SSCP Risk Management & Compliance 1 — Questions and Answers
Question 1: Which risk management approach involves accepting the potential loss from a risk because the cost of mitigation exceeds the benefit?
- Risk transference
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance (also called risk tolerance or risk retention) is chosen when the cost of countermeasures outweighs the potential impact of the risk.
Question 2: What is the formula for calculating Annualized Loss Expectancy (ALE)?
- ALE = SLE × AV
- ALE = SLE × ARO (Correct answer)
- ALE = AV × EF
- ALE = ARO / SLE
Correct answer: ALE = SLE × ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO), representing the expected annual loss from a threat.
Question 3: Which framework provides a structured, flexible approach to managing cybersecurity risk and is widely adopted in US critical infrastructure?
- ISO 27001
- COBIT 5
- NIST Cybersecurity Framework (Correct answer)
- ITIL v4
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF) was specifically designed for US critical infrastructure and organizes practices around Identify, Protect, Detect, Respond, and Recover functions.
Question 4: A qualitative risk assessment differs from a quantitative risk assessment primarily because it:
- Requires actuarial data and precise monetary values
- Uses descriptive ratings like High, Medium, and Low instead of exact numbers (Correct answer)
- Can only be performed by external auditors
- Always produces a lower risk score than quantitative methods
Correct answer: Uses descriptive ratings like High, Medium, and Low instead of exact numbers
Qualitative assessments use subjective ratings and descriptive scales (e.g., High/Medium/Low) rather than precise monetary calculations, making them faster but less precise.
Question 5: Which term describes the remaining risk after security controls have been applied?
- Inherent risk
- Residual risk (Correct answer)
- Total risk
- Control risk
Correct answer: Residual risk
Residual risk is the risk that remains after safeguards or controls have been implemented to reduce the original (inherent) risk.
Question 6: Under HIPAA, which type of information must be protected by covered entities and business associates?
- Personally Identifiable Information (PII)
- Protected Health Information (PHI) (Correct answer)
- Controlled Unclassified Information (CUI)
- Sensitive But Unclassified (SBU) data
Correct answer: Protected Health Information (PHI)
HIPAA mandates the protection of Protected Health Information (PHI), which includes any individually identifiable health data created, received, or transmitted by covered entities.
Question 7: Which element is NOT typically part of a Business Impact Analysis (BIA)?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD)
- Annualized Rate of Occurrence (ARO) (Correct answer)
Correct answer: Annualized Rate of Occurrence (ARO)
ARO is a quantitative risk metric used in threat/risk analysis, not a BIA element; BIA focuses on recovery objectives (RTO, RPO) and maximum tolerable downtime.
Which risk management approach involves accepting the potential loss from a risk because the cost of mitigation exceeds the benefit?