MCTS 70-642 Risk Assessment & Management 2 — Questions and Answers
Question 1: A network administrator needs to evaluate the likelihood and impact of a potential threat to the Windows Server 2008 network infrastructure. Which risk assessment approach quantifies risk using numerical values such as dollar amounts?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Hybrid risk assessment
- Residual risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical monetary values to assets and risks, enabling calculation of Annual Loss Expectancy (ALE).
Question 2: During a Windows Server 2008 network audit, you discover that patch management has been neglected for six months. Which term best describes the window of time between the discovery of a vulnerability and the application of a patch?
- Zero-day window
- Exposure window (Correct answer)
- Threat window
- Residual window
Correct answer: Exposure window
The exposure window is the period during which a system remains vulnerable between vulnerability discovery and patch deployment.
Question 3: An organization wants to prioritize security controls for its Windows Server 2008 infrastructure based on the cost of a control versus the value of the asset it protects. Which formula helps determine whether a safeguard is cost-effective?
- SLE × ARO = ALE
- ALE before – ALE after – cost of control (Correct answer)
- Asset Value × EF = SLE
- Threat frequency × Vulnerability factor
Correct answer: ALE before – ALE after – cost of control
The cost-benefit formula (ALE before safeguard – ALE after safeguard – annual cost of safeguard) determines whether a control is worth implementing.
Question 4: A Windows Server 2008 administrator is performing a risk assessment and calculates a Single Loss Expectancy (SLE) of $50,000 and an Annualized Rate of Occurrence (ARO) of 0.5. What is the Annualized Loss Expectancy (ALE)?
- $100,000
- $25,000 (Correct answer)
- $50,000
- $10,000
Correct answer: $25,000
ALE = SLE × ARO = $50,000 × 0.5 = $25,000.
Question 5: When securing a Windows Server 2008 network, which threat modeling approach focuses on categorizing threats by attacker goals such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
- PASTA
- STRIDE (Correct answer)
- DREAD
- OCTAVE
Correct answer: STRIDE
STRIDE is Microsoft's threat categorization model that classifies threats into six categories to help identify security risks systematically.
Question 6: A company's Windows Server 2008 file server stores confidential HR data. After a risk assessment, management decides to purchase cyber liability insurance to handle potential data breach costs. Which risk response strategy does this represent?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequence of a risk to a third party, such as an insurance provider, without eliminating the risk itself.
Question 7: During a Windows Server 2008 security review, an administrator identifies a vulnerability in a network service that is rarely used. Management decides the cost to fix it outweighs the risk and chooses to do nothing. Which risk treatment is being applied?
- Risk avoidance
- Risk transfer
- Risk mitigation
- Risk acceptance (Correct answer)
Correct answer: Risk acceptance
Risk acceptance (also called risk tolerance) means acknowledging a risk and deciding to live with it because the mitigation cost exceeds the potential loss.
A network administrator needs to evaluate the likelihood and impact of a potential threat to the Windows Server 2008 network infrastructure.
Which risk assessment approach quantifies risk using numerical values such as dollar amounts?