SSCP Security Policies & Risk Management 5 — Questions and Answers
Question 1: During a Business Impact Analysis (BIA), the team identifies that a system must be restored within 4 hours after a disaster. This 4-hour window is called the:
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable time to restore a system or process after a disruption.
Question 2: Which of the following BEST describes a compensating control?
- A control that replaces a more expensive primary control
- An alternative control used when the primary control cannot be implemented (Correct answer)
- A control that verifies another control is working correctly
- A control mandated by external regulations
Correct answer: An alternative control used when the primary control cannot be implemented
Compensating controls provide equivalent protection when the primary or required control is infeasible due to technical, operational, or business constraints.
Question 3: An information security manager assigns risk ownership to a business unit manager rather than the IT department. What principle does this reflect?
- Risk owners should be technical staff with the most control knowledge
- Risk ownership belongs to those accountable for the affected business process (Correct answer)
- IT is solely responsible for all information security risks
- Risk ownership should rotate annually among departments
Correct answer: Risk ownership belongs to those accountable for the affected business process
Risk owners are typically the business process owners because they are accountable for the outcomes affected by the risk.
Question 4: A policy states: 'All sensitive data must be encrypted at rest using AES-256.' This is an example of which level of policy documentation?
- High-level organizational policy
- Standard or baseline (Correct answer)
- Guideline
- Procedure
Correct answer: Standard or baseline
Specific, mandatory technical requirements (like algorithm specifications) are documented in standards, which support higher-level policies.
Question 5: Which risk metric measures the percentage of an asset's value that would be lost in a single threat event?
- Annualized Rate of Occurrence (ARO)
- Annualized Loss Expectancy (ALE)
- Exposure Factor (EF) (Correct answer)
- Single Loss Expectancy (SLE)
Correct answer: Exposure Factor (EF)
Exposure Factor (EF) is the percentage of asset value lost in a single realized threat event, used to calculate SLE (SLE = Asset Value × EF).
Question 6: A security team is performing continuous monitoring of its risk posture. Which activity BEST supports ongoing risk awareness?
- Conducting a one-time risk assessment at system deployment
- Reviewing and updating the risk register based on new threat intelligence (Correct answer)
- Implementing all recommended controls from the initial audit
- Archiving past risk assessments for compliance purposes
Correct answer: Reviewing and updating the risk register based on new threat intelligence
Continuous monitoring requires regular updates to the risk register based on evolving threats, vulnerabilities, and business changes.
Question 7: A security policy review committee recommends retiring an outdated password complexity policy in favor of NIST SP 800-63B guidance on passphrases. What process formalizes this change?
- A change management and policy update process with management approval (Correct answer)
- An emergency incident response process
- A vulnerability disclosure process
- A configuration management database update
Correct answer: A change management and policy update process with management approval
Policy changes must go through a formal change management process, including review, approval, version control, and communication to affected parties.
During a Business Impact Analysis (BIA), the team identifies that a system must be restored within 4 hours after a disaster.
This 4-hour window is called the: