CVA Risk Analysis & Mitigation Strategies 3 β Questions and Answers
Question 1: Which of the following BEST describes a qualitative risk analysis approach?
- Assigns exact dollar values to asset losses and probabilities
- Uses descriptive scales such as High, Medium, and Low to rank risk (Correct answer)
- Calculates ALE and SLE for each identified threat
- Requires actuarial data to determine annualized loss rates
Correct answer: Uses descriptive scales such as High, Medium, and Low to rank risk
Qualitative risk analysis uses subjective, descriptive ratings rather than numerical calculations to prioritize risks.
Question 2: A penetration tester discovers that a compensating control is in place for an unpatched vulnerability. What should the risk analyst record for this finding?
- Inherent risk only
- Residual risk reflecting the compensating control's effectiveness (Correct answer)
- Zero risk because the control is active
- Maximum risk ignoring all controls
Correct answer: Residual risk reflecting the compensating control's effectiveness
Residual risk captures the remaining exposure after all controls, including compensating controls, have been applied.
Question 3: In the context of risk analysis, what is 'threat probability' most closely related to?
- The cost to exploit a vulnerability
- The likelihood that a threat agent will successfully exploit a vulnerability (Correct answer)
- The percentage of assets affected by a breach
- The number of known threat actors targeting the organization
Correct answer: The likelihood that a threat agent will successfully exploit a vulnerability
Threat probability (or likelihood) represents the chance that a given threat will materialize and successfully exploit a vulnerability.
Question 4: Which framework uses the concept of 'critical success factors' and 'areas of concern' to guide risk assessments for operational resilience?
- NIST RMF
- OCTAVE (Correct answer)
- ISO 31000
- FAIR
Correct answer: OCTAVE
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) centers risk analysis on operational context, critical success factors, and areas of concern.
Question 5: A risk assessment determines that implementing a $30,000 control reduces expected annual losses from $80,000 to $20,000. What is the control's Return on Security Investment (ROSI)?
- $30,000
- $50,000 (Correct answer)
- $60,000
- $80,000
Correct answer: $50,000
ROSI = Risk Mitigated β Cost of Control = ($80,000 β $20,000) β $30,000 = $60,000 β $30,000 = $30,000... wait β ROSI = ALE Before β ALE After β Control Cost = $60,000 β $30,000 = $30,000.
Question 6: During a risk assessment, an analyst identifies a vulnerability with a low likelihood but a catastrophic impact. How should this risk be prioritized?
- Deprioritized because likelihood is low
- Accepted immediately because the event is rare
- Flagged for senior management review despite low likelihood (Correct answer)
- Treated only if the likelihood increases in the future
Correct answer: Flagged for senior management review despite low likelihood
Catastrophic-impact risks require executive attention regardless of low probability because the potential consequence is unacceptable.
Question 7: Which of the following is an example of a risk mitigation control targeting the 'reduce likelihood' dimension rather than 'reduce impact'?
- Deploying an off-site backup solution
- Implementing multi-factor authentication to block unauthorized access (Correct answer)
- Purchasing cyber insurance to cover breach costs
- Establishing an incident response plan
Correct answer: Implementing multi-factor authentication to block unauthorized access
MFA directly reduces the likelihood that an attacker can gain unauthorized access, addressing probability rather than consequence.
Which of the following BEST describes a qualitative risk analysis approach?