Microsoft Networking Essentials Exam Risk Assessment & Management 3 — Questions and Answers
Question 1: A security team creates a list of all possible threats, ranks them by likelihood and impact, and plots them on a grid. What is this grid called?
- Vulnerability scan report
- Risk matrix (Correct answer)
- Business impact analysis
- Threat intelligence feed
Correct answer: Risk matrix
A risk matrix (or risk heat map) plots likelihood against impact to prioritize risks visually.
Question 2: Which component of a Business Impact Analysis (BIA) identifies the maximum tolerable downtime before significant harm occurs?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
MTD defines the longest period a business function can be unavailable before causing unacceptable damage.
Question 3: A threat actor deliberately causes network congestion to make services unavailable. Which type of threat does this represent?
- Eavesdropping
- Denial of Service (DoS) (Correct answer)
- Spoofing
- Man-in-the-Middle
Correct answer: Denial of Service (DoS)
A DoS attack intentionally disrupts service availability by overwhelming network or system resources.
Question 4: What is the PRIMARY purpose of a vulnerability assessment in the risk management process?
- To identify and rank weaknesses that threats could exploit (Correct answer)
- To calculate the annual loss expectancy
- To implement security controls
- To transfer risk to a third party
Correct answer: To identify and rank weaknesses that threats could exploit
A vulnerability assessment systematically finds and prioritizes weaknesses before they are exploited.
Question 5: Which risk management concept describes the level of risk an organization is willing to accept without requiring additional controls?
- Risk appetite (Correct answer)
- Risk threshold
- Residual risk
- Control objective
Correct answer: Risk appetite
Risk appetite defines how much risk leadership is willing to tolerate in pursuit of organizational goals.
Question 6: A company backs up its data to an offsite location to ensure recovery after a disaster. This practice primarily addresses which risk category?
- Reputational risk
- Operational risk (Correct answer)
- Compliance risk
- Strategic risk
Correct answer: Operational risk
Operational risk includes disruptions to business processes such as data loss, and offsite backups directly mitigate this category.
Question 7: When calculating Single Loss Expectancy (SLE), which two values are multiplied?
- Asset value × Annualized Rate of Occurrence
- Asset value × Exposure Factor (Correct answer)
- Exposure Factor × Annualized Rate of Occurrence
- Threat likelihood × Control effectiveness
Correct answer: Asset value × Exposure Factor
SLE = Asset Value × Exposure Factor, giving the expected dollar loss from a single incident.
A security team creates a list of all possible threats, ranks them by likelihood and impact, and plots them on a grid.
What is this grid called?