SY0-601 Governance, Risk & Compliance 1 — Questions and Answers
Question 1: A company purchases cyber insurance to offset potential financial losses from a data breach. Which risk response strategy does this represent?
- Risk avoidance
- Risk transfer (Correct answer)
- Risk mitigation
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to a third party, such as through purchasing cyber insurance.
Question 2: An organization labels its most sensitive data as 'Confidential' and its public-facing data as 'Public.' What security concept is being applied?
- Data retention
- Data masking
- Data classification (Correct answer)
- Data sovereignty
Correct answer: Data classification
Data classification categorizes data based on its sensitivity level so that appropriate security controls can be applied.
Question 3: Which regulation requires organizations processing EU citizens' personal data to notify authorities of a breach within 72 hours and obtain explicit consent before collection?
- HIPAA
- PCI-DSS
- SOX
- GDPR (Correct answer)
Correct answer: GDPR
GDPR (General Data Protection Regulation) mandates 72-hour breach notification and explicit consent for processing EU citizens' personal data.
Question 4: During a Business Impact Analysis, which metric defines the maximum length of time a critical business function can be unavailable before causing unacceptable harm to the organization?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Recover (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the absolute outer limit of downtime before the impact becomes unacceptable to the business.
Question 5: A company's payroll system can tolerate losing no more than 4 hours of transaction data in the event of a disaster. Which metric does this describe?
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO)
- Mean Time Between Failures (MTBF)
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss, measured in time, that an organization can tolerate.
Question 6: Which function of the NIST Cybersecurity Framework focuses on developing organizational understanding of cybersecurity risks to systems, assets, and data?
- Protect
- Detect
- Identify (Correct answer)
- Respond
Correct answer: Identify
The NIST CSF 'Identify' function helps organizations understand their cybersecurity risk environment, including assets, data, and current governance practices.
Question 7: Which security policy document defines the rules employees must follow when using company-owned computers, networks, and internet access?
- Data Retention Policy
- Clean Desk Policy
- Acceptable Use Policy (AUP) (Correct answer)
- Non-Disclosure Agreement (NDA)
Correct answer: Acceptable Use Policy (AUP)
An Acceptable Use Policy (AUP) outlines permitted and prohibited uses of organizational IT resources to govern employee behavior.
A company purchases cyber insurance to offset potential financial losses from a data breach.
Which risk response strategy does this represent?