SSCP Security Policies & Risk Management 3 — Questions and Answers
Question 1: A company outsources its payroll processing to a third-party vendor. The company retains full legal liability for data breaches. Which risk response strategy does this represent?
- Risk avoidance
- Risk acceptance
- Risk transfer (partial) (Correct answer)
- Risk mitigation
Correct answer: Risk transfer (partial)
Outsourcing operational risk to a vendor is risk transfer, but legal/regulatory liability often remains with the originating organization, making it only partial transfer.
Question 2: Which element is MOST critical when developing a security policy to ensure it is enforceable?
- Technical complexity of the controls
- Senior management sponsorship and authorization (Correct answer)
- Length and detail of the document
- Use of industry-standard terminology
Correct answer: Senior management sponsorship and authorization
Policies require senior management authorization to carry organizational authority and be legally enforceable within the enterprise.
Question 3: What is the difference between a threat and a vulnerability in risk management?
- A threat is a weakness; a vulnerability is a potential attacker
- A threat is a potential harm event; a vulnerability is a weakness that could be exploited (Correct answer)
- They are interchangeable terms in risk assessments
- A threat is internal; a vulnerability is always external
Correct answer: A threat is a potential harm event; a vulnerability is a weakness that could be exploited
A threat is any circumstance that could cause harm, while a vulnerability is a flaw or weakness that a threat could exploit.
Question 4: An organization reviews its risk register every quarter. A previously accepted risk now has a higher likelihood due to a new exploit. What action should be taken first?
- Immediately implement compensating controls
- Re-evaluate the risk using updated threat intelligence (Correct answer)
- Close the risk and open a new one
- Escalate directly to the board of directors
Correct answer: Re-evaluate the risk using updated threat intelligence
Changed threat conditions require re-evaluation of the risk's likelihood and impact before determining the appropriate response.
Question 5: Which framework specifically provides a five-step Risk Management Framework (RMF) process used by US federal agencies?
- ISO/IEC 27005
- NIST SP 800-37 (Correct answer)
- COBIT 5
- FAIR model
Correct answer: NIST SP 800-37
NIST SP 800-37 defines the Risk Management Framework used by US federal agencies for categorizing, selecting, implementing, and authorizing information systems.
Question 6: A security manager wants to calculate the probability that a specific threat will occur within a given year. Which metric does this represent?
- Single Loss Expectancy (SLE)
- Annualized Rate of Occurrence (ARO) (Correct answer)
- Exposure Factor (EF)
- Annualized Loss Expectancy (ALE)
Correct answer: Annualized Rate of Occurrence (ARO)
ARO expresses how often a specific threat is expected to materialize in a 12-month period.
Question 7: What type of control is a mandatory vacation policy primarily designed to support?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Deterrent control
Correct answer: Detective control
Mandatory vacation is a detective control because it creates opportunities to uncover fraud or irregularities that may be concealed by a single employee staying on the job.
A company outsources its payroll processing to a third-party vendor.
The company retains full legal liability for data breaches.
Which risk response strategy does this represent?