SSCP Certification SSCP Risk Management Process 4 โ Questions and Answers
Question 1: Which framework uses a five-step process including Frame, Assess, Respond, Monitor, and is published by NIST for organizational risk management?
- NIST SP 800-39 (Correct answer)
- ISO/IEC 27005
- OCTAVE
- FAIR
Correct answer: NIST SP 800-39
NIST SP 800-39 'Managing Information Security Risk' defines the organization-wide risk management process with Frame, Assess, Respond, and Monitor steps.
Question 2: A threat source intentionally exploits a weakness in an application to gain unauthorized access. In risk terminology, what is the threat source in this scenario?
- Threat agent (Correct answer)
- Vulnerability
- Control gap
- Risk owner
Correct answer: Threat agent
A threat agent (or threat actor) is the entity โ human or otherwise โ that intentionally or unintentionally initiates a threat event against a system.
Question 3: In a Delphi risk assessment technique, a group of experts anonymously provide risk estimates in multiple rounds. What is the primary advantage of this approach?
- It reduces groupthink and anchoring bias by anonymizing expert opinions (Correct answer)
- It produces precise quantitative risk values based on historical data
- It eliminates the need for a risk register
- It is the fastest risk assessment method available
Correct answer: It reduces groupthink and anchoring bias by anonymizing expert opinions
The Delphi technique uses anonymized, iterative expert feedback to reach consensus while avoiding the social pressures that cause groupthink or anchoring bias.
Question 4: A Single Loss Expectancy (SLE) is calculated as:
- Asset Value ร Exposure Factor (Correct answer)
- Asset Value ร Annual Rate of Occurrence
- Annualized Loss Expectancy รท Annual Rate of Occurrence
- Threat Likelihood ร Vulnerability Score
Correct answer: Asset Value ร Exposure Factor
SLE = Asset Value (AV) ร Exposure Factor (EF), representing the expected loss from a single occurrence of a specific threat.
Question 5: Which risk analysis method uses attack trees, scenarios, and threat modeling to systematically identify risk without assigning specific monetary values?
- Qualitative risk analysis (Correct answer)
- Quantitative risk analysis
- Annualized loss expectancy calculation
- Monte Carlo simulation
Correct answer: Qualitative risk analysis
Qualitative risk analysis uses descriptive scales and scenario-based methods like attack trees to rank risks without requiring precise financial quantification.
Question 6: An organization uses a 5ร5 risk matrix to rate risks by likelihood and impact. A risk scored 4 (likelihood) ร 5 (impact) would be classified as:
- High risk requiring immediate treatment (Correct answer)
- Low risk requiring periodic review
- Medium risk accepted without controls
- Critical risk requiring insurance transfer
Correct answer: High risk requiring immediate treatment
A score of 20 out of 25 on a 5ร5 matrix places the risk in the high or critical zone, demanding immediate treatment action.
Question 7: What is the purpose of the 'risk framing' step at the organizational tier in NIST's risk management hierarchy?
- To establish the context, constraints, and assumptions that shape how risk decisions are made (Correct answer)
- To identify specific vulnerabilities in systems and software
- To calculate ALE and SLE for all assets
- To select and implement security controls from NIST SP 800-53
Correct answer: To establish the context, constraints, and assumptions that shape how risk decisions are made
Risk framing establishes the organizational risk context โ governance structure, risk tolerance, assumptions, and constraints โ that guides all subsequent risk decisions.
Which framework uses a five-step process including Frame, Assess, Respond, Monitor, and is published by NIST for organizational risk management?