Courseiva

CCNA Risk Identification, Monitoring, and Analysis Questions

16 of 91 questions · Page 2/2 · Risk Identification, Monitoring, and Analysis · Answers revealed

76
MCQhard

An organization uses a risk register to track identified risks. A risk owner reports that a mitigation control was implemented six months ago, but the residual risk rating has not been updated and no post-implementation review was performed. Which activity is MOST important for maintaining the integrity of the risk management process?

A.Transfer the risk to a third party through cyber insurance and remove the original mitigation control.
B.Escalate the risk to the board as an accepted risk without further analysis because the owner has already acted.
C.Close the risk entry because the mitigation control has been implemented and the risk is therefore eliminated.
D.Reassess the risk with the control in place, document the updated likelihood and impact, and adjust the residual risk rating accordingly.
AnswerD

Risk registers become unreliable when controls are recorded but their effect is never measured. Reassessing likelihood and impact with the control operating provides an evidence-based residual rating, confirms whether the treatment achieved its objective, and keeps decisions aligned with actual exposure. This is the core feedback loop of risk monitoring and analysis.

Why this answer

A risk register is only useful if it reflects current exposure. When a control is deployed, the risk must be reassessed to measure how much likelihood or impact it actually reduced, and the residual rating updated with evidence. This validation step closes the treatment loop and supports accurate reporting to management.

Exam trap

The trap here is treating implementation of a control as proof that the risk is resolved, skipping the reassessment that determines residual risk.

77
MCQeasy

A security team identifies a vulnerability in a web application that allows SQL injection. Which risk response strategy involves implementing input validation and parameterized queries to reduce the risk to an acceptable level?

A.Risk transfer
B.Risk mitigation
C.Risk acceptance
D.Risk avoidance
AnswerB

Input validation and parameterised queries remove the injection vector, so the SQL injection risk is reduced rather than transferred, avoided or accepted. Mitigation lowers likelihood or impact to a tolerable level, matching the stem's requirement to reduce risk to an acceptable level.

Why this answer

Risk mitigation involves applying controls to reduce the likelihood or impact of a risk to an acceptable level. Implementing input validation and parameterized queries directly addresses the SQL injection vulnerability by preventing malicious SQL from being executed, thereby reducing the risk without eliminating the application's functionality.

Exam trap

The SSCP exam often tests the distinction between risk mitigation (applying controls to reduce risk) and risk avoidance (eliminating the activity entirely), tricking candidates who think input validation removes the risk completely rather than reducing it to an acceptable level.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts the financial burden of a loss to a third party (e.g., insurance), not the technical control of the vulnerability. Option C is wrong because risk acceptance means acknowledging the risk without taking action, which contradicts the active implementation of security controls. Option D is wrong because risk avoidance would require removing the vulnerable web application entirely or disabling the feature that allows user input, which is not the same as applying input validation and parameterized queries.

78
Multi-Selectmedium

A security team is building a continuous monitoring program for a regulated environment. The compliance manager wants assurance that monitoring data is trustworthy and that deviations are detected promptly. Which THREE activities should be included in the monitoring program? (Choose three.)

Select 3 answers
A.Collecting and reviewing audit logs from critical systems on a defined schedule.
B.Reviewing the monitoring program's own controls and making improvements on a recurring cycle.
C.Archiving all monitoring data indefinitely without any review or analysis.
D.Establishing metrics and reporting thresholds that trigger escalation when exceeded.
E.Performing a full penetration test of every system on a weekly basis.
AnswersA, B, D

Scheduled collection and review of audit logs from critical systems is a core continuous monitoring activity because it provides evidence that controls are operating and reveals deviations such as failed logins, privilege changes, and configuration edits. Without a defined review cadence, logs accumulate unread and incidents go unnoticed. This activity directly supports both security detection and compliance evidence requirements.

Why this answer

Continuous monitoring depends on three reinforcing activities: scheduled collection and review of audit logs, defined metrics with escalation thresholds, and recurring evaluation of the program itself. Together they provide detection, measurable response criteria, and a feedback loop that keeps coverage current. Penetration testing is periodic validation rather than continuous monitoring, and indefinite archiving without analysis adds no detection capability.

Exam trap

The trap here is equating continuous monitoring with frequent one-time assessments such as penetration tests, or with simply storing data, rather than with ongoing review, measurement, and program improvement.

79
MCQmedium

A vulnerability scan identifies a critical flaw in a web server. The server is currently in production and cannot be patched immediately due to compatibility issues. The risk response chosen is to implement a web application firewall (WAF) rule to block exploitation attempts. This is an example of which risk response?

A.Risk acceptance
B.Risk avoidance
C.Risk transfer
D.Risk mitigation
AnswerD

Deploying a WAF rule reduces the likelihood or impact of exploitation while the underlying flaw remains unpatched, so the risk is lowered rather than transferred, avoided or accepted. This directly satisfies the stem's constraint that patching is blocked by production compatibility issues.

Why this answer

Implementing a WAF rule to block exploitation attempts reduces the likelihood or impact of the vulnerability without removing the flaw itself. This is a classic risk mitigation technique, as it applies a compensating control to lower residual risk while the server remains unpatched. Risk mitigation involves taking action to reduce risk to an acceptable level, which is exactly what deploying a WAF signature achieves.

Exam trap

ISC2 often tests the distinction between risk mitigation and risk avoidance, where candidates mistakenly think that blocking exploitation attempts 'avoids' the risk, but avoidance requires eliminating the vulnerability entirely (e.g., removing the server), not just reducing its exploitability.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action to reduce it, whereas a WAF rule is an active control. Option B is wrong because risk avoidance would require removing the vulnerable server from production or disabling the affected service entirely, not just blocking exploit attempts. Option C is wrong because risk transfer involves shifting the financial impact of a loss to a third party (e.g., insurance or outsourcing), not implementing a technical control like a WAF.

80
MCQmedium

A security analyst at a financial firm is reviewing the risk register and notes that the firm has purchased a cyber insurance policy to cover losses from a data breach. In risk management terms, which of the following best describes this action?

A.Risk transference
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerA

Risk transference shifts the financial impact of a risk to a third party, typically through insurance or contractual agreements. By purchasing cyber insurance, the firm transfers the monetary loss from a breach to the insurer while still retaining the operational and reputational risk. This matches the scenario precisely, as the firm is not reducing the likelihood but is offsetting the financial burden.

Why this answer

Risk transference is the correct classification because cyber insurance shifts the financial consequences of a data breach to an external insurer. The organization still owns the risk operationally, but the monetary impact is contractually borne by another party. This is a standard risk treatment option alongside avoidance, mitigation, and acceptance, and it is commonly used for low-frequency, high-impact events such as major data breaches.

Exam trap

The trap here is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply transferring the financial loss.

81
MCQhard

A security analyst is configuring a SIEM to detect data exfiltration. Which of the following correlation rules would best identify potential data exfiltration via DNS tunneling?

A.Correlate high outbound DNS query volume with requests to newly registered or suspicious domains
B.Correlate multiple failed logins from a single IP
C.Alert on any single failed login attempt
D.Alert when a user accesses a file share after hours
AnswerA

DNS tunnelling encodes stolen data within query names, producing abnormally high outbound query volumes directed at attacker-controlled domains. Correlating volume spikes with newly registered or suspicious domains satisfies the stem's detection goal by combining two weak indicators into a stronger signal, catching exfiltration that single-event rules would miss.

Why this answer

DNS tunneling encodes data in DNS queries and responses, often generating a high volume of outbound queries to domains that are newly registered or otherwise suspicious. Correlating these two indicators—unusual query volume and suspicious domain characteristics—directly targets the behavior of DNS tunneling, making it the most effective rule for detecting this exfiltration technique.

Exam trap

The trap here is that candidates often confuse general anomaly detection (like failed logins or after-hours access) with the specific network-layer indicators of DNS tunneling, failing to recognize that DNS tunneling is characterized by unusual DNS query patterns to suspicious domains, not by authentication or file access events.

How to eliminate wrong answers

Option B is wrong because multiple failed logins from a single IP indicate a brute-force or credential-stuffing attack, not data exfiltration via DNS tunneling. Option C is wrong because alerting on any single failed login attempt would generate excessive false positives and does not correlate with DNS tunneling behavior. Option D is wrong because after-hours file access may indicate insider threat or policy violation but is unrelated to the network-level anomaly of DNS tunneling.

82
Multi-Selecteasy

Which TWO of the following are examples of vulnerability sources? (Choose TWO.)

Select 1 answer
A.Environmental disaster
B.CVE entries
C.Intentional human attack
D.Hardware failure
E.Configuration weaknesses
AnswersE

Configuration weaknesses count as vulnerability sources because they are flaws introduced by insecure settings, defaults or hardening gaps rather than by software defects. They satisfy the stem's requirement for a source category, sitting alongside poor coding, design flaws and missing patches as an origin of exploitable weakness.

