ARM - Associate in Risk Management Cyber and Data Security Risk Questions and Answers — Questions and Answers
Question 1: A financial services firm discovers that an unauthorized third party accessed and potentially exfiltrated a database containing the names, addresses, and social security numbers of thousands of its customers. According to most U.S. state data breach notification laws, which of the following is the firm's most critical and immediate responsibility?
- Determining the financial impact on the firm.
- Notifying affected individuals, and potentially regulators, without unreasonable delay. (Correct answer)
- Launching a public relations campaign to manage reputational damage.
- Terminating the employees responsible for the security lapse.
Correct answer: Notifying affected individuals, and potentially regulators, without unreasonable delay.
All 50 states have data breach notification laws that require organizations to inform affected individuals when their personally identifiable information (PII) is compromised. The primary and most urgent obligation is to notify these individuals and, in many cases, state regulators or attorneys general, so they can take steps to protect themselves from identity theft or fraud. While other actions are important parts of incident response, notification is the key legal requirement.
Question 2: A risk manager is developing a strategy to mitigate the risk of a successful phishing attack. Which of the following is the MOST effective control measure to address the human element of this risk?
- Implementing an advanced email filtering system to block malicious emails.
- Purchasing a comprehensive cyber insurance policy.
- Conducting regular, mandatory security awareness training and phishing simulations for all employees. (Correct answer)
- Encrypting all sensitive data at rest and in transit.
Correct answer: Conducting regular, mandatory security awareness training and phishing simulations for all employees.
Phishing attacks primarily exploit human psychology to trick employees into divulging information or clicking malicious links. While technical controls like email filters and data encryption are essential layers of defense, the most direct and effective way to mitigate the human vulnerability is through ongoing training and realistic simulations. This educates employees to recognize and report suspicious attempts, turning a potential weakness into a line of defense.
Question 3: Which of the following best describes the primary purpose of network segmentation as a cyber risk control measure?
- To encrypt all data that travels between different parts of the network.
- To ensure all employees have access to the resources they need.
- To monitor all incoming and outgoing network traffic for viruses.
- To contain the impact of a breach by limiting an attacker's ability to move laterally across the network. (Correct answer)
Correct answer: To contain the impact of a breach by limiting an attacker's ability to move laterally across the network.
Network segmentation involves dividing a computer network into smaller, isolated subnetworks. Its main security benefit is that if one segment is compromised, the breach can be contained within that subnetwork, preventing the attacker from easily accessing other parts of the organization's systems and data. This limits the overall impact of a security incident.
Question 4: A manufacturing company relies on a third-party cloud provider to host its critical production and inventory management software. A vulnerability in the cloud provider's platform leads to a significant data breach, exposing the manufacturer's sensitive operational data. This scenario is a prime example of which type of cyber risk?
- Insider threat
- Operational risk
- Supply chain risk (Correct answer)
- Reputational risk
Correct answer: Supply chain risk
This is a classic example of supply chain risk, where a vulnerability in a third-party vendor or partner creates a risk for the primary organization. The company's security is dependent on the security of its supplier (the cloud provider). The breach originated with a third party in the company's supply chain, not from an internal employee or a direct failure of its own operational processes.
Question 5: According to the NIST Risk Management Framework (RMF), what is the first step an organization should take when managing information security risk?
- Select and implement security controls.
- Assess the effectiveness of existing controls.
- Authorize the information system for operation.
- Categorize the information and the system based on its criticality and sensitivity. (Correct answer)
Correct answer: Categorize the information and the system based on its criticality and sensitivity.
The NIST Risk Management Framework (RMF) is a structured process for managing security and privacy risk. The first step in this multi-step process is to 'Categorize' the system and the information it processes, stores, and transmits. This categorization helps determine the potential impact of a loss of confidentiality, integrity, and availability, which then informs all subsequent steps, such as selecting appropriate controls.
Question 6: An organization is implementing multi-factor authentication (MFA) as a security control. This measure is primarily designed to mitigate the risk associated with what common cyber threat?
- Distributed Denial-of-Service (DDoS) attacks
- Compromised credentials (Correct answer)
- Fileless malware
- Unpatched software vulnerabilities
Correct answer: Compromised credentials
Multi-factor authentication (MFA) requires a user to provide two or more verification factors to gain access to a resource. Its primary purpose is to add another layer of security beyond just a password. If a user's password (their credential) is stolen or compromised, MFA prevents an attacker from using it to gain unauthorized access because they would still need the second factor (e.g., a code from a mobile app).
A financial services firm discovers that an unauthorized third party accessed and potentially exfiltrated a database containing the names, addresses, and social security numbers of thousands of its customers.
According to most U.S. state data breach notification laws, which of the following is the firm's most critical and immediate responsibility?