TechNuggets Academy

Information Security Risk Management

Free Certified Information Security Manager practice — 6 questions on Information Security Risk Management, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 2: Information Security Risk Management
A financial institution's data center has an asset value of $10,000,000. A flood risk assessment determines an exposure factor of 40% and an annualized rate of occurrence of 0.1 (once every 10 years, on average). Which value should the risk manager report to the risk committee as the Annualized Loss Expectancy (ALE) for this scenario?
ALE = SLE × ARO. SLE = AV × EF = $10,000,000 × 0.40 = $4,000,000. ALE = $4,000,000 × 0.1 = $400,000. This is the figure that reflects the expected annualized loss and is appropriate for risk committee reporting and cost-benefit analysis of controls.
Question 2 of 6 · Domain 2: Information Security Risk Management
A cloud-based HR and payroll system is used by every business unit in the enterprise. During a routine vulnerability assessment, the security team identifies a risk that could disrupt payroll processing enterprise-wide if exploited. Who should be assigned as the risk owner for this identified risk?
Risk ownership belongs to the individual with the authority and accountability to make decisions about the business process, allocate resources, and accept residual risk — typically the business executive accountable for the affected process, not the party who merely discovered or manages the technical component.
Question 3 of 6 · Domain 2: Information Security Risk Management
An enterprise determines that the cost of additional controls to further reduce the risk of a rare but catastrophic supply-chain disruption exceeds the potential financial loss, yet the current risk level still exceeds the organization's risk appetite. A logistics partner offers a contractual indemnification clause at a reasonable cost that would cover losses from this scenario. Which risk treatment option should the organization select?
Risk transfer shifts the financial impact of the risk to a third party through a contractual mechanism such as indemnification or insurance. This is the appropriate choice when mitigation is not cost-effective, the risk exceeds appetite so it cannot simply be accepted, and discontinuing the activity (avoidance) is not described as feasible.
Question 4 of 6 · Domain 2: Information Security Risk Management
The security team defines a key risk indicator (KRI) tracking the number of critical patches not applied within the defined SLA, intended to provide early warning before unpatched systems become a realized security incident. Which characteristic must the KRI threshold have to serve this early-warning purpose effectively?
An effective KRI is a leading indicator: its threshold must be calibrated below the point of unacceptable exposure so that management has sufficient lead time to intervene before the risk crosses into unacceptable territory or materializes into an incident.
Question 5 of 6 · Domain 2: Information Security Risk Management
A control designed to mitigate a specific risk is later discovered to have been non-functional for the preceding six months, and no compensating control was in place during that period. Which statement BEST describes the actual level of risk exposure the organization faced during those six months?
Residual risk is only valid when the associated control is actually functioning as designed. When a control fails and no compensating control exists, the actual exposure reverts to the inherent risk level — the risk that exists before any control effect is applied — regardless of whether the failure was detected at the time.
Question 6 of 6 · Domain 2: Information Security Risk Management
A board of directors requests a report that describes the range of potential financial loss and the associated probability distribution for a major cyber risk scenario, rather than a simple relative ranking of severity. Which risk analysis technique is MOST appropriate for producing this type of report?
Monte Carlo simulation is a quantitative technique that models thousands of possible scenarios using probability distributions for variables such as loss magnitude and frequency, producing a full probability distribution of potential financial outcomes — exactly what the board is requesting.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →