A fintech enterprise is assessing security controls for an e-commerce API gateway with an Asset Value (AV) of . Threat intelligence indicates an Annual Rate of Occurrence (ARO) of for a major distributed denial-of-service (DDoS) attack. The Chief Risk Officer (CRO) sets a maximum acceptable Annual Loss Expectancy (ALE) threshold of for DDoS-related risks. Which of the following represents the maximum Exposure Factor () that an implemented Web Application Firewall must achieve to keep residual risk within this threshold?
- Answer
- B
- C
- D
Answer
The maximum Exposure Factor () required to remain within the risk threshold is .
The correct response accurately applies the quantitative risk equation . Substituting gives . Solving for yields , which equals . Any Exposure Factor higher than would exceed the Chief Risk Officer's annual risk threshold.
Step-by-Step Solution
Key Concept
Quantitative Risk Analysis (Solving for Exposure Factor given ALE, AV, and ARO)
Estimated Time:2m 0s