SCP-500 Risk Assessment & Management 4 — Questions and Answers
Question 1: In SolarWinds, a 'dependency' relationship between nodes is important for risk management because it:
- Speeds up SNMP polling intervals
- Prevents false alerts when a parent device is down (Correct answer)
- Enables automatic patch deployment
- Generates topology diagrams for auditors
Correct answer: Prevents false alerts when a parent device is down
Defining parent-child dependencies suppresses child alerts when the parent is offline, reducing alert noise and ensuring accurate risk assessment.
Question 2: An organization wants to prioritize remediation efforts across 500 discovered vulnerabilities. The BEST approach is to rank them by:
- Alphabetical order of CVE identifiers
- Discovery date alone
- CVSS score combined with asset criticality (Correct answer)
- Number of affected vendors
Correct answer: CVSS score combined with asset criticality
Combining CVSS severity with the business criticality of the affected asset provides a risk-prioritized remediation order.
Question 3: SolarWinds Server & Application Monitor (SAM) reduces operational risk by monitoring which layer that NPM alone cannot cover?
- Physical cable integrity
- Application and service health on servers (Correct answer)
- Wireless spectrum interference
- BGP peering sessions
Correct answer: Application and service health on servers
SAM monitors processes, services, and application performance on servers, providing visibility beyond network-layer metrics.
Question 4: Which risk concept describes the probability that a threat will successfully exploit a vulnerability within a given time period?
- Risk appetite
- Likelihood (or probability) (Correct answer)
- Control gap
- Residual impact
Correct answer: Likelihood (or probability)
Likelihood quantifies how probable it is that a given threat will materialize and exploit a known vulnerability.
Question 5: When SolarWinds NCM detects that a device configuration has changed outside of a maintenance window, the recommended risk response is to:
- Immediately reboot the device
- Generate an alert and compare the running config against the approved baseline (Correct answer)
- Delete the device from NCM inventory
- Increase SNMP polling frequency
Correct answer: Generate an alert and compare the running config against the approved baseline
Comparing the changed configuration to the approved baseline identifies unauthorized modifications so they can be reverted or approved.
Question 6: A Business Impact Analysis (BIA) is conducted PRIMARILY to:
- Identify the cheapest monitoring vendor
- Determine which business processes are most critical and the cost of their disruption (Correct answer)
- Configure SolarWinds alert thresholds
- Audit firewall rule compliance
Correct answer: Determine which business processes are most critical and the cost of their disruption
A BIA identifies critical business functions and quantifies the impact of their disruption to inform risk prioritization and recovery planning.
Question 7: In SolarWinds Observability, correlating metrics, logs, and traces across a hybrid environment primarily addresses which risk?
- Blind spots that allow incidents to go undetected across service boundaries (Correct answer)
- Excessive SNMP community string sharing
- Unencrypted Telnet sessions
- Unauthorized VPN connections
Correct answer: Blind spots that allow incidents to go undetected across service boundaries
Full-stack observability eliminates visibility gaps, so incidents spanning multiple technology layers are detected before they escalate.
In SolarWinds, a 'dependency' relationship between nodes is important for risk management because it: