TOC Cybersecurity & Risk Management 3 — Questions and Answers
Question 1: In a risk matrix, a threat with HIGH likelihood and LOW impact should be handled with which risk response strategy?
- Accept
- Transfer
- Monitor and mitigate (Correct answer)
- Avoid immediately
Correct answer: Monitor and mitigate
High-likelihood, low-impact risks should be actively monitored and mitigated to reduce their frequency while managing their limited consequences.
Question 2: Which principle dictates that employees should only have access to the systems and data necessary for their specific job functions?
- Defense in depth
- Least privilege (Correct answer)
- Zero trust
- Need to share
Correct answer: Least privilege
The principle of least privilege restricts user access rights to the minimum necessary to perform their job duties.
Question 3: An organization wants to ensure that no single employee can complete a sensitive HR transaction—such as a salary change—without a second approval. This control is called:
- Role-based access control
- Separation of duties (Correct answer)
- Time-based access control
- Mandatory vacation policy
Correct answer: Separation of duties
Separation of duties requires multiple individuals to complete sensitive transactions, reducing the risk of fraud or error.
Question 4: A talent consultant is helping redesign onboarding to include cybersecurity awareness training. Which training format has been shown to be MOST effective at changing employee behavior?
- Annual all-day classroom sessions
- Short, frequent, scenario-based micro-learning modules (Correct answer)
- Distributing printed security policy manuals
- One-time video training at hire
Correct answer: Short, frequent, scenario-based micro-learning modules
Short, frequent, scenario-based micro-learning is more effective at sustaining behavioral change than infrequent, lengthy training sessions.
Question 5: Which regulation specifically requires US healthcare organizations to protect employee and patient health information (PHI) through administrative, physical, and technical safeguards?
- SOX
- HIPAA (Correct answer)
- FERPA
- GDPR
Correct answer: HIPAA
HIPAA's Security Rule mandates administrative, physical, and technical safeguards to protect electronic protected health information (ePHI).
Question 6: During a talent optimization project, a consultant identifies that the client stores sensitive applicant background check data in unencrypted spreadsheets. This represents which type of risk?
- Reputational risk only
- Data at rest vulnerability (Correct answer)
- Physical security risk
- Network perimeter risk
Correct answer: Data at rest vulnerability
Unencrypted data at rest is a vulnerability that exposes sensitive information if storage media is accessed or stolen.
Question 7: A company experiences a breach where attackers accessed the ATS by exploiting a vulnerability in a third-party recruiting plugin. This is an example of which attack vector?
- Phishing attack
- Supply chain or third-party attack (Correct answer)
- Brute force attack
- Insider threat
Correct answer: Supply chain or third-party attack
Supply chain attacks exploit vulnerabilities in third-party vendors or software that has trusted access to the target organization's systems.
In a risk matrix, a threat with HIGH likelihood and LOW impact should be handled with which risk response strategy?