Why this answer

The SSCP exam distinguishes threat sources from vulnerability sources. A vulnerability source is the origin or category from which a weakness arises, such as configuration weaknesses or software flaws. CVE entries are a standardized reference/dictionary of publicly disclosed vulnerabilities, not a source category of vulnerabilities themselves.

Environmental disaster, intentional human attack, and hardware failure are threat sources or threat events, not vulnerability sources. Therefore the only valid vulnerability source among the options is Configuration weaknesses (E).

Exam trap

The SSCP exam tests the distinction between threat sources (e.g., natural disasters, human attacks, hardware failures) and vulnerability sources (e.g., software flaws, configuration weaknesses, architectural weaknesses). Candidates often incorrectly select threat events as vulnerability sources; note that CVE is a vulnerability reference/dictionary, not a vulnerability source category.

83
MCQmedium

A security operations center is deploying a network-based intrusion detection system. The team wants to detect attacks that span multiple packets and sessions, such as a slow port scan followed by exploitation attempts. Which detection method should the team prioritize to correlate these related events?

A.Stateful protocol analysis that tracks session state and compares activity against expected protocol behavior over time.
B.Signature matching against a database of known malicious byte patterns in individual packets.
C.Anomaly detection based solely on bandwidth utilization thresholds for each monitored network segment.
D.Statistical profiling of user login times to identify credential misuse across authentication servers.
AnswerA

Stateful protocol analysis maintains awareness of ongoing sessions and protocol state, allowing the IDS to recognize multi-packet and multi-session patterns such as a gradual scan preceding an exploit. It correlates events across time rather than judging each packet in isolation, which is essential for the described attack chain.

Why this answer

Detecting attacks that unfold across many packets and sessions requires the IDS to retain and reason about session state. Stateful protocol analysis tracks conversations against expected protocol behavior, enabling recognition of slow scans, evasive fragmentation, and follow-on exploitation that isolated packet inspection would miss. This makes it the appropriate priority for the described scenario.

Exam trap

The trap here is equating intrusion detection with signature matching alone, overlooking that multi-session attacks require stateful correlation.

84
MCQmedium

An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?

A.Maximum security with high operational impact
B.Equivalent to DISA STIGs
C.Only applicable to critical systems
D.Basic security hygiene with minimal impact
AnswerD

CIS Level 1 profiles apply settings intended as essential, low-risk hardening that can be deployed broadly with minimal disruption to functionality or performance. This matches the organisation's aim of implementing benchmarks across all Windows servers without breaking operational services.

Why this answer

CIS Benchmarks define Level 1 as a set of configuration settings intended to provide basic security hygiene with minimal impact on business operations. These settings are designed to be easily implemented without causing significant performance degradation or service disruption, making them suitable for most systems. Level 1 focuses on essential security controls that address common vulnerabilities while maintaining system usability.

Exam trap

The trap here is that candidates often confuse Level 1 with 'maximum security' or assume it is only for critical systems, when in fact Level 1 is the baseline recommended for all systems to achieve a practical security posture without disrupting operations.

How to eliminate wrong answers

Option A is wrong because Level 1 is not about maximum security; maximum security with high operational impact is characteristic of Level 2 settings, which may disable features or enforce stricter policies that can affect performance. Option B is wrong because CIS Benchmarks and DISA STIGs are separate frameworks; while they may overlap in some controls, STIGs are typically more restrictive and aligned with U.S. Department of Defense requirements, not equivalent to CIS Level 1.

Option C is wrong because Level 1 is explicitly designed for general-purpose systems, not only critical systems; critical systems often require Level 2 or additional custom hardening.

85
MCQhard

A company's security policy requires that all servers be hardened according to CIS Level 1 benchmarks. During an audit, it is discovered that a server has password complexity settings that exceed Level 1 requirements. Which of the following is the most appropriate action?

A.Report the non-compliance to management for remediation
B.Implement Level 2 benchmarks to be consistent
C.Immediately revert to Level 1 settings to ensure compliance
D.Document the deviation and accept the stronger configuration
AnswerD

Exceeding CIS Level 1 password complexity strengthens rather than weakens security, so the server still meets the benchmark's intent. The auditor should record the stronger setting as a documented deviation instead of forcing a downgrade to match the baseline exactly.

Why this answer

Exceeding CIS Level 1 password complexity requirements represents a stronger security posture, not a violation. CIS benchmarks define Level 1 as a minimum baseline of essential security controls, and deviations that improve security are acceptable as long as they are documented and formally accepted by management. The key principle is that compliance is measured against the minimum baseline, and stronger configurations are permitted with proper risk acceptance.

Exam trap

The trap here is that candidates mistakenly treat any deviation from a baseline as non-compliance, failing to recognize that exceeding the minimum requirements is acceptable and should be documented rather than reverted or escalated.

How to eliminate wrong answers

Option A is wrong because reporting non-compliance implies a violation, but exceeding Level 1 requirements is not a compliance failure—it is a stronger configuration that should be documented, not escalated as a finding. Option B is wrong because implementing Level 2 benchmarks is unnecessary and could introduce operational overhead or compatibility issues; the policy explicitly requires Level 1, and Level 2 is a separate, more restrictive set of controls not mandated here. Option C is wrong because immediately reverting to Level 1 settings would weaken security without justification, violating the principle of least privilege and potentially exposing the system to password-based attacks.

86
Multi-Selectmedium

Which TWO of the following are common techniques used in quantitative risk analysis?

Select 2 answers
A.Exposure Factor (EF)
B.Asset Value (AV)
C.Risk rating (High/Medium/Low)
D.Probability and impact matrix
E.Delphi technique
AnswersA, B

Exposure Factor quantifies the percentage of an asset's value lost in a single incident, feeding directly into SLE and ALE calculations. It is a numeric input, distinguishing quantitative analysis from qualitative techniques such as Delphi or scenario ranking.

Why this answer

Options A and B are correct because quantitative risk analysis relies on numeric monetary values: the Exposure Factor (EF) is the percentage of an asset's value that would be lost in a given incident, and the Asset Value (AV) is the monetary worth of the asset, both of which feed the Single Loss Expectancy (SLE = AV × EF) and Annualized Loss Expectancy (ALE = SLE × ARO) calculations. These are core measurable inputs that make the analysis truly quantitative. Options C, D, and E do not belong: a High/Medium/Low risk rating is qualitative, the probability and impact matrix is a qualitative technique that maps likelihood against consequence, and the Delphi technique is a qualitative expert-consensus method for estimating risk.

Exam trap

The SSCP exam often tests the distinction between qualitative and quantitative methods by listing qualitative tools (like risk ratings, probability-impact matrices, and Delphi) as distractors, expecting candidates to recognize that only metrics like EF, AV, SLE, and ALE are truly quantitative.

87
MCQeasy

During a risk assessment, a team identifies that a legacy inventory application has no vendor support and cannot be patched. Leadership decides to accept the risk because replacing the application would cost more than the potential loss. Which term best describes this decision?

A.Risk transference
B.Risk avoidance
C.Risk mitigation
D.Risk acceptance
AnswerD

Acceptance means the organization acknowledges the risk and chooses to proceed without additional mitigation because the cost of controls or replacement exceeds the expected loss. Leadership weighed the replacement cost against the potential loss and decided to retain the risk. Documenting this decision in the risk register, with a review date, is essential so the acceptance remains a conscious, accountable choice rather than neglect.

Why this answer

When leadership evaluates a risk and consciously decides to continue operating without adding controls because remediation costs outweigh expected losses, the decision is risk acceptance. This must be documented and periodically reviewed so it remains an informed choice. It differs from avoidance, which eliminates the activity, and from transference, which shifts financial impact to another party.

Exam trap

The trap here is confusing acceptance with doing nothing; acceptance is a documented, deliberate decision, while neglect is an unmanaged exposure.

88
MCQmedium

An organization wants to reduce the likelihood that a terminated employee's credentials can still be used to access SaaS applications after departure. Which control BEST addresses this risk?

A.Conduct quarterly access reviews of all SaaS application user lists.
B.Integrate the identity provider with HR systems so account deactivation is triggered automatically on termination.
C.Enforce a stronger password complexity policy for all user accounts.
D.Require multi-factor authentication for all SaaS application logins.
AnswerB

Automating deactivation through an identity provider linked to HR status removes the manual delay that lets terminated credentials remain valid. When the HR record changes, the identity provider disables the account and revokes active sessions across federated SaaS applications, which directly reduces the window of exposure. This is the most effective control because it addresses the root cause rather than the symptom.

Why this answer

The core risk is that terminated credentials remain usable because deprovisioning depends on manual steps. Linking the identity provider to authoritative HR data automates deactivation and session revocation the moment employment status changes, closing the gap at its source. Complexity policies, MFA, and periodic reviews each reduce some exposure but none prevents a known valid credential from being used after departure.

Exam trap

The trap here is choosing a preventive-sounding control such as MFA or complexity policy when the actual weakness is the delay in revoking credentials that the departing employee already possesses.

89
MCQmedium

After implementing a new IDS, the security team receives numerous alerts about legitimate traffic being flagged as malicious. This phenomenon is known as:

A.False positives
B.Noise
C.False negatives
D.True positives
AnswerA

Legitimate traffic flagged as malicious constitutes false positives: the IDS incorrectly classifies benign activity as an attack. This directly matches the stem's constraint of numerous alerts on genuine traffic, distinguishing it from false negatives, which would be malicious traffic mistakenly permitted. Tuning detection thresholds reduces these erroneous alerts.

Why this answer

A false positive occurs when the IDS incorrectly classifies legitimate traffic as malicious, generating an alert for benign activity. This is a common issue after deploying a new IDS with default or overly sensitive signature sets, leading to alert fatigue. The core reasoning is that the IDS's detection logic (e.g., pattern matching or anomaly thresholds) misidentifies normal behavior as an attack.

Exam trap

The trap here is that candidates confuse 'false positives' with 'noise' (Option B), but noise is a broader category that includes false positives as well as other irrelevant alerts, while the question specifically describes legitimate traffic being flagged as malicious, which is the precise definition of a false positive.

How to eliminate wrong answers

Option B (Noise) is wrong because noise refers to irrelevant or low-value alerts that may be triggered by benign events, but it is not the specific term for legitimate traffic flagged as malicious—noise often includes false positives but also encompasses other non-actionable alerts. Option C (False negatives) is wrong because false negatives occur when the IDS fails to detect actual malicious traffic, not when it flags legitimate traffic. Option D (True positives) is wrong because true positives are alerts that correctly identify actual malicious activity, which is the opposite of the scenario described.

90
MCQeasy

A security administrator has been asked to establish baseline monitoring for a set of Linux web servers so that unexpected changes to critical system files are detected quickly. The administrator wants the tool to compute cryptographic hashes of files, store them, and alert when they change. Which of the following should the administrator deploy to meet this requirement?

A.A vulnerability scanner scheduled to run weekly against the server group
B.A network-based intrusion detection system watching the web server subnet
C.A security information and event management platform with syslog collection only
D.A host-based intrusion detection system performing file integrity monitoring
AnswerD

File integrity monitoring computes cryptographic hashes of critical files, stores the known-good values, and alerts when a hash changes, which is exactly the requirement. A host-based intrusion detection system running file integrity monitoring on each server provides this baseline change detection, making it the appropriate control for detecting unexpected modification of system files.

Why this answer

Detecting unexpected modification of critical system files requires periodic or real-time hashing of those files against a stored known-good baseline. File integrity monitoring, delivered by a host-based intrusion detection agent, performs exactly this function and generates alerts when hashes diverge, which no network sensor, log aggregator, or periodic vulnerability scan accomplishes.

Exam trap

The trap here is confusing general monitoring platforms with file integrity monitoring, when only a hashing-based agent detects changes to local files.

91
MCQmedium

An analyst reviewing the risk register notices that a web application vulnerability has an annualized loss expectancy (ALE) of $40,000 before controls. A web application firewall (WAF) would cost $12,000 per year to operate and is expected to reduce the ALE to $10,000. Based on this quantitative analysis, what should the analyst recommend?

A.Recommend the WAF because the control cost of $12,000 is less than the $30,000 reduction in annualized loss expectancy.
B.Recommend against the WAF because the annualized loss expectancy is still $10,000 after implementation.
C.Recommend against the WAF because the $12,000 cost exceeds ten percent of the original $40,000 annualized loss expectancy.
D.Recommend the WAF only if the residual annualized loss expectancy can be reduced to zero.
AnswerA

The control yields a $30,000 annual reduction in expected loss and costs $12,000 to operate, producing a net benefit of $18,000 per year. Since the cost is clearly below the mitigated loss, the quantitative analysis supports implementing the WAF as a cost-effective risk mitigation measure.

Why this answer

Quantitative risk analysis compares the annual cost of a control with the reduction in annualized loss expectancy it produces. The WAF cuts expected loss by $30,000 while costing $12,000 per year, yielding a positive net benefit of $18,000. That favorable relationship is the basis for recommending implementation; the residual loss simply reflects that no control eliminates risk entirely.

Exam trap

The trap here is fixating on the residual annualized loss expectancy instead of comparing the control's cost against the loss it actually prevents.

← PreviousPage 2 of 2 · 91 questions total

Ready to test yourself?

Try a timed practice session using only Risk Identification, Monitoring, and Analysis questions.