Risk Evaluation & Management Flashcards
7 cards from real SSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Evaluation & Management flashcards as text
A practitioner is reviewing a risk treatment plan and finds that the proposed control will reduce likelihood but NOT reduce consequence. What type of control is this?
Answer: A preventive control that reduces the probability of the threat event occurring
Controls that reduce likelihood are preventive—they make a threat event less likely without changing the severity if it does occur.
During a risk review, a practitioner notes that a previously accepted risk has materially changed due to a new regulatory requirement. What risk management principle does this illustrate?
Answer: Risk is dynamic and must be continuously monitored and reassessed as conditions change
Risk management must be iterative; any material change in context—such as new regulations—can alter the risk level and invalidate prior acceptance decisions.
An organization is applying a Monte Carlo simulation to model financial losses from security incidents. What is the PRIMARY advantage of this technique over a single-point ALE estimate?
Answer: It produces a range of probable outcomes with associated probabilities, capturing uncertainty better than a single estimate
Monte Carlo simulation runs thousands of scenarios with variable inputs, producing a probability distribution of losses that reflects real-world uncertainty better than a deterministic ALE.
Which of the following scenarios BEST illustrates the concept of 'risk aggregation'?
Answer: Multiple low-rated risks combine to create an enterprise-level risk that exceeds the organization's risk tolerance
Risk aggregation occurs when individually acceptable risks collectively create an unacceptable cumulative exposure—a common blind spot in siloed risk management.
A security practitioner is tasked with evaluating insider threat risk. Which data source would be MOST valuable for establishing a likelihood rating?
Answer: Historical internal incident records combined with industry benchmarking data on insider threat frequency
Insider threat likelihood is best estimated from the organization's own historical incidents supplemented by industry benchmarks that reflect comparable insider threat rates.
An organization's risk committee reviews a risk treatment proposal that will reduce residual risk from 'High' to 'Medium' but requires a $2 million investment. The asset's total value is $500,000. What concern should the committee raise?
Answer: The control cost exceeds the asset value, making the investment economically unjustifiable without additional justification
Spending $2 million to protect a $500,000 asset violates the cost-benefit principle; the control cost should not exceed the protected value without compelling justification.
In the context of risk communication, what does 'risk framing' refer to?
Answer: How the presentation of risk information shapes stakeholder perceptions and decisions about acceptable risk levels
Risk framing describes how presenting the same risk differently—as a gain versus a loss, or a percentage versus a frequency—can significantly influence stakeholder decisions.