SSCP Certification SSCP Risk Management Process 2 — Questions and Answers
Question 1: A security analyst is comparing two risk treatment options. Option A costs $50,000 and reduces annual loss expectancy from $200,000 to $80,000. Option B costs $90,000 and reduces it to $40,000. Which metric best justifies selecting Option A?
- Return on Security Investment (ROSI) (Correct answer)
- Mean Time to Recovery (MTTR)
- Control Objectives for Information Technology (COBIT)
- Business Impact Analysis (BIA)
Correct answer: Return on Security Investment (ROSI)
ROSI compares the reduction in annual loss expectancy against the cost of the control, making it the correct metric for comparing security investment options.
Question 2: During a risk assessment, a threat is identified with a likelihood of 0.3 and an impact of $500,000. What is the risk value using quantitative risk analysis?
- $150,000 (Correct answer)
- $500,000
- $166,667
- $1,500,000
Correct answer: $150,000
Quantitative risk value = Likelihood × Impact = 0.3 × $500,000 = $150,000 (Annualized Loss Expectancy concept).
Question 3: Which risk response strategy is being used when a company purchases cyber liability insurance to cover potential data breach costs?
- Risk transfer (Correct answer)
- Risk avoidance
- Risk acceptance
- Risk mitigation
Correct answer: Risk transfer
Purchasing insurance transfers the financial consequence of a risk to a third party (the insurer), which is the definition of risk transfer.
Question 4: A risk register entry shows a vulnerability with no known exploits and a patch available but not yet applied. Which qualitative risk rating is most appropriate?
- Medium (Correct answer)
- Critical
- Low
- High
Correct answer: Medium
No known active exploits lowers likelihood, but an unpatched vulnerability with available patch represents a moderate, manageable risk — typically rated Medium.
Question 5: What is the primary purpose of a risk appetite statement in an organization's risk management framework?
- To define the level of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- To enumerate all identified threats and vulnerabilities
- To assign dollar values to potential losses
- To document regulatory compliance requirements
Correct answer: To define the level of risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement formally defines how much risk an organization is willing to tolerate while pursuing its strategic objectives.
Question 6: During a risk assessment, the team identifies that a flood has a 1-in-10 chance of occurring each year and would cause $300,000 in damages. What is the Annualized Loss Expectancy (ALE)?
- $30,000 (Correct answer)
- $300,000
- $3,000,000
- $3,000
Correct answer: $30,000
ALE = ARO × SLE = 0.1 × $300,000 = $30,000, representing the expected annual financial loss from this specific risk.
Question 7: Which document formally records identified risks, their severity, owners, and treatment plans in a structured format?
- Risk register (Correct answer)
- Business continuity plan
- Security policy
- Vulnerability assessment report
Correct answer: Risk register
A risk register is the central repository that documents all identified risks along with their assessment details, ownership, and treatment decisions.
A security analyst is comparing two risk treatment options.
Option A costs $50,000 and reduces annual loss expectancy from $200,000 to $80,000.
Option B costs $90,000 and reduces it to $40,000.
Which metric best justifies selecting Option A?