- Home
- All questions
- Risk management
CISM study material: Risk management
274 questions of the 1000 in the CISM — Certified Information Security Manager quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 3. During a governance review, the manager finds that executives have a shared but unwritten sense of how much risk is acceptable, and business units interpret it differently. Which CSF 2.0 Govern outcome is not being met?
- 4. Three business units each rate their top risk as high, but each derives that rating differently, so the executive committee cannot tell which risk deserves funding first. Which governance outcome most directly addresses this?
- 5. A manager is drafting the agenda for the quarterly cybersecurity risk discussion under CSF 2.0. Which item belongs on that agenda that a purely threat-focused agenda would omit?
- 19. A newly appointed security manager wants to structure risk management across the organisation using SP 800-39. Which description of the three tiers is correct?
- 20. An organisation is starting to apply SP 800-39 and asks which risk management component belongs at Tier 1 and why it must come first. What is the correct answer?
- 22. A vulnerability discovered in one system turns out to stem from a design pattern reused across the estate. According to SP 800-39, what should follow?
- 28. Each system owner reports that risk to their own system is acceptable, yet the organisation wants to know whether risk is acceptable overall. Which role produces that view under SP 800-39?
- 30. A security manager is drafting the organisation-wide risk management strategy. Which two elements does SP 800-39 expect it to contain? Choose two.
- 31. An organisation publishes a one-line risk tolerance statement on its intranet, yet staff continue to make inconsistent decisions. What does SP 800-39 say was missing?
- 33. An enterprise risk officer worries that adopting SP 800-39 will duplicate the existing enterprise risk management programme. How should the security manager characterise the relationship?
- 67. Under IR 8286, which governance responsibility sits with executive leaders in relation to risk?
- 68. An organisation set its risk strategy three years ago and treats it as settled. According to IR 8286, why is this inadequate?
- 69. IR 8286 distinguishes two risk officer roles. Which pairing correctly describes them?
- 72. An organisation assigns a large portfolio of risks to an owner who has no training or experience in that domain. What does IR 8286 say about this arrangement?
- 74. A system owner proposes to decide their system's risk treatment purely on the system's own technical merits. Which two organisational factors does SP 800-37 say such decisions are also tied to? Choose two.
- 85. A business unit wants to establish a data-sharing partnership and treats the trust decision as a commercial matter outside the risk process. How does SP 800-39 characterise such a decision?
- 87. A risk assessment of partners considers only competitors and known adversaries as sources of concern. Which category does SP 800-39 warn is being missed?
- 95. A technology the business insists on adopting carries vulnerabilities that no available control adequately addresses. Which response does SP 800-39 identify for this situation?
- 106. Which two criteria does NIST use to prioritise potential enterprise-level security investments in the capital planning process? Choose two.
- 109. A manager defines the purpose of the organisation's risk monitoring. Which two purposes does SP 800-39 name? Choose two.
- 110. At the organisation tier, what kind of monitoring activity does SP 800-39 describe as appropriate?
- 111. An organisation sets every monitoring activity to an annual cadence regardless of subject. Which three inputs does SP 800-39 say should shape monitoring frequency instead?
- 112. A risk assessment established a likelihood threshold for a particular threat. How can monitoring use that threshold, according to SP 800-39?
- 113. Before choosing among risk responses, a manager lists the constraints already fixed by framing. Which two does SP 800-39 name? Choose two.
- 114. A risk register records only risks the organisation faces today. Which category does SP 800-39 say is also in scope?
- 115. A manager must explain what risk framing produces. What is its principal output under SP 800-39?
- 116. At the organisation tier, senior leaders define the risk frame. Which two aspects of monitoring do they settle there? Choose two.
- 117. An organisation has never articulated its assumptions, constraints, tolerance or trade-offs for risk. What consequence does SP 800-39 predict?
- 118. Two divisions of the same organisation hold materially different risk tolerances, grounded in their different operating realities. What does SP 800-39 say leadership should do?
- 119. Which two organisational realities does SP 800-39 say shape how an organisation frames risk? Choose two.
- 120. An organisation wants to begin risk framing. What does SP 800-39 identify as the key precondition?
- 121. While developing response options, a team finds a promising approach that the organisation's stated constraints had ruled out entirely. What does SP 800-39 say should happen?
- 122. Monitoring shows the organisation is routinely carrying far more risk than its published tolerance statement allows, with no adverse consequence to date. What does SP 800-39 say this may indicate?
- 123. An organisation with a hybrid governance structure asks how many risk assessment methodologies it should use. What does SP 800-39 suggest is appropriate?
- 124. An organisation whose culture prizes divisional autonomy does not want to mandate one risk methodology. Which approach does SP 800-39 offer?
- 125. A threat assumptions document lists the threat sources the organisation's controls are designed to address. What does SP 800-39 say it should also record?
- 126. An organisation wants to be able to roll up risk assessment results from many business areas into an organisation-wide view. What does SP 800-39 say makes this possible?
- 127. A programme manager complains that early-phase threat analysis is less specific than the analysis done nearer deployment. How does SP 800-39 characterise this?
- 128. An assessment scopes vulnerabilities to weaknesses in assets the organisation owns and controls. Which class of vulnerability does SP 800-39 say is being missed?
- 129. SP 800-39 describes impact being felt at three levels. Which set matches?
- 130. Personal data exposed by the human resources function damages the whole organisation's reputation, while also making it easier for an attacker to defeat authentication on many systems. Which point does SP 800-39 illustrate with such an example?
- 131. An organisation wants to reuse one division's risk assessment results in another division. Which two factors determine how far that reuse is legitimate? Choose two.
- 132. A decentralised organisation performs most risk assessment at the business process tier. What does SP 800-39 say this creates a greater need for?
- 133. A manager must justify the effort of keeping risk assessments current rather than repeating them from scratch each year. Which two benefits does SP 800-39 name? Choose two.
- 134. SP 800-39 distinguishes two lighter forms of reassessment. Which pairing is correct?
- 135. A team must assess risk before the organisation has finished defining its risk frame. What does SP 800-39 permit and warn?
- 136. Which two kinds of vulnerability does SP 800-39 say are identified most effectively at the organisation tier rather than lower down? Choose two.
- 137. An organisation prioritises remediating system-level flaws over addressing a weakness in its business process design. What does SP 800-39 warn about that ordering?
- 139. An assessment examines only those threats for which the organisation already has safeguards deployed. What does SP 800-39 say is missing?
- 140. Two experienced assessors reach different risk conclusions from the same evidence. How does SP 800-39 treat this outcome?
- 141. A manager considers using a panel of assessors with varied backgrounds. Which two effects does SP 800-39 attribute to that diversity? Choose two.
- 171. A team debating a risk rating cannot agree because they are weighing threat capability, control maturity and asset value simultaneously. Under SP 800-30, which two factors is risk actually a function of?
- 172. A manager plans to complete a risk assessment and then hold a separate exercise to rank the results. How does SP 800-30 define the scope of assessment?
- 173. An auditor asks the security manager to describe the organisation's risk assessment methodology. Which two components does SP 800-30 say it should contain? Choose two.
- 174. A team is about to begin a specific risk assessment and proposes selecting the methodology as their first activity. What does SP 800-30 say about when the methodology is settled?
- 175. An organisation relies on a three-year-old risk assessment because nothing formally changed. Why does SP 800-30 regard the validity of any assessment as bounded in time?
- 176. Which set correctly lists the typical risk factors in the NIST risk model?
- 177. A threat catalogue lists only deliberate attacks by outsiders. Which two further categories of threat source does SP 800-30 identify? Choose two.
- 178. A provisioning server goes offline and the team assumes an attack. Which point does SP 800-30 make about attributing a threat event to a single cause?
- 179. How does SP 800-30 characterise a threat source?
- 180. An assessment must estimate whether a particular adversary will initiate an attack. Which three adversary characteristics does SP 800-30 assess?
- 181. An analyst wants to model how a breach would actually unfold rather than listing isolated events. Which SP 800-30 construct is designed for this?
- 182. After a new control is deployed, the adversary begins attacking at a different time of day and against a less protected system. Which SP 800-30 concept describes this behaviour?
- 183. Which two observations does SP 800-30 make about how sophisticated adversaries behave when they meet defences? Choose two.
- 184. A team restricts its vulnerability register to software defects. Which broader definition does SP 800-30 give?
- 185. A manager assumes every vulnerability results from an omission at build time. Which two origins does SP 800-30 identify? Choose two.
- 186. Controls assessed as effective at deployment are found to be much less effective five years later, without any change being made to them. What does SP 800-30 conclude from this tendency?
- 187. Which two of the following does SP 800-30 recognise as vulnerabilities in governance structures themselves? Choose two.
- 188. The same technical vulnerability is rated critical on one system and low on another. Why is this consistent with SP 800-30?
- 189. A data centre sits on a flood plain, and a separate system has no network connectivity at all. Which SP 800-30 concept do both illustrate?
- 190. An organisation runs no database management system anywhere in its estate. What does SP 800-30 say about its exposure to SQL injection?
- 191. An analyst has a long list of individual weaknesses, each rated low. Why does SP 800-30 recommend also analysing them together?
- 192. Which two estimates does SP 800-30 combine into the overall likelihood of a threat event? Choose two.
- 193. An analyst must estimate the likelihood of a hardware failure rather than an attack. Which basis does SP 800-30 prescribe?
- 194. A likelihood rating of high is recorded with no period attached. Which requirement of SP 800-30 has been overlooked?
- 195. How does SP 800-30 distinguish the likelihood of impact from the magnitude of impact?
- 196. An analyst proposes mapping every threat to every vulnerability one-to-one across the estate. What does SP 800-30 warn about this approach?
- 197. Which four consequences does SP 800-30 use to define the level of impact from a threat event?
- 198. An asset register lists only systems, facilities, people and equipment. Which class of asset does SP 800-30 say is also in scope?
- 199. An organisation has never formally stated which impacts matter most. Which two sources does SP 800-30 say priorities can usually be derived from? Choose two.
- 200. An organisation declares that threat events whose impact falls below a stated value receive no further analysis. Is this consistent with SP 800-30?
- 201. At which tiers does SP 800-30 say risk aggregation is mainly performed?
- 202. Several moderate risks materialise in the same quarter and the combined loss exceeds anything the organisation had assessed. Which limitation of risk aggregation does this illustrate?
- 203. When aggregating risks, an analyst treats each entry as independent. Which relationship does SP 800-30 ask them to consider?
- 204. Which two sources of uncertainty in risk evaluation does SP 800-30 identify? Choose two.
- 205. An analyst wants to convey that a risk estimate is uncertain without abandoning the estimate. Which two techniques does SP 800-30 suggest? Choose two.
- 206. An organisation must compare the cost-effectiveness of several competing risk responses. Which assessment approach does SP 800-30 say supports this best?
- 207. A quantitative risk model produces precise figures, but several of its inputs were expert guesses recorded as point values. What does SP 800-30 say about this?
- 208. An organisation uses a five-level qualitative scale and finds it cannot decide which of eleven high risks to fund first. Which limitation of qualitative assessment does this show?
- 209. Two experienced assessors assign very different qualitative ratings to the same scenario. Which two remedies does SP 800-30 offer? Choose two.
- 210. An organisation scores risks from 0 to 100 but states the numbers carry no meaning outside the assessment. Which approach is this?
- 211. Which comparison does a semi-quantitative scale allow that a purely qualitative one cannot express?
- 212. SP 800-30 names three analysis orientations. Which set is correct?
- 213. An analysis begins with the consequences the organisation most fears and its critical assets, drawing on business impact analysis results, then works back to the threats that could cause them. Which orientation is this?
- 214. A team has completed a thorough threat-oriented analysis. Why does SP 800-30 recommend running a second orientation as well?
- 215. Which two many-to-many relationships does SP 800-30 identify in risk analysis? Choose two.
- 216. Which two graph-based techniques does SP 800-30 name for generating and bounding threat scenarios? Choose two.
- 217. A manager wants to be able to compare this year's risk assessment against last year's to see trends. Which property must the assessment have?
- 218. An organisation assesses risk system by system and is surprised by an exposure created by interconnections between systems. Which weakness does SP 800-30 identify in this practice?
- 219. A newly discovered vulnerability requires an organisation-wide mitigation mandate. How does this fit SP 800-30's observation about the pace of risk management at different tiers?
- 220. Which two examples does SP 800-30 use to show that risks and responses run on different time scales? Choose two.
- 221. Early in a system's life, little is known about threats or control effectiveness. What does SP 800-30 say about the risk model used at that point?
- 222. A vendor offers a single fixed risk model with fixed factors, scales and combining algorithm, claiming it suits any organisation. What does NIST say?
- 223. Which two authorisation decisions can risk assessment results support, according to SP 800-30? Choose two.
- 224. A business process depends entirely on a system that cannot be adequately protected within budget. Which response does SP 800-30 identify as sometimes the most effective?
- 225. Which sequence correctly names the four components of the SP 800-39 risk management process?
- 226. A risk frame documents the organisation's assumptions and its tolerance. Which two further elements does SP 800-39 require? Choose two.
- 227. Which four things does the assessment component of SP 800-39 identify?
- 228. SP 800-39 lists five risk responses. Why does it list sharing and transferring separately rather than treating them as one?
- 229. Which two purposes does risk monitoring serve under SP 800-39, beyond confirming that planned responses were implemented? Choose two.
- 230. A vulnerability register covers only information systems. Which two further locations does SP 800-39 say organisational vulnerabilities can occupy? Choose two.
- 231. New legislation obliges the organisation to deploy a specific safeguard immediately. Under SP 800-39, what may happen to the normal sequence of risk components?
- 232. How does SP 800-39 define risk tolerance, and where is it determined?
- 233. A consultant asserts there is an objectively correct level of risk tolerance for an organisation of a given size. How does SP 800-39 characterise risk tolerance?
- 234. Two organisations scope their threat analysis differently: one considers only threats its peers have actually suffered, the other adds threats that are merely plausible. What best explains the difference?
- 235. Two organisations adopt the same technology, but one demands far more assessment before deployment. Which factor does SP 800-39 identify as the cause?
- 236. Which two costs does SP 800-39 attribute to the extremes of risk tolerance? Choose two.
- 237. A residual risk accepted two years ago is still recorded as acceptable, and nobody has revisited it. Why does SP 800-39 regard that as a problem?
- 238. An organisation maps only the risks its suppliers pose to it. Which point does SP 800-39 make about external risk relationships?
- 239. How does SP 800-39 characterise an advanced persistent threat, and what does it say about supply chain risk in that context?
- 240. Which two channels does SP 800-39 name for exchanging threat and vulnerability information with parties outside the organisation? Choose two.
- 241. Under CSF 2.0, which combination of factors is used to understand inherent risk and rank which responses come first?
- 242. An organisation approves exceptions to policy in a change ticket and takes no further action. Which CSF 2.0 expectation is not being met?
- 243. A supplier's hardware is verified for authenticity and integrity only after it has been racked and connected. Which CSF 2.0 outcome does this fail?
- 244. CSF 2.0 names four responses for negative risk and four for positive risk. Which two are the positive-risk responses? Choose two.
- 245. An organisation applies the same assurance questionnaire to every one of its 900 suppliers and cannot complete the programme. Which CSF 2.0 outcome would address this?
- 246. A supplier is onboarded and the first security review takes place six months into the contract. Which CSF 2.0 outcome does this arrangement miss?
- 247. A supplier contract ends and the supplier retains administrative access and copies of organisational data for months afterwards. Which CSF 2.0 outcome addresses this?
- 248. A researcher reports a flaw in the organisation's public application and receives no acknowledgement for weeks because no route exists to handle such reports. Which CSF 2.0 outcome is missing?
- 249. Which sequence correctly describes the enterprise risk management life cycle used in IR 8286?
- 250. A programme schedules stakeholder communication as a discrete step after risk prioritisation. How does IR 8286 position communication in the life cycle?
- 251. What is the stated purpose of the monitoring step in the IR 8286 risk life cycle?
- 252. Which two items does IR 8286 say a risk register typically contains, beyond a description of the risk? Choose two.
- 253. An enterprise risk register holds legal and financial risks but no cybersecurity entries, and the board cannot see cyber risk alongside the rest. What does IR 8286 prescribe?
- 254. In the IR 8286 risk register, what does the term exposure denote, and what do other frameworks call the same thing?
- 255. A register entry reads simply 'ransomware'. Which form does IR 8286 recommend for a risk description?
- 256. IR 8286 distinguishes two roles attached to a register entry. Which pairing is correct?
- 257. Three business units each maintain a risk register using their own categorisation scheme. What consequence does IR 8286 identify?
- 258. IR 8286 prefers current risk to inherent risk in its register template. What reasoning does it give?
- 259. Which pairing correctly distinguishes residual risk from target residual risk in IR 8286?
- 260. Which two kinds of information does IR 8286 say a risk detail record holds that the register itself does not? Choose two.
- 261. Which two dates does IR 8286 say a risk detail record should carry? Choose two.
- 262. Which four elements does IR 8286 say a complete risk scenario describes?
- 263. IR 8286 warns two kinds of control must not be confused. Which pairing describes them correctly?
- 264. According to IR 8286, security controls respond to cybersecurity risk in four ways. Which set is correct?
- 265. Which two activities does IR 8286 say a cybersecurity risk register should support to condition its data for the enterprise view? Choose two.
- 266. A board proposes eliminating all cybersecurity risk from the organisation's operations. How does IR 8286 characterise both extremes of this spectrum?
- 267. A team applies a standard control set to every new device as a matter of course. Which practice does IR 8286 criticise here?
- 268. Controls have been deployed to treat a risk, and the register records the treatment as complete. Which follow-up does IR 8286 say is usually missing?
- 269. System-level risk data reaches the board as an unchanging red heatmap, and the board reports it cannot use it. How does IR 8286 explain this common failure?
- 270. A risk committee treats cybersecurity risk as a self-contained category with no bearing on other enterprise risks. Which example does IR 8286 use to challenge that view?
- 271. Two comparable organisations receive the same system-level risk data, but one translates it into enterprise understanding far more readily. Which structural difference does IR 8286 identify?
- 272. An organisation cannot say with confidence which devices it operates or where its data resides. What consequence does IR 8286 draw?
- 273. IR 8286 divides risk context into two parts. Which pairing is correct?
- 274. How does IR 8286 relate the risk assessment report to the cybersecurity risk register?
- 275. An organisation completes its risk register once and files it. Which point does IR 8286 make about how a register derives its value?
- 276. Which definition of risk appetite does IR 8286 adopt, and at what level is it set?
- 277. A programme drafts detailed operational risk tolerance statements before any appetite has been agreed. Which sequencing does IR 8286 describe?
- 278. Business units report risk levels on incompatible scales, so the enterprise cannot compare them. Which leadership responsibility does IR 8286 identify as missing?
- 279. Which definition of inherent risk does IR 8286 quote?
- 280. After treatment, actual residual risk is measured higher than the target residual risk that was set. What does this indicate under IR 8286?
- 281. Which two of the four inputs to cybersecurity risk identification does IR 8286 name? Choose two.
- 282. A risk identification exercise works only outward from technical scans of infrastructure. Which complementary direction does IR 8286 recommend?
- 283. A finance team values a research database at its replacement cost. Which broader view of asset value does IR 8286 take?
- 284. An analyst decides unilaterally which assets count as critical. What does IR 8286 say is needed for that determination?
