SSP Risk Evaluation & Management 5 — Questions and Answers
Question 1: A practitioner is reviewing a risk treatment plan and finds that the proposed control will reduce likelihood but NOT reduce consequence. What type of control is this?
- A preventive control that reduces the probability of the threat event occurring (Correct answer)
- A corrective control that restores operations after an incident
- A detective control that identifies incidents after they occur
- A compensating control that replaces a failed primary control
Correct answer: A preventive control that reduces the probability of the threat event occurring
Controls that reduce likelihood are preventive—they make a threat event less likely without changing the severity if it does occur.
Question 2: During a risk review, a practitioner notes that a previously accepted risk has materially changed due to a new regulatory requirement. What risk management principle does this illustrate?
- Risk is dynamic and must be continuously monitored and reassessed as conditions change (Correct answer)
- Risk acceptance decisions are permanent once documented in the risk register
- Regulatory risk is always classified separately from operational risk
- Risk treatments must be updated annually regardless of changes in the environment
Correct answer: Risk is dynamic and must be continuously monitored and reassessed as conditions change
Risk management must be iterative; any material change in context—such as new regulations—can alter the risk level and invalidate prior acceptance decisions.
Question 3: An organization is applying a Monte Carlo simulation to model financial losses from security incidents. What is the PRIMARY advantage of this technique over a single-point ALE estimate?
- It produces a range of probable outcomes with associated probabilities, capturing uncertainty better than a single estimate (Correct answer)
- It eliminates the need for subject-matter expert input by relying entirely on statistical models
- It is faster and cheaper to execute than traditional annual loss expectancy calculations
- It is the only method accepted by regulators for cybersecurity risk quantification
Correct answer: It produces a range of probable outcomes with associated probabilities, capturing uncertainty better than a single estimate
Monte Carlo simulation runs thousands of scenarios with variable inputs, producing a probability distribution of losses that reflects real-world uncertainty better than a deterministic ALE.
Question 4: Which of the following scenarios BEST illustrates the concept of 'risk aggregation'?
- Multiple low-rated risks combine to create an enterprise-level risk that exceeds the organization's risk tolerance (Correct answer)
- A single catastrophic risk is divided into smaller sub-risks for easier management
- An organization consolidates all risk registers from subsidiaries into one master document
- A risk assessment team aggregates findings from multiple frameworks into a unified rating scale
Correct answer: Multiple low-rated risks combine to create an enterprise-level risk that exceeds the organization's risk tolerance
Risk aggregation occurs when individually acceptable risks collectively create an unacceptable cumulative exposure—a common blind spot in siloed risk management.
Question 5: A security practitioner is tasked with evaluating insider threat risk. Which data source would be MOST valuable for establishing a likelihood rating?
- Historical internal incident records combined with industry benchmarking data on insider threat frequency (Correct answer)
- External penetration test reports that identify exploitable technical vulnerabilities
- Vendor-provided threat intelligence feeds focused on nation-state cyber actors
- Physical access logs showing who entered server rooms in the past 30 days
Correct answer: Historical internal incident records combined with industry benchmarking data on insider threat frequency
Insider threat likelihood is best estimated from the organization's own historical incidents supplemented by industry benchmarks that reflect comparable insider threat rates.
Question 6: An organization's risk committee reviews a risk treatment proposal that will reduce residual risk from 'High' to 'Medium' but requires a $2 million investment. The asset's total value is $500,000. What concern should the committee raise?
- The control cost exceeds the asset value, making the investment economically unjustifiable without additional justification (Correct answer)
- The residual risk of 'Medium' is unacceptable and the committee should demand 'Low' risk
- The asset should be immediately decommissioned since it carries High risk
- The committee should accept the proposal because reducing risk from High to Medium is always worth the cost
Correct answer: The control cost exceeds the asset value, making the investment economically unjustifiable without additional justification
Spending $2 million to protect a $500,000 asset violates the cost-benefit principle; the control cost should not exceed the protected value without compelling justification.
Question 7: In the context of risk communication, what does 'risk framing' refer to?
- How the presentation of risk information shapes stakeholder perceptions and decisions about acceptable risk levels (Correct answer)
- The process of documenting risk within a formal risk register template
- The regulatory framework that defines reportable risk thresholds for organizations
- A facilitation technique for structuring risk identification workshops
Correct answer: How the presentation of risk information shapes stakeholder perceptions and decisions about acceptable risk levels
Risk framing describes how presenting the same risk differently—as a gain versus a loss, or a percentage versus a frequency—can significantly influence stakeholder decisions.
A practitioner is reviewing a risk treatment plan and finds that the proposed control will reduce likelihood but NOT reduce consequence.
What type of control is this?