SSCP Security Policies & Risk Management 2 — Questions and Answers
Question 1: A risk manager determines that implementing a control costs $50,000 annually but the expected loss from the threat is only $10,000. What is the recommended action?
- Implement the control regardless of cost
- Accept the risk because the control cost exceeds expected loss (Correct answer)
- Transfer the risk to a third party
- Avoid the risk by discontinuing the activity
Correct answer: Accept the risk because the control cost exceeds expected loss
When annualized control cost exceeds the Annualized Loss Expectancy (ALE), accepting the risk is typically the economically rational choice.
Question 2: Which policy type defines the minimum security requirements that all systems in an organization must meet?
- Issue-specific policy
- System-specific policy
- Baseline policy (Correct answer)
- Regulatory policy
Correct answer: Baseline policy
Baseline policies establish the minimum acceptable security configuration standards applied across all organizational systems.
Question 3: During a risk assessment, the team identifies a vulnerability with no known exploit. How should residual risk be categorized?
- High, because the vulnerability exists
- Low to moderate, since exploitability is currently absent (Correct answer)
- Zero, because no exploit exists
- Critical, requiring immediate remediation
Correct answer: Low to moderate, since exploitability is currently absent
Residual risk accounts for both vulnerability severity and current exploitability; no known exploit reduces but does not eliminate risk.
Question 4: What is the PRIMARY purpose of a Statement of Applicability (SoA) in an information security management system?
- To list all identified threats
- To document which controls from a standard are applicable and why (Correct answer)
- To assign risk ownership to departments
- To define the scope of a penetration test
Correct answer: To document which controls from a standard are applicable and why
The SoA documents selected controls from a framework (e.g., ISO 27001 Annex A), including justifications for inclusion or exclusion.
Question 5: An organization's security policy prohibits personal device use on the corporate network, yet employees routinely connect personal phones. This represents which type of risk?
- Residual risk
- Inherent risk
- Policy non-compliance risk (Correct answer)
- Transfer risk
Correct answer: Policy non-compliance risk
When employees violate established policies, the resulting exposure is classified as policy non-compliance risk.
Question 6: In qualitative risk analysis, risks are typically rated using which method?
- Annualized Loss Expectancy calculations
- Descriptive scales such as High, Medium, and Low (Correct answer)
- Monte Carlo simulations
- Net Present Value analysis
Correct answer: Descriptive scales such as High, Medium, and Low
Qualitative risk analysis uses subjective, descriptive scales rather than precise monetary calculations to rank risk severity.
Question 7: Which document formally authorizes a system to operate by accepting its known risks?
- Risk Register
- System Security Plan
- Authorization to Operate (ATO) (Correct answer)
- Business Impact Analysis
Correct answer: Authorization to Operate (ATO)
An Authorization to Operate (ATO) is the formal management decision granting permission to operate a system with its identified residual risks.
A risk manager determines that implementing a control costs $50,000 annually but the expected loss from the threat is only $10,000.
What is the recommended action?