TechNuggets Academy

Risk Identification, Monitoring, and Analysis

Free Systems Security Certified Practitioner practice — 6 questions on Risk Identification, Monitoring, and Analysis, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
A security practitioner is calculating the annualized loss expectancy (ALE) for a data center. The asset value is $500,000. A flood is estimated to destroy 20% of the asset's value (exposure factor), and floods are expected to occur once every two years (ARO = 0.5). What is the ALE?
SLE = Asset Value x Exposure Factor = $500,000 x 0.20 = $100,000. ALE = SLE x ARO = $100,000 x 0.5 = $50,000.
Question 2 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
A financial services firm needs vulnerability scan results that accurately reflect missing OS patches, misconfigured local services, and outdated application libraries on all internal Windows and Linux servers. Which scanning approach BEST meets this requirement?
Credentialed scans authenticate to the host with administrative or service credentials, allowing the scanner to enumerate installed patches, local services, and library versions with far greater accuracy than external checks.
Question 3 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
A SOC analyst notices that a SIEM failed to raise an alert for a brute-force attack in which an attacker submitted five failed login attempts per hour, spread over three days, against a single account. The correlation rule triggers only when 10 failed logins occur within a 5-minute window. What is the BEST remediation?
Low-and-slow attacks evade short-window thresholds by staying under the rate limit. Extending the correlation window allows the SIEM to aggregate sparse events over a longer period and detect the cumulative pattern, reducing false negatives.
Question 4 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
An organization determines it cannot cost-effectively eliminate the risk of a large-scale DDoS attack against its e-commerce platform. Instead, it purchases a cyber-insurance policy that reimburses financial losses resulting from extended outages caused by such attacks. Which risk treatment strategy does this represent?
Purchasing insurance shifts the financial impact of the risk to a third party (the insurer) rather than reducing the likelihood or impact directly — this is the definition of risk transfer (transference).
Question 5 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
During incident response, investigators need log evidence from a compromised server that can withstand challenges to its integrity in a potential legal proceeding, especially given that the attacker obtained root access. Which control BEST ensures the evidentiary integrity of the logs?
Centralized logging to a separate, hardened server with write-once (WORM) storage and cryptographic hashing prevents an attacker with root access on the source host from altering or deleting the evidentiary record, preserving chain of custody and integrity.
Question 6 of 6 · Domain 3: Risk Identification, Monitoring, and Analysis
A security manager wants ongoing assurance that deployed security controls remain effective between scheduled formal assessments, using automated data feeds to track control status in near real time. Which approach BEST satisfies this requirement?
Continuous monitoring programs use automated tools and data feeds to provide near-real-time visibility into control effectiveness and security posture, filling the gaps between periodic formal assessments — this is a core risk monitoring concept tested on the SSCP.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →