SCP-500 Risk Assessment & Management 3 — Questions and Answers
Question 1: SolarWinds Security Event Manager (SEM) helps reduce risk by performing which core function?
- Generating SSL certificates for web servers
- Correlating log events to detect security threats in real time (Correct answer)
- Provisioning VLAN configurations
- Managing software license compliance
Correct answer: Correlating log events to detect security threats in real time
SEM aggregates and correlates log data from multiple sources to identify patterns indicative of security incidents.
Question 2: When evaluating risk impact in an IT environment, which factor most directly determines the financial severity of a system outage?
- Number of network hops to the affected device
- Mean Time to Detect (MTTD) alone
- Revenue loss per hour of downtime multiplied by expected outage duration (Correct answer)
- SNMP trap version used
Correct answer: Revenue loss per hour of downtime multiplied by expected outage duration
Financial severity is best quantified by multiplying the hourly cost of downtime by the expected outage duration.
Question 3: In the context of SolarWinds NPM availability reporting, a node with 99.0% uptime over 30 days experienced approximately how many minutes of downtime?
- 14 minutes
- 72 minutes
- 432 minutes (Correct answer)
- 720 minutes
Correct answer: 432 minutes
99% uptime over 30 days (43,200 minutes) leaves 1% downtime, equal to 432 minutes.
Question 4: A company identifies that a critical router has no redundant path. This represents which type of risk?
- Compliance risk
- Single point of failure risk (Correct answer)
- Vendor lock-in risk
- Regulatory risk
Correct answer: Single point of failure risk
A single point of failure (SPOF) is a component whose failure would halt the entire system or service.
Question 5: SolarWinds IPAM reduces risk by preventing which common network problem?
- Packet fragmentation
- IP address conflicts and unauthorized allocations (Correct answer)
- BGP route flapping
- DNS cache poisoning
Correct answer: IP address conflicts and unauthorized allocations
IPAM tracks IP address assignments to prevent duplicate IPs and unauthorized devices from claiming addresses.
Question 6: Which SolarWinds feature allows administrators to define which users can acknowledge or modify alerts, reducing the risk of unauthorized changes?
- Role-based access control (RBAC) (Correct answer)
- SNMP community strings
- NetFlow traffic analysis
- Syslog forwarding
Correct answer: Role-based access control (RBAC)
RBAC restricts alert management actions to authorized personnel based on their assigned roles.
Question 7: During a risk assessment, 'inherent risk' refers to:
- Risk remaining after controls are applied
- Risk that exists before any controls are in place (Correct answer)
- Risk accepted by executive management
- Risk transferred to a vendor
Correct answer: Risk that exists before any controls are in place
Inherent risk is the raw, unmitigated level of risk present in the absence of any controls.
SolarWinds Security Event Manager (SEM) helps reduce risk by performing which core function?