- 285. An organisation already maintains business impact analysis records for continuity planning. Which further use does IR 8286 suggest for that template?
- 286. Which two cognitive biases does IR 8286 name as distorting threat modelling? Choose two.
- 287. A risk workshop spends most of its time on an attack type recently covered heavily in the press, though it is rare in the organisation's sector. Which bias does IR 8286 describe?
- 288. Which two symptoms does IR 8286 attribute to overconfidence in risk work? Choose two.
- 289. Which technique does IR 8286 name for surfacing opportunities arising from organisational strengths alongside threats reflecting weaknesses?
- 290. A register holds separate entries for a website outage and a help desk outage. What does IR 8286 say may also be needed?
- 291. An organisation records only the immediate effect of each risk event. Which analysis does IR 8286 say is also required?
- 292. Which of these does IR 8286's definition of vulnerability include, alongside an unpatched software flaw?
- 293. An analyst records a serious vulnerability for which no credible threat exists in the organisation's environment. Which two points does IR 8286 make? Choose two.
- 294. An organisation relies wholly on automated scanning to find weaknesses. Which limitation does IR 8286 note?
- 295. A stakeholder submits the risk 'I'm concerned about a denial-of-service attack'. Why does IR 8286 say this cannot be analysed as written?
- 296. A threat event assessed as highly likely nevertheless produces only minor consequences when it occurs. Which explanation does IR 8286 offer?
- 297. In which two circumstances does IR 8286 say qualitative analysis is most useful? Choose two.
- 298. On what two things does the quality of a quantitative risk analysis depend, according to IR 8286?
- 299. Which two external sources does IR 8286 suggest for improving the quality of qualitative analysis? Choose two.
- 300. A manager proposes switching the whole organisation from qualitative to quantitative risk analysis immediately. Which offsetting cost does IR 8286 identify?
- 301. The same payroll server outage is assessed as far more damaging in one week than another. Which factor does IR 8286 use this to illustrate?
- 302. An impact estimate counts only the direct loss of availability from an outage. Which two consequences does IR 8286 warn this omission produces? Choose two.
- 303. Which two secondary losses does IR 8286 give as examples following a telecommunications outage that takes a web server offline? Choose two.
- 304. Which two techniques does IR 8286 name for estimating the probability that a risk event will occur? Choose two.
- 305. Which description matches Monte Carlo simulation as IR 8286 defines it?
- 306. IR 8286 says tangible and less tangible impacts are connected in both directions. Which pair of statements captures that connection?
- 307. An estimate of likelihood and impact takes credit for every control listed in the control catalogue. What caution does IR 8286 give?
- 308. Business units estimate likelihood over different periods — one over a year, another over five. What problem does IR 8286 identify?
- 309. An organisation decides very low exposure risks need not be entered on the register. What condition does IR 8286 attach to such a threshold?
- 310. Stakeholders in different units assign different priorities to risks with identical exposure values. Which governance step does IR 8286 say prevents this?
- 311. A team sets itself the objective of driving every recorded risk to zero. How does IR 8286 state the actual goal of risk response?
- 312. An organisation deploys multi-factor authentication to reduce an access control risk and sees a rise in help desk load and user workarounds. Which point does IR 8286 make about risk responses?
- 313. A risk sits inside tolerance and the owner records the response as accept, then closes the entry and stops tracking it. Which part of the accept response has been dropped?
- 314. An organisation buys cyber insurance and treats the underlying risk as fully addressed. Which limitation does IR 8286 identify?
- 315. No cost-effective control can bring a particular risk within tolerance. Which response does IR 8286 identify, and what must be weighed alongside it?
- 316. Which two kinds of effect does IR 8286 include within mitigation? Choose two.
- 317. An organisation lacks the in-house expertise to recover from a serious cyber attack and cannot justify hiring for it permanently. Which mechanism does IR 8286 describe for this situation?
- 318. Which two control types does IR 8286 name alongside preventative, detective and corrective? Choose two.
- 319. A warning banner and a stated intention to prosecute unauthorised access are deployed. Which control type does IR 8286 classify these as?
