All practice questions

2232 questions

Question 1641Question

A cloud-hosted video rendering cluster maintained by a media organization has an estimated Asset Value (AVAV) of $1,500,000\$1,500,000. Operational metrics show that ransomware incidents targeting the rendering nodes have an Annualized Rate of Occurrence (AROARO) of 0.200.20 and an unmitigated Exposure Factor (EFEF) of 0.500.50. The organization deploys an automated immutable backup solution costing $25,000\$25,000 annually. With this safeguard in place, the Exposure Factor (EFEF) for ransomware attacks drops to 0.100.10, while the AROARO remains unchanged at 0.200.20. What is the net annual financial benefit (in USD) realized by implementing this security control?

Show answer & explanation

Answer: 95000

Answer

The net annual financial benefit realized by implementing the safeguard is $95,000.
The baseline Annualized Loss Expectancy (ALE) is calculated as AV×EF×ARO=$1,500,000×0.50×0.20=$150,000AV \times EF \times ARO = \$1,500,000 \times 0.50 \times 0.20 = \$150,000. With the control active, the mitigated ALE becomes $1,500,000×0.10×0.20=$30,000\$1,500,000 \times 0.10 \times 0.20 = \$30,000, resulting in an annual loss reduction of $120,000\$120,000. Subtracting the annual safeguard maintenance cost of $25,000\$25,000 yields a net annual financial benefit of $95,000\$95,000.

Step-by-Step Solution

1
Calculate the initial Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE)
Initial SLE = $1,500,000×0.50=$750,000\$1,500,000 \times 0.50 = \$750,000; Initial ALE = $750,000×0.20=$150,000\$750,000 \times 0.20 = \$150,000.
Establishes baseline financial risk exposure prior to implementing security controls.
2
Calculate the post-mitigation Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE)
Post-mitigation SLE = $1,500,000×0.10=$150,000\$1,500,000 \times 0.10 = \$150,000; Post-mitigation ALE = $150,000×0.20=$30,000\$150,000 \times 0.20 = \$30,000.
Determines the remaining annualized loss after applying the Exposure Factor reduction.
3
Calculate net annual benefit by subtracting safeguard cost from ALE reduction
ALE Reduction = $150,000$30,000=$120,000\$150,000 - \$30,000 = \$120,000; Net Benefit = $120,000$25,000=$95,000\$120,000 - \$25,000 = \$95,000.
Evaluates the overall cost-effectiveness of the control solution.

Key Concept

Quantitative Risk Analysis - Net Annual Safeguard Value
Question 1642Question

A regional hospital network is evaluating a software provider to host patient portal data in a public cloud deployment. The hospital's compliance policy mandates independent verification that the cloud vendor's security, confidentiality, and availability controls operate effectively over a continuous 12-month monitoring period. Which of the following attestation reports should the hospital request from the vendor?

Show answer & explanation

Answer: SOC 2 Type II report

Answer

The hospital network should request a SOC 2 Type II report.
The SOC 2 Type II report aligns with the Trust Services Criteria (security, availability, confidentiality) and assesses whether controls were operating effectively throughout a specified testing window (such as 12 months).

Step-by-Step Solution

1
Determine the subject domain of the controls required.
The requirement focuses on security, confidentiality, and availability controls for patient data rather than financial reporting controls.
SOC 2 reports directly evaluate security and privacy under the Trust Services Criteria, whereas SOC 1 reports evaluate internal controls over financial reporting.
2
Evaluate the required time scope of auditor verification.
The hospital requires verification of operational effectiveness over a continuous 12-month period.
Type II reports test and verify control execution over a sustained period, whereas Type I reports assess control design at a single point in time.

Key Concept

Distinguishing SOC Report Scope and Attestation Types
Question 1643Question

An international cloud technology enterprise processes user telemetry and account details for customers residing in the European Union. To comply with privacy laws governing large-scale handling of personal information, the enterprise must appoint an individual responsible for monitoring regulatory compliance, conducting privacy impact assessments, and serving as the primary liaison to supervisory authorities. Which of the following governance roles is specifically designated for these statutory duties?

Show answer & explanation

Answer: Data Protection Officer

Answer

The role specifically designated for statutory privacy monitoring, impact assessments, and regulatory liaising is the Data Protection Officer.
The Data Protection Officer is responsible for ensuring an organization adheres to privacy laws, advising on Data Protection Impact Assessments (DPIAs), and acting as the official contact point for data protection authorities and data subjects.

Step-by-Step Solution

1
Identify the regulatory context and required organizational duties
The scenario requires an independent role responsible for monitoring data privacy compliance and communicating with supervisory authorities under EU privacy regulations.
Privacy regulations mandate specific oversight structures when organizations handle personal data at scale.
2
Evaluate the responsibilities of standard security and data management roles
Technical roles such as Data Custodians and Database Administrators manage IT systems, while executive roles like the CISO handle overall corporate security strategy.
These operational and management roles do not satisfy the statutory mandate for independent privacy regulation oversight.
3
Select the designated statutory role matching the regulatory requirements
The Data Protection Officer (DPO) is the formal title and role defined by privacy frameworks to fulfill regulatory compliance monitoring.
The DPO role is explicitly framed with the authority and independence required by international privacy laws.

Key Concept

Data Protection Officer (DPO) role and compliance mandates under privacy regulations
Estimated Time:45s
Question 1644Question

A cloud SaaS provider is evaluating a quantitative risk mitigation strategy for its primary customer invoicing repository, which has an Asset Value (AVAV) of $400,000\$400,000. Security assessment data indicates an unmitigated ransomware threat has an Exposure Factor (EFEF) of 25%25\% and an Annual Rate of Occurrence (AROARO) of 0.50.5. The organization is considering deploying an automated threat prevention platform costing $15,000\$15,000 per year, which is expected to reduce the EFEF to 5%5\% and the AROARO to 0.10.1. What is the net annual financial benefit of implementing this security control?

Show answer & explanation

Answer: $33,000\$33,000

Answer

The net annual financial benefit of implementing the security safeguard is $33,000\$33,000.
The net annual benefit of a security safeguard is calculated as the initial Annual Loss Expectancy (ALEALE) minus the post-mitigation ALEALE, minus the annual cost of the safeguard. The initial ALEALE is $400,000×0.25×0.5=$50,000\$400,000 \times 0.25 \times 0.5 = \$50,000. The modified ALEALE is $400,000×0.05×0.1=$2,000\$400,000 \times 0.05 \times 0.1 = \$2,000. Subtracting the modified ALEALE ($2,000\$2,000) and the control cost ($15,000\$15,000) from the initial ALEALE ($50,000\$50,000) yields a net benefit of $33,000\$33,000.

Step-by-Step Solution

1
Calculate the initial (pre-mitigation) Annual Loss Expectancy (ALE)
Initial SLE=AV×EF=$400,000×0.25=$100,000SLE = AV \times EF = \$400,000 \times 0.25 = \$100,000. Initial ALE=SLE×ARO=$100,000×0.5=$50,000ALE = SLE \times ARO = \$100,000 \times 0.5 = \$50,000.
Determines the baseline expected financial loss per year without the safeguard.
2
Calculate the modified (post-mitigation) Annual Loss Expectancy (ALE)
Modified SLE=AV×EF=$400,000×0.05=$20,000SLE = AV \times EF = \$400,000 \times 0.05 = \$20,000. Modified ALE=SLE×ARO=$20,000×0.1=$2,000ALE = SLE \times ARO = \$20,000 \times 0.1 = \$2,000.
Determines the remaining expected annual loss after deploying the control.
3
Calculate the net annual financial benefit
Net Benefit = (Initial ALEALE - Modified ALEALE) - Annual Control Cost = ($50,000\$50,000 - $2,000\$2,000) - $15,000\$15,000 = $48,000\$48,000 - $15,000\$15,000 = $33,000\$33,000.
Subtracting both the remaining risk loss and the safeguard expense from the initial loss gives the true annual cost savings.

