SSCP Risk Management & Compliance 2 — Questions and Answers
Question 1: Which PCI DSS requirement mandates that cardholder data environments be segmented from other networks?
- Requirement 1 – Firewall configuration (Correct answer)
- Requirement 3 – Stored data protection
- Requirement 6 – Secure systems development
- Requirement 11 – Security testing
Correct answer: Requirement 1 – Firewall configuration
PCI DSS Requirement 1 addresses firewall and router configurations to isolate the cardholder data environment (CDE) from untrusted networks through network segmentation.
Question 2: What is the primary purpose of a risk register?
- To store encrypted passwords for privileged accounts
- To document identified risks, their assessments, and treatment plans (Correct answer)
- To log all firewall rule changes made by administrators
- To track software patch compliance across endpoints
Correct answer: To document identified risks, their assessments, and treatment plans
A risk register is a central repository that records identified risks along with their likelihood, impact, owner, and chosen treatment (accept, mitigate, transfer, or avoid).
Question 3: Which law requires US federal agencies to implement information security programs and report security incidents to US-CERT?
- SOX (Sarbanes-Oxley Act)
- GLBA (Gramm-Leach-Bliley Act)
- FISMA (Federal Information Security Modernization Act) (Correct answer)
- FERPA (Family Educational Rights and Privacy Act)
Correct answer: FISMA (Federal Information Security Modernization Act)
FISMA establishes mandatory information security standards for US federal agencies, requiring risk management programs, security controls, and incident reporting to US-CERT.
Question 4: An organization transfers risk by purchasing cyber liability insurance. Which risk response strategy does this represent?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a loss to a third party (e.g., an insurance company) without eliminating the underlying risk.
Question 5: Which control type is a security policy document that prohibits unauthorized data exfiltration?
- Technical control
- Physical control
- Administrative control (Correct answer)
- Compensating control
Correct answer: Administrative control
Administrative (also called managerial) controls are policy-based, procedural, or governance measures that guide employee behavior rather than technical or physical mechanisms.
Question 6: In risk management, what does 'threat likelihood' refer to?
- The dollar value of assets at risk
- The probability that a threat will exploit a vulnerability within a given timeframe (Correct answer)
- The number of controls currently protecting an asset
- The maximum acceptable downtime for a critical system
Correct answer: The probability that a threat will exploit a vulnerability within a given timeframe
Threat likelihood (or probability) estimates how likely it is that a specific threat will successfully exploit a vulnerability during a defined period, and it is a key input to risk calculation.
Question 7: Which standard provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)?
- NIST SP 800-53
- ISO/IEC 27001 (Correct answer)
- CIS Controls v8
- SOC 2 Type II
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the internationally recognized standard that specifies requirements for an ISMS, enabling organizations to systematically manage information security risks.
Which PCI DSS requirement mandates that cardholder data environments be segmented from other networks?