SSP Risk Evaluation & Management 3 — Questions and Answers
Question 1: An organization uses the DELPHI technique during a risk assessment. What is the defining characteristic of this approach?
- Experts provide anonymous, iterative estimates that are reconciled through successive rounds (Correct answer)
- A facilitator leads a structured group brainstorming session in real time
- Historical incident data is statistically analyzed to project future risk likelihood
- A single subject-matter expert provides a definitive risk rating for each asset
Correct answer: Experts provide anonymous, iterative estimates that are reconciled through successive rounds
The Delphi technique uses anonymous, iterative rounds of expert input to reach consensus while avoiding groupthink.
Question 2: A quantitative risk analysis produces a probability distribution of possible losses. What does the 95th percentile value on this distribution represent?
- There is a 5% chance that losses will exceed this value in a given period (Correct answer)
- 95% of past incidents caused losses above this value
- The organization will definitely experience this loss in 95 out of 100 years
- Controls must reduce losses to below this value to be considered effective
Correct answer: There is a 5% chance that losses will exceed this value in a given period
The 95th percentile means there is a 5% probability that losses will exceed that threshold, commonly used to set worst-case planning budgets.
Question 3: Which risk register field is MOST critical for tracking the effectiveness of a risk treatment plan over time?
- Target risk rating and review date for post-treatment reassessment (Correct answer)
- The name and title of the person who originally identified the risk
- The date the risk was first entered into the risk register
- The threat source category (external, internal, environmental)
Correct answer: Target risk rating and review date for post-treatment reassessment
A target risk rating with a scheduled review date allows practitioners to verify whether treatment reduced risk to the desired level.
Question 4: An organization is deciding whether to self-insure or purchase third-party insurance for a specific risk. Which factor MOST strongly favors purchasing insurance?
- The potential loss magnitude is catastrophic and would threaten organizational survival (Correct answer)
- The risk has a high likelihood but very low financial impact
- The organization has a large capital reserve specifically set aside for losses
- The risk involves reputational damage that insurers typically exclude
Correct answer: The potential loss magnitude is catastrophic and would threaten organizational survival
Insurance is most valuable when a single loss event could be catastrophic, since self-insurance only makes sense when the organization can absorb the maximum likely loss.
Question 5: A security practitioner performing a business impact analysis (BIA) identifies that a payroll system has a Recovery Time Objective (RTO) of 4 hours. What does this mean for risk management?
- Any risk treatment must ensure the system can be restored within 4 hours of a disruption (Correct answer)
- Payroll data must be backed up every 4 hours to prevent loss
- The system has a 4-hour window before a disruption is reportable to regulators
- Risk acceptance for this system is valid for up to 4 hours per incident
Correct answer: Any risk treatment must ensure the system can be restored within 4 hours of a disruption
An RTO of 4 hours means risk controls must support restoring the payroll system within that window to meet business continuity requirements.
Question 6: What is the MAIN limitation of using historical incident data as the sole basis for threat likelihood estimates?
- Historical data may not account for emerging threats or changes in the threat landscape (Correct answer)
- Historical data always underestimates likelihood because many incidents go unreported
- Regulators prohibit using historical data in formal risk assessments
- Historical data is only applicable to quantitative risk analysis, not qualitative methods
Correct answer: Historical data may not account for emerging threats or changes in the threat landscape
Past incidents reflect past conditions; new attack methods, technologies, or adversary capabilities not yet observed will be missed.
Question 7: A risk practitioner assigns a risk a 'low' rating but the asset owner insists it should be 'high.' The disagreement stems from differing views on business impact. What is the BEST resolution process?
- Escalate to a risk committee or senior authority who can adjudicate based on organizational priorities (Correct answer)
- Default to the lower rating to avoid over-allocating security resources
- Accept the asset owner's rating because they have the most knowledge of the asset
- Conduct a new risk assessment using a different methodology to break the tie
Correct answer: Escalate to a risk committee or senior authority who can adjudicate based on organizational priorities
Risk rating disputes should be escalated to a governance body or senior decision-maker who can weigh organizational priorities objectively.
An organization uses the DELPHI technique during a risk assessment.
What is the defining characteristic of this approach?