Key Concept

Quantitative Risk Assessment and Safeguard Cost-Benefit Analysis
Estimated Time:1m 30s
Question 1645Question

An enterprise security operations team is establishing mandatory operational controls to ensure all newly deployed Linux virtual machines meet a uniform minimum level of system hardening before entering production. The documentation must specify exact mandatory technical configurations, such as disabled vulnerable protocols, default account lockouts, and required kernel parameters. Which type of security governance document should the team implement to fulfill this requirement?

Show answer & explanation

Answer: Security baseline

Answer

The team should implement a security baseline, which specifies the mandatory minimum configuration settings and hardening thresholds required for a given platform.
A security baseline provides a mandatory, standardized set of minimum security settings and technical hardening requirements for specific systems or platforms (such as Linux virtual machines). It ensures that all instances deployed into production meet an acceptable baseline level of security configuration.

Step-by-Step Solution

1
Analyze the scenario requirements
The requirement calls for a mandatory document specifying minimum technical configuration settings (e.g., disabled protocols, account lockouts) for system hardening prior to production deployment.
Identifying whether requirements are high-level directives, technical specifications, operational steps, or optional recommendations dictates the correct governance tier.
2
Evaluate document types against governance definitions
A security baseline establishes mandatory minimum security configuration standards for specific operating systems or device types.
Baselines serve as the standardized technical benchmark against which system compliance and hardening are audited.

Key Concept

Security Baselines vs. Policies, Standards, Guidelines, and Procedures
Question 1646Question

A security administrator is managing the remediation of a critical zero-day vulnerability affecting enterprise database servers. To ensure business continuity and adhere to organizational risk management policies, the administrator must execute the patch management lifecycle in a structured sequence. Arrange the operational steps below in the correct order from first to last.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct operational sequence is: (1) Analyze vendor advisories and test the patch in an isolated staging environment, (2) Submit a formal change management request for Change Advisory Board approval, (3) Apply the patch to production servers during an authorized maintenance window, and (4) Perform post-installation vulnerability scanning and baseline configuration auditing.
The standard enterprise patch management process dictates that security patches must first be tested and validated in a staging environment. Once validated, documentation and back-out plans are submitted for Change Advisory Board review. Following formal authorization, patches are deployed to production systems during designated maintenance windows, after which post-deployment scanning confirms vulnerability closure and baseline compliance.

Step-by-Step Solution

1
Validate patch functionality and stability in staging.
Identifies software conflicts and confirms patch effectiveness without risking production system uptime.
Security patches must be vetted in a non-production environment prior to enterprise change requests.
2
Obtain Change Advisory Board (CAB) review and operational approval.
Ensures stakeholder alignment, documents risk mitigation strategies, and authorizes execution details.
Enterprise change control protocol mandates formal review of testing evidence and back-out plans before production alterations.
3
Deploy the patch to production systems during scheduled maintenance windows.
Installs security fixes on live infrastructure while minimizing operational disruption to users.
Production changes should follow approved schedules to control operational risk.
4
Conduct post-deployment compliance verification and vulnerability scanning.
Confirms the flaw is successfully remediated and verifies that server configurations match established baselines.
Audit scanning closes the patch lifecycle by verifying technical control effectiveness.

Key Concept

Patch Management and Change Control Lifecycle Procedures
Question 1647Question

Match each security evaluation term on the left with its primary operational purpose or definition on the right.

Click a left item, then click its matching right item

Items

Internal Audit
External Audit
Attestation Engagement
Vulnerability Assessment

Matches

Show answer & explanation

Answer

Internal Audit matches with internal employee evaluations; External Audit matches with independent third-party evaluations; Attestation Engagement matches with formal independent practitioner opinions on assertions; Vulnerability Assessment matches with automated scanning for security weaknesses.
Each evaluation type directly matches its core operational purpose: Internal audits assess controls from within, external audits offer independent validation, attestations provide formal practitioner opinions on management assertions, and vulnerability assessments identify technical weaknesses through scanning.

