SC-100 Security Strategy & Risk Management 2 — Questions and Answers
Question 1: A cybersecurity architect is designing a risk management framework for a multinational organization. Which approach best aligns with the NIST Cybersecurity Framework's 'Identify' function for asset management?
- Deploying endpoint detection and response tools across all devices
- Creating a comprehensive inventory of hardware, software, and data assets with ownership assignments (Correct answer)
- Implementing multi-factor authentication for all user accounts
- Configuring Azure Security Center to monitor all subscriptions
Correct answer: Creating a comprehensive inventory of hardware, software, and data assets with ownership assignments
The NIST CSF 'Identify' function requires establishing an asset inventory with clear ownership to understand the organizational context and cybersecurity risk.
Question 2: An organization wants to prioritize security investments using a quantitative risk approach. Which metric best represents the annualized financial impact of a specific threat?
- Risk Tolerance Index (RTI)
- Annualized Loss Expectancy (ALE) (Correct answer)
- Mean Time to Detect (MTTD)
- Control Effectiveness Score (CES)
Correct answer: Annualized Loss Expectancy (ALE)
ALE = Single Loss Expectancy × Annual Rate of Occurrence and quantifies the yearly expected financial loss from a specific risk scenario.
Question 3: A security architect needs to recommend a risk treatment strategy for a legacy system that cannot be patched and hosts low-sensitivity data. Which treatment is MOST appropriate?
- Risk avoidance by immediately decommissioning the system
- Risk acceptance with documented compensating controls and monitoring (Correct answer)
- Risk transfer by purchasing cyber insurance for the system
- Risk mitigation by applying a virtual patch via a WAF
Correct answer: Risk acceptance with documented compensating controls and monitoring
Risk acceptance with compensating controls is appropriate when the cost of other treatments exceeds the risk value, which is common for low-sensitivity legacy systems.
Question 4: When integrating security strategy with business objectives, which approach does Microsoft recommend for aligning security with organizational priorities?
- Treating security as a separate IT function with independent budgeting
- Establishing a Business Information Security Officer (BISO) role embedded within business units (Correct answer)
- Requiring all business decisions to be approved by the CISO before implementation
- Implementing security controls based solely on compliance requirements
Correct answer: Establishing a Business Information Security Officer (BISO) role embedded within business units
Microsoft recommends embedding BISOs within business units to bridge security strategy with business objectives and ensure security enables rather than blocks business.
Question 5: An organization is implementing the Zero Trust model. Which principle addresses the risk of lateral movement after a breach?
- Verify explicitly using all available data points
- Use least privilege access with just-in-time and just-enough-access
- Assume breach and minimize blast radius through segmentation (Correct answer)
- Automate threat detection and response using SIEM
Correct answer: Assume breach and minimize blast radius through segmentation
The 'Assume Breach' principle drives segmentation, least privilege, and end-to-end encryption to limit an attacker's ability to move laterally after initial compromise.
Question 6: A cybersecurity architect must evaluate residual risk after implementing controls. Which formula correctly calculates residual risk?
- Residual Risk = Inherent Risk + Control Effectiveness
- Residual Risk = Inherent Risk − Control Effectiveness (Correct answer)
- Residual Risk = Threat × Vulnerability × Impact − Control Cost
- Residual Risk = (Threat Likelihood × Impact) / Number of Controls
Correct answer: Residual Risk = Inherent Risk − Control Effectiveness
Residual risk is the risk remaining after controls are applied, calculated as the inherent risk minus the effectiveness of those controls.
Question 7: When developing a security strategy for a hybrid cloud environment, which approach best addresses supply chain risk?
- Requiring all vendors to achieve ISO 27001 certification before contract signing
- Implementing a Shared Responsibility Matrix and vendor security assessment program with continuous monitoring (Correct answer)
- Blocking all third-party integrations until a full audit is completed
- Deploying a CASB solution to monitor all cloud application usage
Correct answer: Implementing a Shared Responsibility Matrix and vendor security assessment program with continuous monitoring
A Shared Responsibility Matrix combined with ongoing vendor assessments addresses supply chain risk holistically by defining obligations and continuously validating third-party security posture.
A cybersecurity architect is designing a risk management framework for a multinational organization.
Which approach best aligns with the NIST Cybersecurity Framework's 'Identify' function for asset management?