A list of fired employees.
- A database of customer emails.
- A record of identified risks and actions (Correct answer)
- The company's profit margin.
Correct answer: A record of identified risks and actions
A risk register is a central document used in risk management to record and track all identified risks within an organization. For each risk, it typically includes details such as its description, potential impact, likelihood, assigned owner, and the planned or taken mitigation actions. This tool is essential for monitoring and managing an organization's overall risk posture effectively.
Question 8: What is a key outcome of a cybersecurity risk assessment?
- Creating more spreadsheets.
- Reducing physical office space.
- Understanding and mitigating security risks (Correct answer)
- Hiring more developers.
Correct answer: Understanding and mitigating security risks
A cybersecurity risk assessment systematically identifies, analyzes, and evaluates potential security risks to an organization's information systems and data. The key outcome is a clear understanding of the threats, vulnerabilities, and potential impacts, which then informs decisions on how to prioritize and implement effective mitigation strategies. This process helps organizations make informed decisions about security investments and resource allocation.
Question 9: How often should a cybersecurity strategy be reviewed?
- Once every 10 years.
- Only after a breach.
- Every quarter or after major changes (Correct answer)
- Never, if it was done right the first time.
Correct answer: Every quarter or after major changes
Cybersecurity strategies should be reviewed regularly, typically quarterly or whenever significant changes occur in the business environment, technology landscape, or threat profile. This ensures the strategy remains relevant, effective, and aligned with evolving risks and organizational objectives. Regular reviews allow for adaptation and continuous improvement of the security posture.
What is the primary purpose of a cybersecurity strategy?