Microsoft Networking Essentials Exam Risk Assessment & Management 2 — Questions and Answers
Question 1: A company identifies that a flood could destroy its on-premises servers. Which risk response strategy involves purchasing flood insurance?
- Risk avoidance
- Risk transference (Correct answer)
- Risk mitigation
- Risk acceptance
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to a third party, such as an insurance company.
Question 2: Which quantitative risk metric expresses the expected monetary loss from a risk over a one-year period?
- Single Loss Expectancy (SLE)
- Annual Loss Expectancy (ALE) (Correct answer)
- Exposure Factor (EF)
- Return on Security Investment (ROSI)
Correct answer: Annual Loss Expectancy (ALE)
ALE = SLE × ARO and represents the annualized expected cost of a specific risk.
Question 3: During a risk assessment, an analyst rates threats based on gut feeling and experience rather than financial figures. This approach is called:
- Quantitative risk analysis
- Qualitative risk analysis (Correct answer)
- Residual risk analysis
- Threat modeling
Correct answer: Qualitative risk analysis
Qualitative analysis uses subjective ratings (e.g., High/Medium/Low) rather than exact monetary values.
Question 4: After implementing security controls, the remaining risk that has not been fully eliminated is known as:
- Inherent risk
- Residual risk (Correct answer)
- Secondary risk
- Control risk
Correct answer: Residual risk
Residual risk is the risk that remains after countermeasures have been applied.
Question 5: A network administrator discovers a vulnerability but decides the cost to fix it exceeds the potential loss. The organization documents this decision. Which strategy is being used?
- Risk avoidance
- Risk mitigation
- Risk acceptance (Correct answer)
- Risk transference
Correct answer: Risk acceptance
Risk acceptance means the organization consciously chooses to tolerate the risk because addressing it is not cost-effective.
Question 6: Which NIST publication provides a framework specifically designed to help organizations manage cybersecurity risk?
- NIST SP 800-53
- NIST SP 800-30
- NIST CSF 1.1 (Correct answer)
- NIST SP 800-171
Correct answer: NIST CSF 1.1
The NIST Cybersecurity Framework (CSF) organizes risk management into Identify, Protect, Detect, Respond, and Recover functions.
Question 7: An Exposure Factor (EF) of 0.40 means:
- 40% of assets are at risk
- An asset loses 40% of its value if a threat occurs (Correct answer)
- The threat occurs 40 times per year
- 40% of controls are ineffective
Correct answer: An asset loses 40% of its value if a threat occurs
EF represents the percentage of asset value lost due to a specific threat event.
A company identifies that a flood could destroy its on-premises servers.
Which risk response strategy involves purchasing flood insurance?