CVA Risk Analysis & Mitigation Strategies 2 — Questions and Answers
Question 1: A quantitative risk analysis assigns a probability of 0.3 to a threat event and an asset value of $500,000 with an exposure factor of 40%. What is the Annualized Loss Expectancy (ALE)?
- $60,000 (Correct answer)
- $150,000
- $200,000
- $500,000
Correct answer: $60,000
ALE = SLE × ARO = ($500,000 × 0.40) × 0.3 = $200,000 × 0.3 = $60,000.
Question 2: Which risk mitigation strategy involves outsourcing risk to a third party such as purchasing cyber liability insurance?
- Risk avoidance
- Risk transference (Correct answer)
- Risk acceptance
- Risk reduction
Correct answer: Risk transference
Risk transference shifts the financial consequence of a risk to another party, such as an insurance provider.
Question 3: During a risk assessment, a vulnerability is found with a CVSS base score of 9.8 but the asset has no internet exposure. Which factor most appropriately adjusts the effective risk?
- Asset value
- Threat likelihood
- Environmental score modifier (Correct answer)
- Confidentiality impact
Correct answer: Environmental score modifier
The CVSS Environmental score allows organizations to adjust the base score based on their specific deployment environment, including network exposure.
Question 4: A risk register entry shows a residual risk that exceeds the organization's risk appetite. What is the MOST appropriate next step?
- Accept the residual risk and document it
- Apply additional controls to further reduce risk (Correct answer)
- Eliminate the vulnerable asset entirely
- Transfer the risk to the development team
Correct answer: Apply additional controls to further reduce risk
When residual risk exceeds the defined risk appetite, additional controls must be implemented to bring risk within acceptable thresholds.
Question 5: What does the term 'risk appetite' describe in an organizational security context?
- The maximum financial loss an organization can absorb
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The threshold at which a vulnerability is considered critical
- The total cost of implementing security controls
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the level of risk an organization is willing to tolerate while pursuing its strategic goals.
Question 6: Which threat modeling methodology focuses on identifying security objectives, decomposing applications, identifying threats, and then ranking them?
- PASTA
- STRIDE
- DREAD (Correct answer)
- OCTAVE
Correct answer: DREAD
DREAD is a threat ranking model that scores threats on Damage, Reproducibility, Exploitability, Affected users, and Discoverability.
Question 7: An organization decides to discontinue a legacy application because the cost of patching exceeds the asset's value. Which risk response is being applied?
- Risk transference
- Risk reduction
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Discontinuing the application eliminates the risk entirely by removing the activity or asset that creates the risk, which is risk avoidance.
A quantitative risk analysis assigns a probability of 0.3 to a threat event and an asset value of $500,000 with an exposure factor of 40%.
What is the Annualized Loss Expectancy (ALE)?