SCP-500 Risk Assessment & Management 5 — Questions and Answers
Question 1: Which SolarWinds reporting feature allows risk managers to demonstrate compliance posture by showing device configuration adherence over time?
- NetFlow Top Talkers report
- NCM compliance report against policy rules (Correct answer)
- VoIP & Network Quality Manager dashboard
- IPAM subnet utilization report
Correct answer: NCM compliance report against policy rules
NCM's compliance reports compare device configurations against defined policy rules and show historical adherence trends.
Question 2: The concept of 'risk appetite' in an organization defines:
- The maximum number of SolarWinds alerts allowed per day
- The total amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The minimum patch cycle frequency required by regulation
- The bandwidth threshold before an alert is triggered
Correct answer: The total amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the level of risk an organization consciously accepts as tolerable while pursuing its strategic goals.
Question 3: When SolarWinds NPM sends a 'node down' alert but the node is actually reachable, this is called a:
- True positive
- False positive (Correct answer)
- False negative
- True negative
Correct answer: False positive
A false positive alert fires when no actual problem exists, which can erode trust in the monitoring system if not addressed.
Question 4: To reduce the risk of alert fatigue in a large SolarWinds deployment, administrators should:
- Disable all non-critical alerts permanently
- Tune thresholds, use dependencies, and consolidate correlated alerts (Correct answer)
- Increase SNMP polling to every 10 seconds
- Route all alerts only to the SolarWinds admin's inbox
Correct answer: Tune thresholds, use dependencies, and consolidate correlated alerts
Proper tuning, dependency mapping, and alert correlation reduce noise so that meaningful alerts receive appropriate attention.
Question 5: Which term describes the risk that remains after an organization has applied all planned security controls?
- Inherent risk
- Gross risk
- Residual risk (Correct answer)
- Secondary risk
Correct answer: Residual risk
Residual risk is what persists after mitigation measures are implemented and must be explicitly accepted or further treated.
Question 6: SolarWinds Web Help Desk's change management module reduces risk by ensuring that:
- All changes are deployed immediately without review
- Changes follow an approval workflow before implementation (Correct answer)
- Only network devices are tracked for changes
- Patches are applied automatically at midnight
Correct answer: Changes follow an approval workflow before implementation
A structured approval workflow ensures changes are reviewed, authorized, and scheduled before deployment, reducing the risk of unplanned outages.
Question 7: In risk management terminology, a 'threat actor' refers to:
- A SolarWinds alert rule triggered by a threshold
- An entity (person, group, or system) capable of carrying out an attack or causing harm (Correct answer)
- A configuration backup stored in NCM
- An SNMP trap received from a managed device
Correct answer: An entity (person, group, or system) capable of carrying out an attack or causing harm
A threat actor is any individual, group, or automated system with the intent and capability to exploit vulnerabilities.
Which SolarWinds reporting feature allows risk managers to demonstrate compliance posture by showing device configuration adherence over time?