PCIP Risk Assessment 3 โ Questions and Answers
Question 1: In quantitative risk analysis, Annualized Loss Expectancy (ALE) is calculated as:
- ALE = Single Loss Expectancy รท Annualized Rate of Occurrence
- ALE = Single Loss Expectancy ร Annualized Rate of Occurrence (Correct answer)
- ALE = Asset Value ร Threat Probability
- ALE = Exposure Factor + Annualized Rate of Occurrence
Correct answer: ALE = Single Loss Expectancy ร Annualized Rate of Occurrence
ALE equals SLE multiplied by ARO, representing the expected annual financial loss from a specific risk.
Question 2: Which risk treatment option involves purchasing cyber insurance to cover potential cardholder data breach losses?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as an insurer, without eliminating the underlying risk.
Question 3: A new e-commerce checkout feature is being deployed that will process card-not-present transactions. When should a risk assessment be conducted?
- Within 90 days after go-live
- Only at the next annual assessment cycle
- Before the feature is deployed, as a significant environmental change (Correct answer)
- After the first full month of transaction data is available
Correct answer: Before the feature is deployed, as a significant environmental change
PCI DSS requires risk assessments upon significant changes to the cardholder data environment, and a new payment feature qualifies as such a change.
Question 4: Which asset classification BEST describes PANs stored in an encrypted database within the cardholder data environment?
- Public data
- Sensitive cardholder data requiring protection (Correct answer)
- Internal-use only data
- Non-sensitive tokenized data
Correct answer: Sensitive cardholder data requiring protection
PANs are classified as sensitive cardholder data and must be protected per PCI DSS even when encrypted, as they remain within scope.
Question 5: During a risk assessment workshop, a stakeholder suggests accepting a high-rated risk because remediation is too costly. As a PCIP, you should:
- Document the formal risk acceptance with executive sign-off and set a review date (Correct answer)
- Override the decision and require immediate remediation
- Remove the risk from the register to avoid audit findings
- Escalate to the QSA without notifying management
Correct answer: Document the formal risk acceptance with executive sign-off and set a review date
Risk acceptance is a valid treatment option but must be formally documented with executive approval and a defined review timeline.
Question 6: Which of the following BEST represents a vulnerability in the context of PCI DSS risk assessment?
- A hurricane that could flood the data center
- An unpatched operating system running on a POS terminal (Correct answer)
- The financial impact of a data breach
- The likelihood that an attacker targets the cardholder environment
Correct answer: An unpatched operating system running on a POS terminal
A vulnerability is a weakness in a system, such as an unpatched OS, that a threat could exploit; threats and impacts are separate risk components.
Question 7: A risk register entry shows: Threat=Phishing, Vulnerability=No email filtering, Likelihood=High, Impact=High. Which action is MOST appropriate?
- Accept the risk because phishing is industry-wide
- Implement email filtering controls as a priority mitigation (Correct answer)
- Transfer the risk by outsourcing email to a cloud provider
- Avoid the risk by discontinuing email entirely
Correct answer: Implement email filtering controls as a priority mitigation
A High/High risk with an identifiable control gap (missing email filtering) should be prioritized for mitigation with the specific control that closes the gap.
In quantitative risk analysis, Annualized Loss Expectancy (ALE) is calculated as: