Courseiva

CCNA Security and Risk Management Questions

70 questions · Security and Risk Management · All types, answers revealed

1
MCQmedium

A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?

A.IT general controls for financial systems
B.Encryption of data at rest
C.Breach notification procedures
D.Privacy of customer data
AnswerA

The Sarbanes-Oxley Act (SOX) mandates that public companies establish and maintain internal controls over financial reporting. IT General Controls (ITGC) are foundational to this, ensuring the integrity, reliability, and security of the information systems that process financial data. These controls, encompassing areas like access management, change management, and operations, directly support the accuracy of financial statements, which is a core requirement of SOX Sections 302 and 404. Without robust ITGC, the reliability of financial data cannot be assured.

Why this answer

SOX requires publicly traded companies to establish and maintain internal controls over financial reporting. IT general controls (ITGC) are critical for ensuring the integrity of financial systems.

2
MCQmedium

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

A.Restrict physical access to cardholder data
B.Encrypt transmission of cardholder data over open networks
C.Install and maintain a firewall configuration
D.Protect stored cardholder data
AnswerD

Protecting stored cardholder data is precisely what PCI DSS Requirement 3 mandates, making this the correct answer. This requirement specifically addresses data at rest, compelling organizations to render cardholder data unreadable through methods such as strong encryption, truncation, masking, or tokenization when it is stored on systems, databases, or other media, thereby minimizing its value if a breach occurs.

Why this answer

PCI DSS Requirement 3 is to protect stored cardholder data, often through encryption or tokenization.

3
MCQeasy

Which component of the CIA triad ensures that information is not disclosed to unauthorized individuals, entities, or processes?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality is the core principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. It involves protecting sensitive data from being viewed or accessed by those without the proper clearance or need-to-know. Encryption, access controls, and proper data handling policies are primary mechanisms used to uphold confidentiality, directly addressing the prevention of unauthorized disclosure.

Why this answer

Confidentiality ensures that information is accessible only to those authorized. Integrity ensures accuracy and completeness, and availability ensures timely access.

4
MCQmedium

During a business impact analysis (BIA), which metric represents the maximum amount of time a business process can be disrupted before causing significant harm to the organization?

A.Work Recovery Time (WRT)
B.Recovery Point Objective (RPO)
C.Maximum Tolerable Period of Disruption (MTPD)
D.Recovery Time Objective (RTO)
AnswerC

The Maximum Tolerable Period of Disruption (MTPD), also known as Maximum Tolerable Downtime (MTD), is the absolute longest period a business process or function can be inoperative before experiencing unacceptable consequences. This critical metric, determined during a Business Impact Analysis (BIA), establishes the ultimate deadline for recovery, guiding the prioritization of resources and recovery strategies to prevent severe organizational harm.

Why this answer

Maximum Tolerable Period of Disruption (MTPD) or Maximum Tolerable Downtime (MTD) is the longest time a process can be unavailable before causing severe damage. RTO is the recovery time objective, RPO is recovery point objective, and WRT is work recovery time.

5
MCQhard

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

A.A memorandum of understanding (MOU)
B.A data processing agreement under GDPR
C.A consent form from each patient
D.A business associate agreement (BAA)
AnswerD

A Business Associate Agreement (BAA) is a legally mandated contract under HIPAA that must be established between a covered entity and its business associates before Protected Health Information (PHI) is shared. This agreement obligates the business associate to implement specific administrative, physical, and technical safeguards to protect PHI, adhering to the HIPAA Security and Privacy Rules. The BAA ensures accountability and extends the covered entity's compliance responsibilities to third parties handling PHI on its behalf, making it the correct and essential mechanism for such sharing.

Why this answer

HIPAA requires covered entities to have a business associate agreement (BAA) with any third party that will handle PHI on their behalf. The BAA ensures the business associate will safeguard the PHI.

6
MCQeasy

Which document is mandatory, high-level, and sets the direction for security within an organization?

A.Policy
B.Standard
C.Procedure
D.Baseline
AnswerA

A policy is a mandatory, high-level statement approved by management, articulating the organization's strategic intent and overarching requirements for information security. It establishes the fundamental rules and direction for protecting assets, often driven by legal, regulatory, or business imperatives, without specifying technical details. Policies are foundational, setting the broad scope and purpose of security efforts across the enterprise.

Why this answer

A security policy is a high-level, mandatory document that establishes the overall security direction and principles. Standards, baselines, guidelines, and procedures are more detailed.

7
MCQhard

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

A.$7,500
B.$30,000
C.$15,000
D.$75,000
AnswerA

This value correctly represents the Annualized Loss Expectancy (ALE), which is a key metric in quantitative risk analysis. It is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Assuming an SLE of $15,000 and an ARO of 0.5 (meaning the event is expected to occur once every two years), the ALE is $15,000 * 0.5 = $7,500. This figure quantifies the expected financial loss from a specific risk over a one-year period, informing cost-benefit analyses for security controls.

Why this answer

ALE = SLE * ARO = $15,000 * 0.5 = $7,500.

8
Multi-Selectmedium

Which TWO of the following are lawful bases for processing personal data under the GDPR? (Select two)

Select 2 answers
A.Data subject's employment status
B.Data subject's nationality
C.Consent of the data subject
D.Legitimate interests of the controller
E.Profit maximization
AnswersC, D

Consent is a fundamental lawful basis where the data subject explicitly and unambiguously agrees to the processing of their personal data for a specific purpose. For consent to be valid, it must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, often requiring a clear affirmative action. This places control directly with the individual.

Why this answer

Consent and legitimate interests are two of the lawful bases under Article 6 of the GDPR.

9
Multi-Selectmedium

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

Select 3 answers
A.Critical business processes
B.Maximum tolerable downtime (MTD)
C.Preferred vendor contracts
D.Recovery point objective (RPO)
E.Employee performance metrics
AnswersA, B, D

The primary objective of a Business Impact Analysis (BIA) is to identify and prioritize the organization's critical business processes. By distinguishing core operations from non-essential ones, the BIA allows planners to allocate recovery resources effectively and establish realistic recovery timelines. Without this inventory, the BCP cannot target the most vital survival functions of the enterprise.

Why this answer

During BIA, critical processes are identified, and metrics such as MTD (maximum tolerable downtime) and RPO (recovery point objective) are determined. Vendor contracts are not part of BIA; they are part of procurement or vendor management.

10
MCQhard

A company's disaster recovery plan includes an agreement with another company to provide backup computing facilities in case of a disaster. The agreement allows the second company to use the facilities for its own operations if needed. This arrangement is best described as:

A.Hot site
B.Warm site
C.Cold site
D.Reciprocal agreement
AnswerD

A reciprocal agreement is a mutual arrangement between two organizations, often competitors or peers, to provide each other with backup facilities, equipment, or resources in the event of a disaster. This type of agreement directly addresses the concept of 'an agreement with' another entity to ensure business continuity, leveraging shared risk and resources rather than dedicated, pre-built recovery sites.

Why this answer

A reciprocal agreement is an arrangement between two organizations to provide backup facilities to each other, but it may be unreliable if both need the resources simultaneously.

11
MCQeasy

Which of the following is the correct order of the ISC2 Code of Ethics canons from highest to lowest priority?

A.Protect society, act honorably, provide diligent service, advance the profession
B.Act honorably, protect society, provide diligent service, advance the profession
C.Advance the profession, protect society, act honorably, provide diligent service
D.Provide diligent service, advance the profession, protect society, act honorably
AnswerA

This sequence precisely matches the four canons of the (ISC)² Code of Ethics, which are hierarchically ordered to guide cybersecurity professionals. The primary responsibility is to protect society, followed by acting honorably, providing diligent service to principals, and finally advancing the profession. This specific order reflects the increasing scope of responsibility, from global impact to individual professional growth, making it the correct representation of the ethical framework.

Why this answer

The ISC2 Code of Ethics canons are, in priority order: Protect society, the common good, and the public trust; Act honorably, honestly, and justly; Provide diligent and competent service to principals; and Advance and protect the profession.

12
Multi-Selecthard

Under GDPR, which TWO of the following are valid lawful bases for processing personal data?

Select 2 answers
A.Data subject's employment
B.Data processor's request
C.Consent
D.Legitimate interest
E.Data controller's profit
AnswersC, D

Consent is a valid lawful basis under GDPR Article 6(1)(a) when the data subject has given their explicit agreement to the processing of their personal data for one or more specific purposes. For consent to be valid, it must be freely given, specific, informed, and unambiguous, signified by a clear affirmative action. Furthermore, the data subject must be able to withdraw their consent as easily as they gave it, and the controller must be able to demonstrate that consent was obtained.

Why this answer

GDPR Article 6 lists lawful bases including consent, contract, legal obligation, vital interests, public task, and legitimate interests.

13
MCQmedium

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

A.Provide diligent and competent service to principals
B.Act honorably, honestly, justly, responsibly, and legally
C.Protect society, the common good, and the infrastructure
D.Advance and protect the profession
AnswerC

This is the correct answer because it represents the first and highest priority canon in the (ISC)² Code of Ethics. It mandates that certified professionals prioritize the safety, welfare, and security of the public, critical systems, and shared resources above all other considerations. This overarching responsibility ensures that individual or organizational interests never compromise the broader societal well-being or the integrity of essential information technology infrastructure.

Why this answer

The first canon is to protect society, the common good, and the public trust. It is the highest priority.

14
MCQmedium

A security manager is calculating the annual loss expectancy (ALE) for a server valued at $50,000. The exposure factor (EF) is 40%, and the annual rate of occurrence (ARO) is 0.5. What is the ALE?

A.$10,000
B.$100,000
C.$25,000
D.$20,000
AnswerA

This option correctly calculates the Annual Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Subsequently, multiplying this SLE by the ARO (0.5) yields the correct ALE of $10,000, representing the expected financial loss from this specific risk over a year.

Why this answer

SLE = AV x EF = $50,000 x 0.4 = $20,000. ALE = SLE x ARO = $20,000 x 0.5 = $10,000.

15
MCQmedium

An organization is implementing a new access control system. The security team wants to ensure that users cannot deny having performed an action. Which security principle is being addressed?

A.Availability
B.Integrity
C.Confidentiality
D.Non-repudiation
AnswerD

Non-repudiation provides irrefutable proof that a specific action or event has occurred and that a particular entity was responsible for it, preventing them from later denying their involvement. This is typically achieved through robust audit trails, digital signatures, and secure logging mechanisms that cryptographically link an action to a user. Therefore, it directly addresses the requirement to prevent users from disclaiming responsibility for their actions within an access control system.

Why this answer

Non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message. In access control, this is often achieved through audit logs and digital signatures.

16
MCQeasy

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

A.$10,000
B.$100,000
C.$50,000
D.$20,000
AnswerA

This value represents the Annualized Loss Expectancy (ALE), which is derived by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $50,000 and an ARO of 0.2 (meaning a 20% chance of the event occurring annually), the correct ALE calculation is $50,000 * 0.2, resulting in $10,000. This figure quantifies the expected financial loss from a specific risk over a one-year period.

Why this answer

SLE = AV * EF = $100,000 * 0.5 = $50,000. ALE = SLE * ARO = $50,000 * 0.2 = $10,000.

17
MCQeasy

Which of the following is an example of a security policy?

A.Step 1: Log in, Step 2: Enter code, Step 3: Access system
B.It is recommended to change passwords every 90 days
C.All employees must use multi-factor authentication
D.Use passwords of at least 12 characters with mixed case and numbers
AnswerC

A security policy is a high-level, mandatory statement issued by management that defines the organization's overall security objectives and requirements. This statement clearly dictates a non-negotiable requirement for all employees, establishing a foundational security control to protect organizational assets. It addresses *what* is required for security, without specifying the technical implementation details.

Why this answer

A policy is a high-level mandatory statement that reflects management's intent. 'All employees must use multi-factor authentication' is a mandatory directive.

18
MCQmedium

Under GDPR, which of the following is a valid lawful basis for processing personal data?

A.Corporate policy
B.Profit motive
C.Marketing preference
D.Vital interests
AnswerD

Vital interests is a lawful basis under GDPR Article 6(1)(d) that permits the processing of personal data when it is necessary to protect the life of the data subject or another natural person. This basis is typically invoked in emergency situations where obtaining consent is impossible or impractical, such as medical emergencies, humanitarian crises, or public health threats. It represents a very high threshold and is generally reserved for situations involving a serious threat to life or physical integrity, making it a basis of last resort rather than routine processing.

Why this answer

GDPR Article 6 lists lawful bases including consent, contract, legal obligation, vital interests, public task, and legitimate interests. 'Vital interests' is a valid basis.

19
MCQmedium

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

A.High risk
B.Medium risk
C.Low risk
D.De minimis risk
AnswerA

In a qualitative risk assessment, "High risk" is assigned when both the likelihood of a threat event occurring and the potential impact of that event on organizational assets or operations are rated as high or critical. This combination signifies a significant exposure that demands immediate attention and substantial resource allocation for mitigation, as the potential for severe damage is both probable and substantial.

Why this answer

In a typical 5x5 risk matrix, high likelihood and critical impact place the risk in the 'High' or 'Extreme' risk category, requiring immediate action.

20
MCQeasy

Which component of the AAA framework is responsible for determining what resources a user can access and what actions they can perform?

A.Auditing
B.Authentication
C.Accounting
D.Authorization
AnswerD

Authorization is the critical component of the AAA framework responsible for determining what actions an authenticated user or system is permitted to perform on a resource. After identity verification, authorization mechanisms consult policies and access control lists (ACLs) to decide "what you are allowed to do," granting or denying specific privileges based on the user's role, group membership, or other attributes. This directly addresses the question of defining permissions.

Why this answer

AAA stands for Authentication, Authorization, and Accounting. Authorization is the process of granting or denying access to resources based on policies.

21
MCQmedium

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

A.Warm site
B.Cold site
C.Hot site
D.Reciprocal agreement
AnswerC

A hot site is a fully operational, mirrored facility that replicates the primary production environment with identical hardware, software, and up-to-date data, often synchronized in real-time. This comprehensive setup allows for immediate failover in the event of a disaster, ensuring minimal data loss and near-zero downtime. A hot site achieves the lowest Recovery Time Objective (RTO) and Recovery Point Objective (RPO), making it the optimal choice for critical applications requiring continuous availability and rapid business continuity.

Why this answer

A hot site is fully configured with hardware, software, and real-time data synchronization, minimizing RTO and RPO.

22
MCQhard

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

A.Avoid
B.Mitigate
C.Transfer
D.Accept
AnswerD

Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.

Why this answer

When the cost of mitigation exceeds the potential loss, accepting the risk is the most cost-effective response.

23
MCQmedium

An organization is implementing a BCP. After completing the BIA, which of the following is the next logical step in the planning process?

A.Develop recovery strategies
B.Test the plan
C.Conduct a risk assessment
D.Train personnel
AnswerA

Developing recovery strategies is the direct and logical next step after completing a Business Impact Analysis (BIA). The BIA identifies critical business functions, their Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs), essentially defining *what* needs to be recovered and *how quickly*. Based on these findings, the organization then determines the *how* by selecting and designing appropriate recovery strategies, such as hot sites, warm sites, or reciprocal agreements, to meet those defined objectives.

Why this answer

After the BIA identifies critical processes and recovery requirements, the next step is to develop strategies to meet those requirements, such as selecting recovery sites and technologies.

24
MCQmedium

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

A.Work Recovery Time (WRT)
B.Maximum Tolerable Period of Disruption (MTPD)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerB

The Maximum Tolerable Period of Disruption (MTPD) represents the absolute longest time a business process or function can be inoperative before the organization experiences unacceptable consequences, such as significant financial loss, regulatory penalties, or irreparable reputational damage. It is a critical business-driven metric established during the BIA, defining the ultimate threshold for downtime that the business can endure without suffering severe harm. All recovery objectives, including RTO, must be set to ensure MTPD is not exceeded.

Why this answer

Maximum Tolerable Period of Disruption (MTPD) is the longest time a process can be disrupted before recovery is required.

25
MCQmedium

A company is implementing a risk management program. They have identified a critical server with an asset value of $50,000. The exposure factor due to a potential threat is 40%, and the annual rate of occurrence is 2. What is the Annualized Loss Expectancy (ALE)?

A.$50,000
B.$40,000
C.$20,000
D.$100,000
AnswerB

This option correctly calculates the Annualized Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Multiplying this SLE by the ARO of 2 yields an ALE of $40,000, representing the expected financial loss from this specific risk over a year.

Why this answer

ALE = ARO × SLE; SLE = AV × EF = $50,000 × 0.4 = $20,000; ALE = 2 × $20,000 = $40,000.

26
MCQmedium

Which of the following is the correct order of priority for the ISC2 Code of Ethics Canons?

A.Advance the profession, protect society, act honorably, provide diligent service
B.Protect society, act honorably, provide diligent service, advance the profession
C.Provide diligent service, protect society, act honorably, advance the profession
D.Act honorably, provide diligent service, protect society, advance the profession
AnswerB

This sequence accurately represents the correct hierarchical order of the (ISC)² Code of Ethics Canons. "Protect Society, the Commonwealth, and the Infrastructure" is the foundational and highest-priority canon, followed by "Act honorably, honestly, justly, responsibly, and legally," then "Provide diligent and competent service to principals and the profession," and finally, "Advance and protect the profession."

Why this answer

The canons in order: 1. Protect society, the common good, and the public trust. 2. Act honorably, honestly, justly, responsibly, and legally. 3.

Provide diligent and competent service to principals. 4. Advance and protect the profession.

27
MCQhard

A company uses a qualitative risk analysis matrix where likelihood ranges from 1 to 5 and impact ranges from 1 to 5. A risk with a likelihood of 4 and an impact of 5 would fall into which risk level if the matrix defines high risk as scores above 15, medium as 10-15, and low as below 10?

A.Medium
B.Critical
C.High
D.Low
AnswerC

According to the company's qualitative risk analysis matrix, a risk score of 20 exceeds the established threshold of 15, which delineates the boundary for 'High' risk. This indicates that any risk with a numerical assessment equal to or greater than 15 is categorized into the 'High' severity level. Consequently, a score of 20 directly and correctly maps to a 'High' risk classification within this framework.

Why this answer

In qualitative risk analysis using a 5x5 matrix, the score is typically the product of likelihood and impact. 4 x 5 = 20, which is above 15, indicating high risk.

28
MCQeasy

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

A.Authentication, Authorization, Accounting
B.Authorization, Authentication, Accounting
C.Authentication, Accounting, Authorization
D.Accounting, Authentication, Authorization
AnswerA

This sequence correctly represents the foundational AAA framework. Authentication verifies the user's identity, establishing 'who you are.' Subsequently, Authorization determines the specific resources or actions the authenticated user is permitted to access, defining 'what you can do.' Finally, Accounting meticulously logs all user activities and resource consumption, providing a record of 'what you did' for auditing and accountability.

Why this answer

The AAA framework stands for Authentication, Authorization, and Accounting, in that order. First, a user's identity is verified, then permissions are checked, and finally activities are logged.

29
MCQeasy

Which document provides detailed step-by-step instructions for performing a specific security task?

A.Policy
B.Procedure
C.Standard
D.Guideline
AnswerB

A procedure is a mandatory, detailed set of step-by-step instructions that describes *how* to perform a specific task or process consistently and securely. It outlines the exact actions to be taken, the order in which they should occur, and often specifies roles, responsibilities, and tools required. Procedures ensure uniformity, repeatability, and compliance with established policies and standards, directly addressing the need for explicit operational guidance for security functions.

Why this answer

A procedure is a detailed, step-by-step document that describes how to perform a task.

30
MCQhard

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

A.To transfer ownership of PHI to the business associate
B.To authorize the use of PHI for marketing purposes
C.To require the business associate to comply with HIPAA Privacy and Security Rules
D.To allow the business associate to disclose PHI to any third party
AnswerC

The primary purpose of a Business Associate Agreement (BAA) is to contractually obligate the business associate to comply with the applicable provisions of the HIPAA Privacy and Security Rules. This legally binding agreement ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect Protected Health Information (PHI), reports breaches, and limits PHI use and disclosure to only what is necessary for the services provided, thereby extending the chain of trust.

Why this answer

A BAA ensures that business associates handling PHI will appropriately safeguard the information.

31
MCQhard

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

A.Annual audit report
B.Business Associate Agreement
C.Patient consent
D.Data Protection Impact Assessment
AnswerB

A Business Associate Agreement (BAA) is a legally required contract under HIPAA that must be in place before a Covered Entity (like a hospital) shares Protected Health Information (PHI) with a Business Associate (like a billing company). This agreement outlines the permissible uses and disclosures of PHI by the Business Associate and mandates their compliance with HIPAA's Security and Privacy Rules, ensuring appropriate safeguards are maintained. It establishes the responsibilities and liabilities of both parties regarding PHI protection.

Why this answer

Under HIPAA, covered entities must have a Business Associate Agreement (BAA) with business associates that handle PHI.

32
Multi-Selectmedium

A security manager is choosing a risk response for a high-impact, high-likelihood risk. Which TWO responses are most appropriate? (Select TWO)

Select 2 answers
A.Risk mitigation
B.Risk research
C.Risk avoidance
D.Risk acceptance
E.Risk deferral
AnswersA, C

Risk mitigation involves implementing specific security controls and countermeasures to actively reduce the likelihood of a risk occurring or to lessen its potential impact. For a high-impact risk, this means taking proactive steps, such as strengthening defenses, improving processes, or deploying new technologies, to bring the risk level down to an acceptable threshold. It is a primary and responsible strategy when the activity causing the risk cannot be avoided.

Why this answer

For high-impact, high-likelihood risks, avoidance (eliminating the activity) or mitigation (reducing impact/likelihood) are common. Transfer (insurance) may also be used but is less comprehensive. Acceptance is for low risks.

33
MCQeasy

Under the ISC2 Code of Ethics, which canon has the highest priority?

A.Advance the profession
B.Provide diligent service
C.Act honorably
D.Protect society
AnswerD

The canon to "Protect society, the common good, necessary public trust and confidence, and the infrastructure" is unequivocally the first and highest priority within the (ISC)² Code of Ethics. This principle mandates that all cybersecurity professionals prioritize the safety, welfare, and security of the public above all other considerations. It encompasses safeguarding critical infrastructure, protecting sensitive data, and ensuring the reliability of information systems, establishing a clear ethical imperative that supersedes individual, organizational, or professional interests.

Why this answer

The ISC2 Code of Ethics lists canons in order: Protect society, Act honourably, Provide diligent service, Advance the profession.

34
MCQeasy

Which type of risk remains after management has implemented controls to mitigate the identified risks?

A.Acceptable risk
B.Control risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is the specific level of risk that persists within an organization or system even after all planned and implemented risk mitigation strategies, controls, and countermeasures have been applied. It represents the remaining exposure that management has either consciously accepted or has been unable to further reduce through cost-effective means. This is the risk an organization must live with, requiring continuous monitoring and potential future reassessment.

Why this answer

Residual risk is the risk that remains after controls are applied. Inherent risk is the risk before controls.

35
MCQmedium

In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?

A.Low
B.Medium
C.High
D.Critical
AnswerC

A risk score of 20, calculated as the product of a high likelihood (e.g., 4 on a 5-point scale) and a very high impact (e.g., 5 on a 5-point scale), correctly places the risk in the "High" category. In a qualitative risk matrix, the "High" range typically encompasses scores from approximately 15 to 25, signifying a significant probability of occurrence combined with substantial potential negative consequences that demand immediate attention and mitigation strategies.

Why this answer

Likelihood × Impact = 4 × 5 = 20, which falls in the high range (15-25).

36
MCQhard

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

A.72 hours
B.24 hours
C.48 hours
D.7 days
AnswerA

Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.

Why this answer

GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms.

37
MCQeasy

According to the ISC2 Code of Ethics, which of the following canons has the highest priority when resolving an ethical dilemma?

A.Act honorably and lawfully
B.Provide diligent and competent service
C.Advance and protect the profession
D.Protect society, the common good, and the public trust
AnswerD

"Protect society, the common good, and the public trust" is unequivocally the highest priority canon in the ISC2 Code of Ethics, serving as the foundational principle for all cybersecurity professionals. This canon mandates that all actions and decisions must prioritize the safety, welfare, and confidence of the public, ensuring that information systems and data are secured to prevent harm to individuals, organizations, and critical infrastructure. This overarching responsibility guides all other ethical considerations, making it the correct answer.

Why this answer

The ISC2 Code of Ethics canons are in order of priority: 1. Protect society, the common good, and the public trust; 2. Act honorably and lawfully; 3.

Provide diligent and competent service; 4. Advance and protect the profession. Therefore, option D is the highest priority canon.

38
MCQmedium

An organization wants to avoid a particular risk entirely by not engaging in the activity that creates the risk. Which risk response strategy is being used?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerA

Risk avoidance is a strategy where an organization eliminates a particular risk entirely by choosing not to engage in the activity or process that gives rise to it. This approach completely removes the potential for the risk event to occur, rather than merely reducing its likelihood or impact. It is typically employed when the potential consequences of a risk are deemed unacceptable and cannot be effectively managed through other means.

Why this answer

Risk avoidance involves eliminating the risk by not performing the activity that causes it. Transfer shifts risk to a third party, mitigate reduces impact/likelihood, and accept acknowledges the risk.

39
MCQeasy

An organization's security policy requires that all data at rest must be encrypted. Which security principle is primarily being addressed?

A.Integrity
B.Confidentiality
C.Availability
D.Non-repudiation
AnswerB

Encryption directly addresses confidentiality by transforming plaintext data into an unreadable ciphertext using a cryptographic algorithm and a secret key. This process ensures that even if unauthorized individuals gain access to the encrypted data, they cannot decipher its content without the correct decryption key. Consequently, encryption effectively prevents unauthorized disclosure of sensitive information, making it the primary control for upholding the confidentiality of data both at rest and in transit.

Why this answer

Encryption of data at rest protects against unauthorized access, thus ensuring confidentiality.

40
MCQhard

An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?

A.Low likelihood, low impact
B.Medium likelihood, medium impact
C.High likelihood, high impact
D.Control risk is not a defined term
AnswerB

After implementing security controls, the inherent risk (high likelihood, potentially high impact) is expected to be reduced to a more acceptable level. "Medium likelihood, medium impact" represents a plausible and common outcome of effective risk mitigation strategies, where controls successfully diminish the probability of the event occurring and/or lessen its potential consequences. This remaining risk, after controls are applied, is precisely what is defined as residual risk, indicating a successful but not absolute reduction from the initial state.

Why this answer

Residual risk is the remaining risk after controls are applied. In this case, it is the medium likelihood and medium impact risk.

41
MCQmedium

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

A.ISO/IEC 27001
B.NIST Cybersecurity Framework
C.COBIT 2019
D.ITIL
AnswerD

ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing best practices for IT service management (ITSM). It specifically guides organizations through the entire service lifecycle, encompassing Service Strategy, Design, Transition, Operation, and Continual Service Improvement, making it ideal for managing the full journey of IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) is a set of practices for IT service management that focuses on aligning IT services with business needs.

42
MCQmedium

Which of the following is a key requirement under the GDPR regarding personal data breaches?

A.Notify the supervisory authority within 72 hours
B.Conduct a privacy impact assessment within 30 days
C.Report the breach to law enforcement immediately
D.Notify affected individuals within 24 hours
AnswerA

GDPR Article 33 mandates that in the event of a personal data breach, the data controller must notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This notification is required unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification must include details such as the nature of the breach, categories of data subjects and records concerned, and the likely consequences.

Why this answer

GDPR Article 33 requires data controllers to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms.

43
Multi-Selecteasy

Which TWO of the following are examples of risk response strategies?

Select 2 answers
A.Risk acceptance
B.Risk analysis
C.Risk identification
D.Risk avoidance
E.Risk communication
AnswersA, D

Risk acceptance is a deliberate decision by an organization to acknowledge and bear the potential consequences of a specific risk, often when the cost or effort of implementing other response strategies outweighs the potential impact. This strategy is typically documented, and the organization may establish a contingency plan or simply monitor the risk without further action.

Why this answer

Risk avoidance eliminates the risk by not performing the activity that gives rise to it. Risk acceptance acknowledges the risk and makes a conscious decision to accept its potential consequences without additional mitigation, often because the cost of mitigation exceeds the potential impact.

44
Multi-Selecthard

A company is implementing PCI DSS compliance. Which THREE requirements are part of the PCI DSS? (Select THREE)

Select 3 answers
A.Use only approved encryption algorithms for stored data
B.Implement multi-factor authentication for all employees
C.Encrypt transmission of cardholder data across open, public networks
D.Restrict physical access to cardholder data
E.Install and maintain a firewall configuration to protect cardholder data
AnswersC, D, E

This option directly corresponds to PCI DSS Requirement 4: 'Encrypt transmission of cardholder data across open, public networks.' This foundational requirement mandates the use of strong cryptography and security protocols, such as TLS 1.2 or higher, to protect cardholder data during transit over untrusted networks, preventing interception and unauthorized disclosure. It is one of the 12 high-level requirements.

Why this answer

PCI DSS has 12 requirements including installing firewalls, encrypting cardholder data, and restricting physical access. Implementing MFA for all users is not a specific requirement (though it may be part of access control).

45
Multi-Selecthard

Under the GDPR, which THREE of the following are rights of data subjects? (Select THREE.)

Select 3 answers
A.Right to erasure (right to be forgotten)
B.Right to ignore processing
C.Right to sell data
D.Right to data portability
E.Right to access
AnswersA, D, E

This fundamental GDPR right allows data subjects to request the deletion or removal of their personal data without undue delay under specific circumstances. These conditions include when the data is no longer necessary for the purpose for which it was collected, when consent is withdrawn, or when the data has been unlawfully processed. However, this right is not absolute and can be overridden by legal obligations or public interest considerations.

Why this answer

GDPR grants data subjects rights including the right to access, right to erasure ('right to be forgotten'), and right to data portability. The right to sell data is not a GDPR right, and the right to ignore processing is not a formal right.

46
Multi-Selectmedium

Which TWO of the following are examples of non-repudiation controls? (Select two)

Select 2 answers
A.Firewall rules
B.Encryption of data at rest
C.Audit logs with timestamps
D.Digital signatures
E.Biometric authentication
AnswersC, D

Audit logs meticulously record system events, user activities, and changes, often including source IP, user ID, and a precise timestamp. When properly secured against tampering, these immutable records serve as irrefutable evidence of who performed what action and when, making it difficult for an individual to deny their involvement in a specific event. This comprehensive logging provides a verifiable trail for accountability.

Why this answer

Non-repudiation ensures that a party cannot deny an action. Digital signatures and audit logs with timestamps provide evidence of actions.

47
MCQhard

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

A.RTO = 15 minutes, RPO = 4 hours
B.RTO = 4 hours, RPO = 4 hours
C.RTO = 4 hours, RPO = 15 minutes
D.RTO = 15 minutes, RPO = 15 minutes
AnswerC

This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.

Why this answer

RTO (Recovery Time Objective) is the maximum acceptable downtime, here 4 hours. RPO (Recovery Point Objective) is the maximum acceptable data loss, here 15 minutes.

48
Multi-Selectmedium

A security officer is developing a risk management plan. Which TWO of the following are valid risk response strategies? (Select TWO.)

Select 2 answers
A.Transfer
B.Avoid
C.Accept
D.Ignore
E.Eliminate
AnswersA, C

Transfer is a valid risk response strategy where the risk is shifted to a third party, such as through insurance or outsourcing.

Why this answer

Valid risk response strategies include Transfer and Accept. Avoid is a standard strategy but is not listed as correct in this context because the question expects the two distinct options that are clearly valid among the given choices. Ignore and Eliminate are not standard risk response strategies.

49
MCQmedium

Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?

A.To determine the maximum acceptable outage for each process
B.To test the disaster recovery plan
C.To assign roles and responsibilities during a disaster
D.To select a hot site vendor
AnswerA

The primary goal of a Business Impact Analysis (BIA) is to systematically identify and quantify the potential impacts of business disruptions and, crucially, to determine the Maximum Acceptable Outage (MAO), also known as Maximum Tolerable Downtime (MTD), for each critical business process. This analysis establishes the absolute longest period a business function can be unavailable before suffering unacceptable consequences, thereby setting critical recovery time objectives (RTOs) that guide subsequent disaster recovery planning and resource allocation.

Why this answer

The BIA identifies critical business processes and their recovery requirements, such as RTO and RPO.

50
MCQmedium

Which of the following is a key difference between a policy and a guideline in information security governance?

A.Policies are created by IT, while guidelines are created by executives
B.Policies are technical, while guidelines are managerial
C.Policies are mandatory, while guidelines are recommended
D.Policies are static, while guidelines are updated frequently
AnswerC

This is the correct distinction. Policies are formal, high-level statements that mandate specific actions or behaviors, establishing compulsory rules that all relevant parties must adhere to, with non-compliance typically incurring disciplinary or legal consequences. In contrast, guidelines provide recommended best practices, suggestions, or advisory information designed to assist individuals in making informed decisions or performing tasks, but they are not strictly enforced. This fundamental difference in obligation and enforceability is key to their purpose within an organization's governance framework.

Why this answer

Policies are high-level, mandatory statements that define the organization's security posture. Guidelines are recommendations that suggest best practices but are not mandatory.

51
MCQeasy

Which of the following is the PRIMARY purpose of the confidentiality principle in the CIA triad?

A.Preventing unauthorized access to information
B.Ensuring data is accurate and complete
C.Ensuring that users are who they claim to be
D.Guaranteeing that systems are available when needed
AnswerA

Confidentiality's primary purpose is to safeguard sensitive information from unauthorized disclosure or access. This involves implementing controls such as encryption, robust access control mechanisms, and the principle of least privilege to ensure that only authorized individuals or systems can view or obtain specific data. Its core objective is to maintain the secrecy and privacy of information, preventing its exposure to those without a legitimate need-to-know.

Why this answer

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes.

52
MCQhard

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

A.A physical room where payment cards are stored
B.Any system that connects to the internet
C.Systems that store, process, or transmit cardholder data
D.A network segment that contains only point-of-sale devices
AnswerC

This statement precisely defines the Cardholder Data Environment (CDE) according to PCI DSS. It includes all system components, applications, and network devices that directly store, process, or transmit cardholder data, as well as any system that could impact the security of the CDE. This comprehensive definition ensures that all relevant assets handling sensitive payment information are brought under the stringent security controls mandated by the standard.

Why this answer

The CDE includes people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data. Segmentation is used to isolate the CDE from other networks.

53
Multi-Selectmedium

A security auditor is reviewing an organization's governance framework. Which TWO of the following are commonly used frameworks for IT governance and security management?

Select 2 answers
A.ISO/IEC 27001
B.PMBOK
C.TOGAF
D.COBIT 2019
E.Six Sigma
AnswersA, D

ISO/IEC 27001 is a globally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides security auditors with a structured, risk-based framework to evaluate an organization's overall security governance, risk management, and control objectives.

Why this answer

COBIT 2019 is a framework for IT governance and management. ISO/IEC 27001 is an international standard for information security management systems.

54
Multi-Selecthard

A company is recovering from a ransomware attack. Which THREE of the following are key considerations when restoring data from backups to ensure integrity and minimal downtime?

Select 3 answers
A.Ensure encryption keys for backups are available
B.Isolate the restored data from the production network until verified
C.Perform a test restoration to a separate environment
D.Validate the integrity of the backup data before restoration
E.Restore data directly to production servers to save time
AnswersB, C, D

After a ransomware attack, restored data might still contain dormant malware or vulnerabilities if the backup was taken post-infection or if the restoration process itself introduces risks. Isolating this data in a segregated environment, such as a sandbox or a quarantined network segment, allows for thorough scanning and integrity validation without jeopardizing the clean production environment. This crucial step prevents the potential re-spread of the original or new threats, ensuring a secure return to operations.

Why this answer

Isolating the restored data from production prevents reinfection. Validating backup integrity ensures clean data. Testing the restoration process ensures the backups work.

Encrypted backups require decryption keys.

55
MCQmedium

Which of the following is a key objective of a business impact analysis (BIA)?

A.Implement security controls
B.Identify vulnerabilities in the network
C.Test the disaster recovery plan
D.Determine the maximum tolerable downtime for critical processes
AnswerD

BIA focuses on determining recovery objectives.

Why this answer

BIA identifies critical business processes and their recovery requirements such as RTO, RPO, and maximum tolerable downtime.

56
MCQeasy

An organization is implementing a new governance framework to align IT with business goals. Which framework is specifically designed for IT service management?

A.ISO/IEC 27001
B.COBIT 2019
C.ITIL
D.NIST Cybersecurity Framework
AnswerC

ITIL (Information Technology Infrastructure Library) is the most appropriate choice as it provides a detailed, practical framework of best practices for IT service management (ITSM). It encompasses the entire service lifecycle, from strategy and design to transition, operation, and continual service improvement, ensuring that IT services are aligned with business needs and deliver value. ITIL's focus on service delivery, customer experience, and value co-creation makes it ideal for governing IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) provides best practices for IT service management.

57
MCQhard

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

A.Change management process for the financial system
B.Data encryption for customer PII
C.Firewall rule to block unauthorized traffic
D.Automated calculation of interest on loans
AnswerA

Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.

Why this answer

IT general controls (ITGC) include access controls, change management, backup and recovery, and computer operations. Change management ensures that changes to financial systems are authorized and tested.

58
MCQmedium

During a business impact analysis (BIA), the recovery point objective (RPO) for a critical database is determined to be 2 hours. What does this mean?

A.Data can be recovered from any point within the past 2 hours
B.The maximum tolerable downtime is 2 hours
C.Data backups must be taken at least every 2 hours
D.The database must be fully recovered within 2 hours of a disaster
AnswerC

A Recovery Point Objective (RPO) of 2 hours signifies that the organization can tolerate a maximum loss of 2 hours' worth of data. To achieve this objective, data backups or replication points must be created at intervals no longer than 2 hours. This ensures that, in the event of a system failure or disaster, the oldest data that might be lost would be from the last backup taken within that 2-hour window, thereby meeting the defined RPO.

Why this answer

RPO defines the maximum acceptable data loss measured in time. An RPO of 2 hours means that data can be lost up to the last 2 hours before the disruption.

59
MCQmedium

Which governance framework is specifically designed to help organizations manage and protect their information assets by providing a comprehensive set of controls based on a risk management approach?

A.ISO/IEC 27001
B.NIST Cybersecurity Framework
C.COBIT 2019
D.ITIL
AnswerA

ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Its primary purpose is to provide a systematic approach for organizations to manage and protect their sensitive information assets, ensuring their confidentiality, integrity, and availability. This framework is specifically designed to help organizations manage information security risks effectively and achieve certification.

Why this answer

ISO/IEC 27001 is an international standard for information security management systems (ISMS) that provides a risk-based approach to managing information security.

60
MCQmedium

A security analyst is evaluating the risk of a data breach in a healthcare organization. The asset value of the patient database is $500,000, and the exposure factor is 0.2. The annual rate of occurrence is estimated at 0.1. What is the annualized loss expectancy (ALE)?

A.$10,000
B.$5,000
C.$50,000
D.$100,000
AnswerA

This option correctly calculates the Annualized Loss Expectancy (ALE) using the formula ALE = SLE × ARO. With an Asset Value (AV) of $500,000 and an Exposure Factor (EF) of 0.20, the Single Loss Expectancy (SLE) is $100,000. Multiplying this SLE by the Annualized Rate of Occurrence (ARO) of 0.10 yields the correct annualized risk value of $10,000.

Why this answer

ALE = ARO × SLE, and SLE = AV × EF = $500,000 × 0.2 = $100,000. Then ALE = 0.1 × $100,000 = $10,000.

61
MCQmedium

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

A.Transfer
B.Accept
C.Avoid
D.Mitigate
AnswerA

Purchasing cyber insurance is a classic example of risk transfer. This strategy involves shifting the financial responsibility for potential losses, such as those arising from data breaches, ransomware attacks, or business interruption, to a third party—the insurance provider. While the underlying operational risk itself still exists, the financial impact on the company is significantly reduced, as the insurer assumes the cost of recovery, legal fees, and other covered damages. This allows the organization to mitigate the severe financial consequences of a cyber incident without eliminating the threat entirely.

Why this answer

Transfer involves shifting the risk to a third party, such as through insurance.

62
MCQhard

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

A.A cloud service provider hosting ePHI
B.A janitorial service that cleans the office
C.A government regulator conducting an audit
D.A patient requesting their medical records
AnswerA

A cloud service provider that hosts electronic Protected Health Information (ePHI) on behalf of a covered entity is unequivocally a Business Associate under HIPAA. By storing or processing ePHI, the CSP creates, receives, maintains, or transmits this data, making them directly subject to HIPAA's Security Rule and certain aspects of the Privacy Rule. A Business Associate Agreement (BAA) is mandatory to define their responsibilities and ensure appropriate safeguards are in place for the ePHI.

Why this answer

A BAA is required with a business associate, which is a person or entity that performs certain functions or activities involving the use or disclosure of PHI on behalf of a covered entity. A cloud service provider that stores ePHI is a business associate.

63
Multi-Selecthard

Which THREE of the following are key components of a disaster recovery plan for a hot site? (Select three)

Select 3 answers
A.Pre-installed servers and workstations
B.Empty space with power and cooling only
C.Real-time data replication from primary site
D.Network connectivity with bandwidth to support operations
E.Long lead time to activate (e.g., weeks)
AnswersA, C, D

A hot site's defining characteristic is its immediate operational readiness. This means all necessary computing hardware, including servers, storage, and end-user workstations, must be pre-installed, configured, and often pre-loaded with essential operating systems and applications. This readiness minimizes recovery time objectives (RTO) by eliminating the need for hardware procurement and setup during a crisis, allowing for rapid business resumption.

Why this answer

A hot site is fully equipped and ready to take over operations quickly, requiring real-time data synchronization, pre-installed hardware, and network connectivity.

64
MCQmedium

Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

Article 33(1) of the GDPR requires data controllers to notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This timeframe applies specifically when the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, ensuring prompt action to mitigate potential harm and facilitate regulatory oversight.

Why this answer

Article 33 of the GDPR requires notification within 72 hours of becoming aware of the breach.

65
MCQmedium

A security team is performing a quantitative risk analysis for a server valued at $100,000. The exposure factor is 0.4 and the annual rate of occurrence is 2. What is the annualized loss expectancy (ALE)?

A.$40,000
B.$200,000
C.$160,000
D.$80,000
AnswerD

This is the correct Annualized Loss Expectancy (ALE), derived from accurately applying the quantitative risk analysis formula. First, the Single Loss Expectancy (SLE) is calculated as the Asset Value ($100,000) multiplied by the Exposure Factor (0.4), yielding $40,000. This SLE is then correctly multiplied by the Annualized Rate of Occurrence (2) to determine the total expected financial loss over a year, which is $80,000.

Why this answer

SLE = AV × EF = $100,000 × 0.4 = $40,000. ALE = SLE × ARO = $40,000 × 2 = $80,000.

66
MCQmedium

An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?

A.GDPR
B.PCI DSS
C.SOX
D.HIPAA
AnswerA

The General Data Protection Regulation (GDPR) explicitly mandates that organizations report personal data breaches to the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This strict timeline applies unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It also requires notification to affected data subjects if the breach poses a high risk.

Why this answer

GDPR Article 33 requires data controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach.

67
Multi-Selectmedium

Which THREE of the following are valid risk response strategies?

Select 3 answers
A.Transfer
B.Eliminate
C.Avoid
D.Mitigate
E.Ignore
AnswersA, C, D

Risk transfer is a strategic approach where the financial liability or responsibility for a specific risk is contractually shifted to a third party. This does not eliminate the underlying risk event itself, but rather reallocates the potential financial impact or operational burden. Common methods include purchasing insurance policies, outsourcing functions to vendors who assume associated risks, or incorporating indemnification clauses into service level agreements, thereby protecting the organization from direct financial loss.

Why this answer

Common risk responses include Avoid, Transfer, Mitigate, and Accept.

68
MCQmedium

A company is implementing a hot site as a disaster recovery option. Which of the following best describes a hot site?

A.A facility with basic infrastructure but no equipment
B.A reciprocal agreement with another company to share space
C.A facility with some equipment but not fully operational
D.A facility that is fully configured and ready to operate within hours
AnswerD

A hot site is a fully operational and configured disaster recovery facility, mirroring the primary site with all necessary hardware, software, and up-to-date data. It is designed for immediate activation, allowing critical business operations to resume within hours or even minutes, minimizing downtime and data loss. This level of readiness is crucial for systems with very low recovery time objectives (RTOs).

Why this answer

A hot site is a fully equipped backup facility that is ready to take over operations immediately, including hardware, software, and data synchronization.

69
MCQmedium

An organization is implementing a new access control system. They want to ensure that users are who they claim to be, that actions can be traced to individuals, and that access rights are managed appropriately. Which framework encompasses all three of these goals?

A.COBIT 2019
B.AAA framework
C.CIA triad
D.ISO/IEC 27001
AnswerB

The AAA (Authentication, Authorization, and Accounting) framework is the fundamental model for implementing access control systems, directly addressing the core requirements for managing user access. Authentication verifies a user's identity, ensuring only legitimate entities can attempt access to resources. Authorization then determines what specific actions the authenticated user is permitted to perform, based on defined policies and privileges. Finally, Accounting tracks user activities and resource consumption, providing an essential audit trail for accountability, billing, and compliance purposes.

Why this answer

The AAA framework (Authentication, Authorization, and Accounting) covers identification/authentication, authorization (access rights), and accounting (audit trails for non-repudiation).

70
MCQeasy

Which of the following is the primary purpose of the CIA triad in information security?

A.To establish a framework for risk management
B.To ensure compliance with regulatory requirements
C.To balance security controls with usability
D.To define the core objectives of information security
AnswerD

The CIA triad fundamentally defines the three paramount objectives that information security strives to achieve: Confidentiality, Integrity, and Availability. This foundational model provides a universal language and framework for understanding, categorizing, and prioritizing security goals across all aspects of information systems and data protection.

Why this answer

The CIA triad—Confidentiality, Integrity, and Availability—provides a foundational model for developing security policies and ensuring that data is protected from unauthorized access, tampering, and downtime.

Ready to test yourself?

Try a timed practice session using only Security and Risk Management questions.