Risk Evaluation & Management Flashcards
7 cards from real SSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Evaluation & Management flashcards as text
An organization uses the DELPHI technique during a risk assessment. What is the defining characteristic of this approach?
Answer: Experts provide anonymous, iterative estimates that are reconciled through successive rounds
The Delphi technique uses anonymous, iterative rounds of expert input to reach consensus while avoiding groupthink.
A quantitative risk analysis produces a probability distribution of possible losses. What does the 95th percentile value on this distribution represent?
Answer: There is a 5% chance that losses will exceed this value in a given period
The 95th percentile means there is a 5% probability that losses will exceed that threshold, commonly used to set worst-case planning budgets.
Which risk register field is MOST critical for tracking the effectiveness of a risk treatment plan over time?
Answer: Target risk rating and review date for post-treatment reassessment
A target risk rating with a scheduled review date allows practitioners to verify whether treatment reduced risk to the desired level.
An organization is deciding whether to self-insure or purchase third-party insurance for a specific risk. Which factor MOST strongly favors purchasing insurance?
Answer: The potential loss magnitude is catastrophic and would threaten organizational survival
Insurance is most valuable when a single loss event could be catastrophic, since self-insurance only makes sense when the organization can absorb the maximum likely loss.
A security practitioner performing a business impact analysis (BIA) identifies that a payroll system has a Recovery Time Objective (RTO) of 4 hours. What does this mean for risk management?
Answer: Any risk treatment must ensure the system can be restored within 4 hours of a disruption
An RTO of 4 hours means risk controls must support restoring the payroll system within that window to meet business continuity requirements.
What is the MAIN limitation of using historical incident data as the sole basis for threat likelihood estimates?
Answer: Historical data may not account for emerging threats or changes in the threat landscape
Past incidents reflect past conditions; new attack methods, technologies, or adversary capabilities not yet observed will be missed.
A risk practitioner assigns a risk a 'low' rating but the asset owner insists it should be 'high.' The disagreement stems from differing views on business impact. What is the BEST resolution process?
Answer: Escalate to a risk committee or senior authority who can adjudicate based on organizational priorities
Risk rating disputes should be escalated to a governance body or senior decision-maker who can weigh organizational priorities objectively.