SC-100 Risk Assessment 2 — Questions and Answers
Question 1: A cybersecurity architect is evaluating residual risk after implementing controls. Which formula correctly represents residual risk?
- Inherent Risk + Control Effectiveness
- Inherent Risk - Control Effectiveness (Correct answer)
- Threat × Vulnerability × Asset Value
- Impact × Likelihood × Control Gap
Correct answer: Inherent Risk - Control Effectiveness
Residual risk equals inherent risk minus the effectiveness of applied controls, representing remaining exposure after mitigations.
Question 2: During a cloud risk assessment, you identify that a third-party vendor has access to sensitive customer data stored in Azure. Which risk category does this primarily represent?
- Operational risk
- Supply chain / third-party risk (Correct answer)
- Regulatory compliance risk
- Insider threat risk
Correct answer: Supply chain / third-party risk
Third-party access to sensitive data is classified as supply chain or third-party risk, requiring vendor risk management controls.
Question 3: Which Microsoft tool provides a unified risk score by aggregating signals from Microsoft 365 Defender, Defender for Cloud, and other security products?
- Microsoft Purview Compliance Manager
- Microsoft Secure Score (Correct answer)
- Azure Security Benchmark
- Microsoft Sentinel Risk Analytics
Correct answer: Microsoft Secure Score
Microsoft Secure Score aggregates security posture signals across Microsoft products into a unified risk-based score.
Question 4: A security architect must prioritize remediation across 200 vulnerabilities. Which approach best aligns with a risk-based methodology?
- Remediate all critical CVSS scores first regardless of asset context
- Prioritize by combining CVSS score with asset criticality and exploitability (Correct answer)
- Fix vulnerabilities in alphabetical order by CVE ID
- Address all vulnerabilities on internet-facing systems before internal ones
Correct answer: Prioritize by combining CVSS score with asset criticality and exploitability
Risk-based prioritization combines vulnerability severity (CVSS) with asset business value and real-world exploitability to focus effort where risk is highest.
Question 5: When performing a quantitative risk assessment, which metric expresses the expected monetary loss from a threat occurring once?
- Annual Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Annual Rate of Occurrence (ARO)
- Recovery Time Objective (RTO)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) = Asset Value × Exposure Factor, representing the monetary loss from one occurrence of a threat event.
Question 6: An organization uses Azure Policy to enforce tagging and configuration standards. In a risk register, this control type is classified as:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Azure Policy enforces compliance before non-compliant resources can be created or changed, making it a preventive control.
Question 7: A risk appetite statement says the organization will not accept risks with an impact above 'High' and likelihood above 'Medium.' A newly identified risk scores High impact and High likelihood. What is the correct action?
- Accept the risk and monitor it quarterly
- Transfer the risk to cyber insurance immediately
- Treat the risk by implementing additional controls to reduce it within appetite (Correct answer)
- Ignore the risk since it has not materialized yet
Correct answer: Treat the risk by implementing additional controls to reduce it within appetite
When a risk exceeds defined appetite thresholds, the organization must treat (mitigate) it until the residual risk falls within acceptable boundaries.
A cybersecurity architect is evaluating residual risk after implementing controls.
Which formula correctly represents residual risk?