Microsoft Networking Essentials Exam Risk Assessment & Management 5 — Questions and Answers
Question 1: A third-party vendor with access to your network is compromised, leading to a breach of your systems. This scenario is an example of:
- Zero-day exploit
- Supply chain risk (Correct answer)
- Insider threat
- Social engineering
Correct answer: Supply chain risk
Supply chain risk occurs when a trusted partner or vendor introduces vulnerabilities into your environment.
Question 2: Which document formally authorizes the operation of an IT system by accepting its residual risk?
- System Security Plan (SSP)
- Authority to Operate (ATO) (Correct answer)
- Risk Treatment Plan
- Incident Response Plan
Correct answer: Authority to Operate (ATO)
An ATO is an official management decision to authorize operation of a system, acknowledging and accepting its residual risk.
Question 3: During risk prioritization, an analyst should address which combination FIRST?
- Low likelihood, high impact
- High likelihood, low impact
- High likelihood, high impact (Correct answer)
- Low likelihood, low impact
Correct answer: High likelihood, high impact
Risks with both high likelihood and high impact pose the greatest overall threat and should be addressed first.
Question 4: What is the MAIN difference between a threat and a vulnerability in risk terminology?
- A threat is internal; a vulnerability is external
- A threat is a potential danger; a vulnerability is a weakness that can be exploited (Correct answer)
- A vulnerability causes harm directly; a threat only describes weakness
- They are interchangeable terms
Correct answer: A threat is a potential danger; a vulnerability is a weakness that can be exploited
A threat is any circumstance or event that could exploit a vulnerability, while a vulnerability is the specific weakness being exploited.
Question 5: A company installs an intrusion prevention system (IPS) to automatically block detected attacks. This is an example of which type of control?
- Deterrent
- Preventive (Correct answer)
- Detective
- Compensating
Correct answer: Preventive
A preventive control stops attacks before they cause damage, which an IPS does by blocking malicious traffic in real time.
Question 6: Which standard provides a globally recognized framework for establishing, implementing, and improving an Information Security Management System (ISMS)?
- ISO/IEC 27001 (Correct answer)
- NIST SP 800-53
- PCI DSS
- SOC 2 Type II
Correct answer: ISO/IEC 27001
ISO/IEC 27001 specifies requirements for an ISMS and is the leading international standard for information security management.
Question 7: An organization decides to stop offering a particular online service because the security risks are too great to manage. This is an example of:
- Risk mitigation
- Risk acceptance
- Risk transference
- Risk avoidance (Correct answer)
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by choosing not to engage in the activity that creates it.
A third-party vendor with access to your network is compromised, leading to a breach of your systems.
This scenario is an example of: