← All SSP Flashcard Decks

Risk Evaluation & Management Flashcards

7 cards from real SSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Evaluation & Management flashcards as text
  1. A security manager is comparing two risk treatment options. Option A has an annualized loss expectancy (ALE) of $80,000 and costs $20,000 to implement. Option B has an ALE of $50,000 and costs $60,000 to implement. Which option provides better value?

    Answer: Option A, because the net benefit ($60,000 reduction) exceeds its cost by more

    Option A yields a net benefit of $60,000 (ALE reduction) minus $20,000 (cost) = $40,000 net benefit, while Option B yields $30,000 minus $60,000 = -$30,000 net loss.

  2. During a risk assessment, a practitioner discovers that a critical asset has no documented owner. What is the MOST significant consequence of this gap?

    Answer: No one is accountable for accepting, treating, or monitoring risk to that asset

    Without an asset owner, accountability for risk decisions—accept, treat, transfer, or avoid—is undefined, leaving the asset unmanaged.

  3. Which risk treatment strategy is being applied when an organization decides to discontinue a product line that carries unacceptable cybersecurity risk?

    Answer: Risk avoidance

    Risk avoidance eliminates the activity or condition that creates the risk, such as discontinuing a product line.

  4. A risk matrix uses likelihood and consequence axes. A threat rated 'possible' (3/5) with 'major' consequences (4/5) produces a risk score of 12. The organization's risk appetite threshold is 10. What action is required?

    Answer: The risk must be treated because it exceeds the risk appetite threshold

    A risk score of 12 exceeds the threshold of 10, so the organization's risk appetite requires a treatment plan.

  5. What is the primary purpose of a residual risk assessment conducted AFTER implementing security controls?

    Answer: To determine whether remaining risk falls within the organization's risk acceptance criteria

    Residual risk assessment verifies that the post-control risk level is acceptable relative to the organization's defined tolerance.

  6. A security practitioner is briefing senior leadership on risk. Which communication approach is MOST effective for a non-technical executive audience?

    Answer: Express risks in financial terms such as potential dollar losses and business impact

    Executives respond best to risk communicated as business impact—financial loss, reputational harm, or operational disruption—rather than technical metrics.

  7. Which of the following BEST describes the concept of 'inherent risk' in risk management?

    Answer: The level of risk that exists before any controls or countermeasures are applied

    Inherent risk is the raw or baseline risk level of a threat-asset combination with no controls in place.