- 320. How does IR 8286 define a corrective control?
- 321. Controls have been deployed to mitigate a risk and the register is updated to show the risk as treated. What further step does IR 8286 require before that treatment can be relied upon?
- 322. After treatment, residual risk remains above the acceptable level and further controls would cost more than the activity is worth to the business. Which option does IR 8286 point the risk owner toward?
- 323. A potential breach of design plans is estimated to cost 750,000 while full disk encryption and remote tracking would cost 275,000. Which conclusion follows from the cost-benefit reasoning IR 8286 describes?
- 324. A mitigation cannot be implemented immediately because the necessary resources are unavailable. Which two things does IR 8286 say the corrective action plan records? Choose two.
- 325. The window in which a particular risk could have occurred has now passed and its risk reserve is unspent. What does IR 8286 say should happen, and what does it require?
- 326. Which four risk factors does SP 800-37 identify as considered during risk assessment?
- 327. Which two activities belong to the preparation step of a risk assessment under SP 800-30? Choose two.
- 328. How does SP 800-30 distinguish the purpose of an initial assessment from that of a reassessment?
- 329. Which two events does SP 800-30 name as triggers for a reassessment of risk? Choose two.
- 330. Which two questions does establishing the scope of a risk assessment answer, under SP 800-30? Choose two.
- 331. An assessment team decides for itself how wide the assessment will be. Who does SP 800-30 say determines the scope?
- 332. Why does SP 800-30 expect a policy-level risk assessment to remain valid longer than one supporting a compensating control on a system?
- 333. An assessment reuses threat data gathered three years ago for a different exercise. Which consideration does SP 800-30 raise?
- 334. A system-level assessment must decide whether to include weaknesses in the controls the system inherits. What does SP 800-30 say about this choice?
- 335. Which two benefits does SP 800-30 attribute to making assumptions and constraints explicit? Choose two.
- 336. Which two constraints on a risk assessment does SP 800-30 identify? Choose two.
- 337. An organisation must assess a threat about which very little credible information exists. What effect does SP 800-30 say the resulting uncertainty may have?
- 338. Two organisations differ on whether a threat event must have been observed before it is assessed. What does SP 800-30 say about this?
- 339. Why does SP 800-30 require organisations to give guidance on identifying and compensating for uncertainty in individual risk factors?
- 340. Assessing an advanced persistent threat, an organisation must choose a stance on likelihood. Which two stances does SP 800-30 present as the ends of that range? Choose two.
- 341. What does SP 800-30 call the combination of the assessment approach and the analysis approach?
- 342. Which two circumstances does SP 800-30 say warrant greater analytical detail? Choose two.
- 343. Which two internal sources does SP 800-30 name as providing insight into both threats and vulnerabilities? Choose two.
- 344. An organisation subscribes to several external threat feeds and ingests all of them without filtering. Which three qualities does SP 800-30 say should be weighed?
- 345. A business process assessment has just been completed. What does SP 800-30 say can be done with that report at other tiers?
- 346. How does SP 800-30 describe the role of security categorisation within risk assessment?
- 347. Business owners list the shared services they currently depend on. Which further category does SP 800-30 urge them to identify?
- 348. Why does SP 800-30 ask that an organisation-specific risk model include or be translatable into the standard risk factors?
- 349. A risk model defines its factors and scales but leaves how they combine to the assessor's judgement each time. What does SP 800-30 say a model requires, and what do those rules reflect?
- 350. An organisation looks in SP 800-30 for the formula to combine semi-quantitative values and cannot find one. What is the reason NIST gives?
- 351. Is it acceptable under SP 800-30 for an organisation to use qualitative values for low-impact systems and a granular numeric scale for high-impact ones?
- 352. What is the stated objective of the conduct step of a risk assessment under SP 800-30?
- 353. Which sequence correctly orders the tasks of conducting a risk assessment under SP 800-30?
- 354. A team completes vulnerability identification and discovers weaknesses that suggest attack paths nobody had listed as threat events. What does SP 800-30 say about this?
