Microsoft Networking Essentials Exam Risk Assessment & Management 4 — Questions and Answers
Question 1: An organization maps out every critical business process and determines which IT systems support each process. This activity is part of:
- Penetration testing
- Business Impact Analysis (Correct answer)
- Threat hunting
- Gap analysis
Correct answer: Business Impact Analysis
A BIA identifies critical business functions and the IT resources that support them to prioritize recovery efforts.
Question 2: Which type of control is a security camera used to record activity in a server room?
- Preventive
- Detective (Correct answer)
- Corrective
- Deterrent
Correct answer: Detective
A detective control identifies and records incidents after or as they occur, like security cameras capturing events.
Question 3: An employee accidentally deletes a shared network folder. Which risk category best describes this event?
- External threat
- Natural disaster
- Human error (internal threat) (Correct answer)
- Compliance violation
Correct answer: Human error (internal threat)
Accidental data deletion by staff is classified as an internal human error threat.
Question 4: A risk register is BEST described as:
- A log of firewall rules blocking threats
- A documented inventory of identified risks, their ratings, and assigned owners (Correct answer)
- A list of all software vulnerabilities found by a scanner
- A policy document defining acceptable use
Correct answer: A documented inventory of identified risks, their ratings, and assigned owners
A risk register tracks each identified risk, its likelihood, impact, owner, and mitigation status.
Question 5: Which security principle ensures that users and systems are given only the access necessary to perform their job functions?
- Defense in depth
- Least privilege (Correct answer)
- Separation of duties
- Need to know
Correct answer: Least privilege
The principle of least privilege limits permissions to the minimum required, reducing the attack surface.
Question 6: A company conducts an annual review of its risk management plan to account for new technologies and emerging threats. This demonstrates which risk management practice?
- One-time risk assessment
- Continuous risk monitoring (Correct answer)
- Risk transference
- Vulnerability disclosure
Correct answer: Continuous risk monitoring
Continuous risk monitoring ensures the risk posture stays current as the threat landscape and business environment evolve.
Question 7: What does the Annualized Rate of Occurrence (ARO) represent in risk calculations?
- The dollar value of an asset
- The estimated number of times a threat event is expected to occur per year (Correct answer)
- The percentage of asset value lost per incident
- The time needed to recover from an incident
Correct answer: The estimated number of times a threat event is expected to occur per year
ARO quantifies how frequently a specific threat is expected to materialize in a 12-month period.
An organization maps out every critical business process and determines which IT systems support each process.
This activity is part of: