SAC Safety & Risk Management 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring the financial consequences of a risk to a third party?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts financial liability to another party, typically through insurance or outsourcing contracts.
Question 2: A system administrator is classifying data stored on company servers. Which data classification level typically requires the MOST stringent access controls?
- Public
- Internal
- Confidential
- Top Secret / Restricted (Correct answer)
Correct answer: Top Secret / Restricted
Top Secret or Restricted classifications demand the highest level of access controls due to potential for severe harm if disclosed.
Question 3: What is the primary purpose of a Business Impact Analysis (BIA)?
- To identify vulnerabilities in network infrastructure
- To determine the financial and operational impact of service disruptions (Correct answer)
- To audit user access permissions
- To test backup restoration procedures
Correct answer: To determine the financial and operational impact of service disruptions
A BIA identifies critical business functions and quantifies the impact of disruptions to help prioritize recovery efforts.
Question 4: Which metric in disaster recovery planning defines the maximum acceptable amount of data loss measured in time?
- RTO (Recovery Time Objective)
- MTBF (Mean Time Between Failures)
- RPO (Recovery Point Objective) (Correct answer)
- MTTR (Mean Time to Repair)
Correct answer: RPO (Recovery Point Objective)
RPO defines how far back in time a recovery point must be, essentially the maximum tolerable data loss window.
Question 5: An attacker exploits a known vulnerability in an unpatched server. Which risk management control failure does this BEST represent?
- Inadequate detective controls
- Failure of preventive controls (Correct answer)
- Missing corrective controls
- Absence of compensating controls
Correct answer: Failure of preventive controls
Preventive controls, such as patch management, are designed to stop incidents before they occur; failure to patch allows exploitation.
Question 6: In a server room, which environmental control is MOST critical for preventing hardware failure due to heat buildup?
- Fire suppression system
- Uninterruptible Power Supply (UPS)
- Hot/cold aisle containment and HVAC (Correct answer)
- Raised flooring
Correct answer: Hot/cold aisle containment and HVAC
Hot/cold aisle containment combined with HVAC systems ensures proper airflow and maintains safe operating temperatures for equipment.
Question 7: Which document formally authorizes the start of a risk assessment project and defines its scope?
- Risk register
- Statement of work
- Project charter (Correct answer)
- System security plan
Correct answer: Project charter
A project charter officially authorizes the project, names the project manager, and defines the scope and objectives of the risk assessment.
Which risk treatment option involves transferring the financial consequences of a risk to a third party?