Step-by-Step Solution

1
Identify internal audit characteristics
Matched Internal Audit to evaluation performed by an organization's own employees.
Internal audits provide internal assurance for executive management.
2
Identify external audit characteristics
Matched External Audit to independent third-party evaluations.
Independence is required for third-party objective verification.
3
Identify attestation characteristics
Matched Attestation Engagement to independent practitioner issuing a written report on management assertions.
Attestations (like SOC reports) formally report on specific security claims.
4
Identify vulnerability assessment characteristics
Matched Vulnerability Assessment to automated scanning for known security weaknesses.
Vulnerability scans systematically detect flaws without exploiting them.

Key Concept

Security Audit and Assessment Types
Question 1648Question

An enterprise organization is updating its continuity plan for a web server. The management team defines a requirement stating that, following an outage, data restored from backup must not be older than two hours. Which of the following business continuity parameters defines this maximum acceptable data loss timeframe?

Show answer & explanation

Answer: Recovery Point Objective (RPO)

Answer

Recovery Point Objective (RPO)
Recovery Point Objective (RPO) dictates the maximum tolerable age of unrecovered data resulting from an interruption, which determines backup frequency.

Step-by-Step Solution

1
Identify the core metric requirement from the scenario.
The scenario specifies a maximum acceptable data loss limit of two hours prior to an outage.
Determining whether the constraint refers to system recovery duration or data loss duration isolates the correct parameter.
2
Map the requirement to standard business continuity metrics.
Recovery Point Objective (RPO) is defined as the point in time to which systems and data must be restored after a disruption.
RPO directly establishes data backup frequency and allowable data loss thresholds.

Key Concept

Recovery Point Objective (RPO) vs. Recovery Time Objective (RTO)
Estimated Time:45s
Question 1649Question

A governance team at an online retail company is reviewing its security documentation hierarchy to ensure operational compliance across all engineering units. Which of the following governance document types establish mandatory requirements that all employees and system configurations must follow? (Select TWO).

Select all that apply

Show answer & explanation

Answer: High-level organizational security policies; Specific technical baseline security standards

Answer

The mandatory governance document types are high-level organizational security policies and specific technical baseline security standards.
High-level organizational security policies and specific technical baseline security standards represent compulsory components of a security framework. Policies set top-down management directives that require compliance across the entity, while standards define mandatory operational parameters and baseline controls. In contrast, guidelines, implementation whitepapers, and vendor best practices offer discretionary suggestions rather than enforceable obligations.

Step-by-Step Solution

1
Analyze the governance documentation hierarchy to separate mandatory controls from discretionary guidance.
Policies and standards/baselines carry mandatory compliance requirements across the organization.
Executive policies establish overarching business expectations, while standards mandate technical configurations and measurable compliance targets.
2
Evaluate guidelines, whitepapers, and vendor best practices against mandatory enforcement criteria.
These document types provide non-binding recommendations and reference information.
Guidelines and whitepapers offer implementation flexibility and operational advice without imposing compulsory requirements.

Key Concept

Mandatory vs. Discretionary Governance Documents
Question 1650Question

A security operations team is triaging high-priority alerts generated by a Network Intrusion Detection System (NIDS) placed between an enterprise web tier and an internal database subnet. The NIDS logs show multiple HTTP requests containing payload strings such as `UNION SELECT username, password_hash FROM user_credentials--`. Which of the following statements correctly interpret this network security monitoring alert and identify an appropriate remediation control? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The alert indicates an attempted SQL injection attack targeting backend database storage.; The security team should implement input validation and configure web application firewall rules to filter malicious database syntax.

Answer

The alert accurately identifies a SQL injection attack targeting database infrastructure, and the appropriate response involves implementing web application filtering and input validation controls.
The NIDS log entry contains classic SQL command syntax ('UNION SELECT'), which signifies a SQL injection attempt aimed at extracting confidential database records. To remediate web application layer attacks like SQL injection, organizations must implement input validation, prepared statements, and Web Application Firewall (WAF) filtering to detect and block malicious database queries.

Step-by-Step Solution

1
Analyze the NIDS alert payload syntax
The string 'UNION SELECT... FROM...' matches relational database query syntax used in database data exfiltration attempts.
Recognizing command syntax in network alerts distinguishes SQL injection from client-side script execution.
2
Differentiate web application attack types
Identify the attack as server/database targeted (SQLi) rather than end-user browser targeted (XSS).
Proper threat classification ensures the application of correct defense controls.
3
Select effective technical mitigation controls
Apply application-layer security controls including WAF rules and parameterized database queries.
WAFs inspect layer 7 HTTP traffic to block SQL commands, addressing application-level vulnerability root causes.

Key Concept

Network Intrusion Alert Interpretation and Web Application Attack Remediation
Estimated Time:1m 30s
Question 1651Question

A multinational biomedical company operating in the United States and the European Union processes continuous telemetry from connected medical devices. During a compliance audit, the enterprise privacy team notes a structural conflict between HIPAA administrative audit logging mandates, which require immutable retention of user access records for six years, and GDPR data subject rights, which grant individuals the right to erasure of personal data. Which technical implementation best satisfies both legal mandates without violating regulatory compliance?

Show answer & explanation

Answer: Maintain immutable access and transaction audit logs for the mandated retention period while pseudonymizing or anonymizing personal identifiers within the target records upon receiving a verified erasure request.

Answer

Maintain immutable access and transaction audit logs for the mandated retention period while pseudonymizing or anonymizing personal identifiers within the target records upon receiving a verified erasure request.
The correct strategy preserves mandatory HIPAA security access logs while satisfying GDPR principles by removing PII connections through anonymization or pseudonymization. Under GDPR, the right to erasure is qualified by legal obligations (such as statutory log retention requirements). Anonymizing personal identifiers within audit logs maintains audit integrity without preserving identifiable personal data.

Step-by-Step Solution

1
Analyze regulatory obligations under HIPAA and GDPR.
HIPAA requires strict 6-year retention of administrative and security audit logs to track PHI access. GDPR Article 17 mandates the right to erasure for personal data upon data subject request.
Understanding the precise scope of each regulatory framework is essential to identify overlapping and conflicting requirements.
2
Evaluate exceptions to GDPR erasure rights when legal/regulatory retention duties exist.
GDPR right to erasure is not absolute and contains explicit exceptions for compliance with a legal obligation or the establishment, exercise, or defense of legal claims.
Regulatory compliance frameworks allow data retention for mandatory audit and security purposes provided personal identification links are minimized or removed.
3
Select the control mechanism that balances immutable log retention with privacy principles.
Anonymizing or pseudonymizing the PII in audit records removes personal identifiers while retaining necessary technical audit logs for statutory retention periods.
This dual-control strategy satisfies audit trail immutability requirements without unlawfully maintaining identifiable personal data.

Key Concept

Balancing statutory audit log retention obligations with legal data subject erasure rights through technical controls like pseudonymization and anonymization.
Question 1652Question

An organization is preparing for an independent external audit to verify that its operational security controls have functioned effectively throughout the previous fiscal year. The Lead Auditor requires evidence and reports that demonstrate control performance over this extended timeframe rather than at a single point in time. Which of the following evidence sources or attestation types satisfy the auditor's requirement? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: A SOC 2 Type II attestation report evaluating the operational effectiveness of security controls over the specified 12-month window; Historical log management records and continuous monitoring evidence collected across the full 12-month timeframe

Answer

The correct selections are the SOC 2 Type II attestation report evaluating control effectiveness over the 12-month window and historical log management records collected continuously across the 12-month timeframe.
The requirement specifically calls for demonstrating operational security control effectiveness over an extended 12-month period. A SOC 2 Type II attestation report specifically covers operational effectiveness over a designated timeframe, and continuous historical log management records provide empirical evidence of ongoing control execution across that entire period.

