SSP Risk Evaluation & Management 2 â Questions and Answers
Question 1: A security manager is comparing two risk treatment options. Option A has an annualized loss expectancy (ALE) of $80,000 and costs $20,000 to implement. Option B has an ALE of $50,000 and costs $60,000 to implement. Which option provides better value?
- Option A, because the net benefit ($60,000 reduction) exceeds its cost by more (Correct answer)
- Option B, because it reduces risk to a lower absolute level
- Option A, because its implementation cost is the lowest
- Option B, because lower ALE always indicates better risk management
Correct answer: Option A, because the net benefit ($60,000 reduction) exceeds its cost by more
Option A yields a net benefit of $60,000 (ALE reduction) minus $20,000 (cost) = $40,000 net benefit, while Option B yields $30,000 minus $60,000 = -$30,000 net loss.
Question 2: During a risk assessment, a practitioner discovers that a critical asset has no documented owner. What is the MOST significant consequence of this gap?
- No one is accountable for accepting, treating, or monitoring risk to that asset (Correct answer)
- The asset cannot be included in the risk register
- Insurance coverage for the asset becomes void
- The risk assessment must be restarted from the beginning
Correct answer: No one is accountable for accepting, treating, or monitoring risk to that asset
Without an asset owner, accountability for risk decisionsâaccept, treat, transfer, or avoidâis undefined, leaving the asset unmanaged.
Question 3: Which risk treatment strategy is being applied when an organization decides to discontinue a product line that carries unacceptable cybersecurity risk?
- Risk avoidance (Correct answer)
- Risk acceptance
- Risk transfer
- Risk mitigation
Correct answer: Risk avoidance
Risk avoidance eliminates the activity or condition that creates the risk, such as discontinuing a product line.
Question 4: A risk matrix uses likelihood and consequence axes. A threat rated 'possible' (3/5) with 'major' consequences (4/5) produces a risk score of 12. The organization's risk appetite threshold is 10. What action is required?
- The risk must be treated because it exceeds the risk appetite threshold (Correct answer)
- The risk may be accepted because the likelihood is moderate
- The risk can be deferred until the next assessment cycle
- No action is needed unless the consequence rating rises to 5/5
Correct answer: The risk must be treated because it exceeds the risk appetite threshold
A risk score of 12 exceeds the threshold of 10, so the organization's risk appetite requires a treatment plan.
Question 5: What is the primary purpose of a residual risk assessment conducted AFTER implementing security controls?
- To determine whether remaining risk falls within the organization's risk acceptance criteria (Correct answer)
- To justify the budget spent on the controls implemented
- To identify new threats introduced by the controls themselves
- To update the threat landscape for the next fiscal year
Correct answer: To determine whether remaining risk falls within the organization's risk acceptance criteria
Residual risk assessment verifies that the post-control risk level is acceptable relative to the organization's defined tolerance.
Question 6: A security practitioner is briefing senior leadership on risk. Which communication approach is MOST effective for a non-technical executive audience?
- Express risks in financial terms such as potential dollar losses and business impact (Correct answer)
- Present detailed technical vulnerability scan results and CVSS scores
- Provide a comprehensive list of all identified threats and vulnerabilities
- Focus exclusively on regulatory compliance requirements and penalties
Correct answer: Express risks in financial terms such as potential dollar losses and business impact
Executives respond best to risk communicated as business impactâfinancial loss, reputational harm, or operational disruptionârather than technical metrics.
Question 7: Which of the following BEST describes the concept of 'inherent risk' in risk management?
- The level of risk that exists before any controls or countermeasures are applied (Correct answer)
- The risk that remains after all planned controls have been fully implemented
- The risk transferred to a third party through insurance or contract
- The risk accepted by senior management as part of normal business operations
Correct answer: The level of risk that exists before any controls or countermeasures are applied
Inherent risk is the raw or baseline risk level of a threat-asset combination with no controls in place.
A security manager is comparing two risk treatment options.
Option A has an annualized loss expectancy (ALE) of $80,000 and costs $20,000 to implement.
Option B has an ALE of $50,000 and costs $60,000 to implement.
Which option provides better value?