- 355. An assessment cannot cover the whole threat space in the detail the methodology describes within the resources available. What compromise does SP 800-30 permit?
- 356. An organisation begins its risk assessment with a business impact analysis at the upper tiers rather than with threat identification. Is this consistent with SP 800-30?
- 357. How does SP 800-30 characterise non-adversarial threat sources, in contrast to adversarial ones?
- 358. Which two broader considerations does SP 800-30 suggest when viewing adversarial threat sources? Choose two.
- 359. Which kind of threat event does SP 800-30 say is of particular interest at the business process tier?
- 360. How does SP 800-30 link the relevance values an organisation assigns to threat events with its risk tolerance?
- 361. Two organisations receive the same unconfirmed threat report. The more risk-tolerant one sets it aside. How does SP 800-30 explain this?
- 362. Which organisation-tier vulnerability does SP 800-30 illustrate with the example of subverted components entering the estate?
- 363. A newly identified vulnerability has not yet been through risk assessment, so its severity is unknown. Which interim proxy does SP 800-30 permit?
- 364. Why does SP 800-30 ask organisations to assess how pervasive a predisposing condition is?
- 365. An estate has tens of thousands of individual vulnerabilities and cataloguing each would exhaust the assessment budget. Which approach does SP 800-30 permit?
- 366. Which two circumstances does SP 800-30 say mean an adversary is not expected to initiate a threat event? Choose two.
- 367. A threat event is identified for which no vulnerability or predisposing condition can be found. What does SP 800-30 direct?
- 368. Why does SP 800-30 require a rationale to accompany each likelihood assessment?
- 369. For a non-adversarial threat event, which two attributes of the event itself does SP 800-30 say the likelihood of adverse impact takes into account? Choose two.
- 370. An assessor proposes restating the organisation's risk tolerance and constraints in full within every individual risk assessment report. What does SP 800-30 say?
- 371. SP 800-39 distinguishes a course of action from a risk response measure. Which pairing is correct?
- 372. An organisation's policy states only low risks may be accepted. How does SP 800-39 describe the scope of acceptance?
- 442. Monitoring produces a finding that a control is ineffective. Which two categories of response does SP 800-137 permit? Choose two.
- 454. Which two continuous monitoring responsibilities does SP 800-137 assign to the risk executive function? Choose two.
- 472. A supply chain programme sets itself the objective of eliminating supply chain risk. How does NIST frame the correct objective?
- 602. Which two sources does an organisation-level risk assessment draw on, under SP 800-37? Choose two.
- 604. Why does SP 800-37 ask risk assessment to account for variability across an organisation?
- 630. What risk does NIST identify as arising from widespread dependence on common controls?
- 649. Two systems with different configurations and control sets are to be interconnected. Why does NIST say the resulting risk must be weighed carefully?
- 672. How does NIST characterise the relationship between programme assessments, control assessments and risk assessment?
- 735. The Community Profile asks that incident decision-making be informed by more than cybersecurity risk. Which two other risk types does it name? Choose two.
- 736. Which two uses does the Community Profile identify for a standardised risk calculation method during incident response? Choose two.
- 871. What does a business impact analysis do, in NIST's formulation?
- 872. Which two outputs does NIST say business impact analysis results feed? Choose two.
- 876. What does maximum tolerable downtime represent?
- 877. Which definition matches recovery time objective as NIST states it?
- 878. Which quantity does recovery point objective express?
- 879. Why is recovery point objective not counted as part of maximum tolerable downtime, while recovery time objective is?
- 882. The achievable recovery time objective exceeds a maximum tolerable downtime that cannot be relaxed. What does NIST direct?
- 884. How does NIST describe the two cost curves that determine an optimal recovery solution?
- 905. What must be negotiated in advance with a commercial alternate site provider serving many customers?
- 916. Which risk does NIST attach to a replacement strategy that depends on shipment after a catastrophic disaster?
- 923. Which two external points of contact should a business impact analysis draw on? Choose two.