A financial services firm is classifying its information assets. The CISO needs to explain to the board why the customer transaction database has a higher business value than the internal marketing materials. Which characteristic most directly determines the high business value of the customer transaction database compared to internal marketing collateral?
Answer and explanation
Correct answer: B
The business value of information is heavily influenced by the consequences of its compromise. For a financial firm, the compromise of a customer transaction database can lead to severe regulatory fines (e.g., under GDPR), significant reputational damage, and loss of customer trust. This direct financial and reputational impact makes its confidentiality and integrity critical and gives it a higher business value than internal materials.
Question 2
When a healthcare provider outsources its patient portal to a cloud vendor, what is the most critical aspect of information governance from the customer's (the healthcare provider's) perspective to ensure regulatory compliance?
Answer and explanation
Correct answer: B
From a governance standpoint, the healthcare provider (data controller) remains ultimately responsible for protecting patient data under regulations like HIPAA. A critical governance requirement is to ensure the vendor (data processor) has robust, compliant processes for handling security incidents, especially data breaches. The vendor's breach notification process directly impacts the provider's legal and regulatory obligations to patients and authorities.
Question 3
Multiple answers
An e-commerce company integrates a third-party payment gateway into its platform. To gain security assurance, which TWO of the following artifacts are most crucial for the supplier to provide and maintain? (Select TWO)
Answer and explanation
Correct answers: B, E
A PCI DSS AoC is mandatory proof that a service provider securely handles cardholder data. This is a primary document for security assurance in any payment processing context.
A SOC 2 Type II report provides detailed, independent assurance over a period of time about the effectiveness of a vendor's security controls. It is a standard and crucial document for third-party risk management.
Question 4
A risk analyst is conducting a qualitative risk assessment for a new mobile application. The analyst has identified a threat of "unauthorized access to user data" and a vulnerability of "weak session management." What is the next logical step in the risk analysis process?
Answer and explanation
Correct answer: C
The fundamental principle of risk analysis involves evaluating identified threat/vulnerability pairs. After identifying a threat and a vulnerability, the next step is to assess the likelihood of that threat successfully exploiting the vulnerability and the potential business impact if it does. This assessment is necessary to determine the overall risk level before deciding on treatment. Calculating ALE is for quantitative analysis, while implementing controls and buying insurance are risk treatment options.
Question 5
FinSecure Bank's online banking platform processes millions of dollars in transactions daily. The Chief Risk Officer (CRO) has tasked a team with performing a quantitative risk analysis on a specific threat: a sophisticated phishing attack leading to fraudulent wire transfers. The team has determined that the value of an average fraudulent wire transfer (Single Loss Expectancy - SLE) is $10,000.
Historical data and industry threat intelligence suggest that a major phishing campaign targeting the bank's customers occurs approximately four times per year. The bank's current security controls, including email filtering and user awareness training, are estimated to be 75% effective at preventing these attacks from succeeding. The CRO wants to know the residual risk to decide if a new, more advanced anti-phishing solution is justified.
The proposed new solution costs $5,000 per year but claims to increase the effectiveness of controls to 95%. The CRO needs a clear financial justification based on risk reduction.
Which of the following statements accurately represents the current financial risk and the justification for the new control?
Answer and explanation
Correct answer: C
The calculation is as follows:
Potential ALE (before controls) = ARO (4) * SLE ($10,000) = $40,000.
Current residual risk (current ALE) = Potential ALE * (1 - control effectiveness) = $40,000 * (1 - 0.75) = $10,000.
Risk reduction (annual benefit) = Current ALE - New ALE = $10,000 - $2,000 = $8,000.
Net annual benefit = Benefit ($8,000) - Cost of control ($5,000) = $3,000. Since this is positive, the investment is financially justified.
Question 6
A security architect is selecting controls for a critical customer database. To address the "Detection" stage of the incident response cycle, which control would be most appropriate?
Answer and explanation
Correct answer: C
The incident response cycle includes stages like Prevention, Detection, Response, and Recovery. Firewalls and encryption are primarily preventive controls. A disaster recovery plan is a recovery/responsive control. A Database Activity Monitoring (DAM) tool is a classic detective control, as its main purpose is to monitor for and alert on suspicious activities that could indicate an ongoing incident, fitting squarely into the Detection stage.
Question 7
True or False: After implementing a set of security controls, the goal of risk management is to completely eliminate all residual risk.
Answer and explanation
Correct answer: B
It is practically impossible and financially prohibitive to eliminate all risk. The goal of risk management is to reduce risk to an acceptable level, known as the organization's risk appetite. Residual risk is the risk that remains after controls have been implemented, and some level of residual risk must always be formally accepted by management.
Question 8
An organization is mapping its incident handling process to align with industry best practices. A security analyst has proposed the following high-level workflow. At which stage should the "Lessons Learned" activity be formally conducted?
[ A ] [ B ] [ C ] [ D ]
Event --> Triage & --> Containment & --> Post-Incident
Detected Analysis Eradication Activity
Answer and explanation
Correct answer: D
The "Lessons Learned" or post-mortem review is a critical part of the Post-Incident Activity stage. This activity is conducted after the incident has been fully contained, eradicated, and normal operations have been restored. Its purpose is to analyze the incident and the response effort to identify weaknesses and make improvements to prevent future occurrences and enhance future responses. Conducting it earlier would be premature.
Question 9
A fast-growing tech startup is transitioning its monolithic application to a microservices architecture hosted in a public cloud. A security architect advises implementing a "Zero Trust" security model. What is the primary purpose of adopting this architecture?
Answer and explanation
Correct answer: C
The core principle of a Zero Trust architecture is "never trust, always verify." It assumes that threats exist both inside and outside the traditional network perimeter. Therefore, it requires that every request to access a resource is authenticated and authorized based on identity and context, regardless of whether it originates from a supposedly 'trusted' internal network or an external one.
Question 10
A company is designing the physical security for its new data center. Which of the following controls is a detective physical security control?
Answer and explanation
Correct answer: C
Physical controls can be categorized as preventive, detective, or corrective. A mantrap, biometric scanner, and reinforced door are all preventive controls designed to stop unauthorized access. A motion-activated security camera is a detective control; it does not prevent entry but records the event and can trigger an alert, allowing security personnel to detect and respond to an intrusion.