SSCP Certification SSCP Risk Management Process 3 — Questions and Answers
Question 1: A security team discovers that a critical server has an open vulnerability but the vendor has not yet released a patch. The team implements additional network monitoring and restricts access to the server. This is an example of:
- Compensating controls (Correct answer)
- Detective controls
- Directive controls
- Corrective controls
Correct answer: Compensating controls
Compensating controls are alternative security measures implemented when primary controls cannot be applied, such as when a patch is unavailable.
Question 2: In the context of SSCP risk management, what does the term 'residual risk' mean?
- The risk remaining after controls have been applied (Correct answer)
- The total risk before any controls are in place
- The risk transferred to an insurance company
- The risk accepted by senior management
Correct answer: The risk remaining after controls have been applied
Residual risk is the remaining risk exposure after all planned security controls and risk treatments have been implemented.
Question 3: Which of the following best describes the relationship between threats, vulnerabilities, and risk?
- A threat exploiting a vulnerability creates risk (Correct answer)
- A vulnerability exploiting a threat creates risk
- Risk exists independently of threats and vulnerabilities
- Threats and vulnerabilities are synonymous with risk
Correct answer: A threat exploiting a vulnerability creates risk
Risk arises when a threat (potential harm source) has the ability to exploit a vulnerability (weakness) — no vulnerability means the threat cannot realize a risk.
Question 4: An organization decides to discontinue an e-commerce feature because the security risks outweigh the business benefits. This risk response is called:
- Risk avoidance (Correct answer)
- Risk acceptance
- Risk mitigation
- Risk transfer
Correct answer: Risk avoidance
Risk avoidance eliminates the risk by not engaging in the activity that creates the risk, such as discontinuing a risky feature or process.
Question 5: What is the role of a risk owner in a risk management program?
- To be accountable for monitoring and managing a specific risk (Correct answer)
- To document all organizational risks in the risk register
- To perform penetration testing on vulnerable systems
- To approve all security expenditures
Correct answer: To be accountable for monitoring and managing a specific risk
A risk owner is the designated individual accountable for ensuring that a specific risk is properly monitored, treated, and reported.
Question 6: A company reviews its risk assessments every quarter. Which risk management concept does this practice support?
- Continuous monitoring (Correct answer)
- Risk quantification
- Threat modeling
- Vulnerability scanning
Correct answer: Continuous monitoring
Continuous monitoring ensures that risk assessments remain current as the threat landscape, systems, and business environment change over time.
Question 7: Which of the following scenarios represents risk acceptance as a deliberate management decision?
- Management reviews a low-severity risk and decides no action is needed because the cost of controls exceeds potential loss (Correct answer)
- Management ignores a high-severity risk due to lack of awareness
- Management transfers a risk to a third-party vendor
- Management implements controls to reduce risk below threshold
Correct answer: Management reviews a low-severity risk and decides no action is needed because the cost of controls exceeds potential loss
Risk acceptance is a deliberate, informed decision to acknowledge and tolerate a risk, typically because treatment costs outweigh the expected loss.
A security team discovers that a critical server has an open vulnerability but the vendor has not yet released a patch.
The team implements additional network monitoring and restricts access to the server.
This is an example of: