SC-100 Risk Assessment 4 — Questions and Answers
Question 1: Which risk assessment approach relies on numerical values such as dollar amounts and statistical probabilities to express risk?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Semi-quantitative risk assessment
- Comparative risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses objective numerical measures like ALE, SLE, and ARO to express risk in financial terms.
Question 2: A Cybersecurity Architect is designing governance for a multi-cloud environment. Which framework provides a cloud-specific risk and control catalog recognized by CSPs including Microsoft?
- ISO 27001
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- NIST SP 800-53
- CIS Controls v8
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix is a cloud-specific control framework widely used for cloud risk assessments and mapped to major standards including Azure's compliance offerings.
Question 3: In the context of SC-100, what does 'attack surface reduction' primarily aim to achieve in risk management?
- Increase detective controls to identify breaches faster
- Reduce the number of pathways attackers can exploit to lower likelihood of risk (Correct answer)
- Transfer residual risk to managed security service providers
- Eliminate all vulnerabilities before deployment
Correct answer: Reduce the number of pathways attackers can exploit to lower likelihood of risk
Attack surface reduction minimizes the number of exposed entry points and attack vectors, directly lowering the likelihood component of risk.
Question 4: When using Microsoft Defender for Cloud's regulatory compliance dashboard, what does a 'failed control' indicate from a risk perspective?
- A security incident has occurred in that control area
- A resource configuration does not meet the required compliance control, representing a risk gap (Correct answer)
- The control has been intentionally disabled by an administrator
- Microsoft has deprecated support for that compliance control
Correct answer: A resource configuration does not meet the required compliance control, representing a risk gap
A failed control in Defender for Cloud indicates a resource does not satisfy the compliance requirement, representing an unmitigated risk gap against that standard.
Question 5: A security architect is asked to perform a Business Impact Analysis (BIA). What is the primary output of a BIA in the context of risk assessment?
- A list of all known vulnerabilities in production systems
- Identification of critical business processes and the impact of disruptions on them (Correct answer)
- A penetration test report detailing exploitable weaknesses
- A cost-benefit analysis of security tool investments
Correct answer: Identification of critical business processes and the impact of disruptions on them
A BIA identifies critical business processes, their dependencies, and the financial and operational impact if those processes are disrupted.
Question 6: Which Microsoft Entra feature helps assess and remediate identity risk by detecting anomalous sign-in behaviors and leaked credentials?
- Entra ID Conditional Access
- Entra ID Protection (Identity Protection) (Correct answer)
- Entra Verified ID
- Entra External Identities
Correct answer: Entra ID Protection (Identity Protection)
Microsoft Entra ID Protection uses machine learning to detect identity risks like impossible travel and leaked credentials, enabling automated risk-based remediation.
Question 7: An organization's risk register shows a risk with High inherent risk that has been accepted without controls because the cost of mitigation exceeds the asset value. This is an example of:
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
When the cost of controls exceeds the potential loss, the organization may formally accept the risk, documenting this decision in the risk register.
Which risk assessment approach relies on numerical values such as dollar amounts and statistical probabilities to express risk?