Step-by-Step Solution

1
Analyze the audit requirement specified in the scenario
The scenario requires evidence demonstrating operational control effectiveness across an extended period (12 months), excluding single point-in-time evaluations.
Audits distinguishing between period-of-time performance and point-in-time design require longitudinal evidence.
2
Evaluate the attestation report options against the period-of-time criteria
A SOC 2 Type II report specifically evaluates operational effectiveness over a period of time, whereas a Type I report only evaluates design at a point in time.
Type II audits test whether controls actually functioned over time.
3
Evaluate the operational evidence options against the period-of-time criteria
Continuous log records spanning 12 months fulfill the longitudinal evidence requirement, whereas a single point-in-time vulnerability scan fails to reflect operational continuity.
Audit logs collected continuously demonstrate persistent control execution.

Key Concept

Distinguishing period-of-time attestation reports and evidence (SOC 2 Type II, continuous logs) from point-in-time evaluations (SOC 2 Type I, single vulnerability scans).
Question 1653Question

An organization requires an independent, formal evaluation performed by an accredited third-party organization to verify that its information security controls conform to established compliance standards. Which of the following processes best satisfies this requirement?

Show answer & explanation

Answer: External security audit

Answer

The external security audit provides an independent, accredited third-party evaluation of security controls against formal compliance standards.
An external security audit involves an independent, qualified third party evaluating an enterprise's control environment to confirm compliance with official standards, regulations, or frameworks.

Step-by-Step Solution

1
Identify the organizational requirement
The organization needs an independent, formal third-party evaluation to verify compliance standards.
Understanding the core requirement differentiates formal compliance evaluations from operational security testing.
2
Evaluate the role of an external security audit
An external security audit is conducted by an independent third party to formally assess compliance against frameworks or regulations.
External audits provide objective, certified attestation regarding compliance adherence.
3
Compare against alternative testing types
Vulnerability assessments and penetration tests measure security posture and exploitable flaws, while internal assessments lack external independence.
Technical testing methods do not replace formal audit attestations.

Key Concept

Independent Third-Party Security Audits
Question 1654Question

Match each security audit, assessment, or attestation type on the left with its primary operational purpose or defining characteristic on the right.

Click a left item, then click its matching right item

Items

SOC 1 Type II Report
SOC 2 Type I Report
SOC 3 Report
External Penetration Test Attestation

Matches

Show answer & explanation

Answer

SOC 1 Type II Report pairs with evaluating ICFR controls over a specified period. SOC 2 Type I Report pairs with assessing control design against Trust Services Criteria at a specific point in time. SOC 3 Report pairs with providing a publicly distributable summary for general audiences. External Penetration Test Attestation pairs with delivering offensive technical validation through active vulnerability exploitation.
SOC 1 reports focus on financial reporting controls (ICFR), with Type II testing effectiveness over time. SOC 2 Type I focuses on security control design at a single point in time. SOC 3 reports are high-level, public summaries of SOC 2 criteria. External penetration test attestations represent hands-on, offensive security exercises that validate defensive controls against actual exploit attempts.

Step-by-Step Solution

1
Differentiate financial audits (SOC 1) from security criteria audits (SOC 2 and SOC 3)
Identified that SOC 1 focuses specifically on controls impacting financial reporting, while SOC 2 and SOC 3 address Trust Services Criteria such as security and availability.
SOC 1 reports are mandated when a service organization's activities directly influence client financial statements.
2
Distinguish between Type I and Type II attestation scopes
Determined that Type I assesses control design at a specific point in time, whereas Type II tests control operating effectiveness over a defined duration.
Type I provides immediate snapshot baseline assurance, while Type II proves operational consistency over time.
3
Separate public reporting from technical assessment attestations
Matched SOC 3 to public executive summaries and Penetration Testing to active offensive security assessments.
SOC 3 enables broad marketing and customer confidence without exposing internal architecture, whereas penetration testing validates defensive control efficacy through simulated exploits.

Key Concept

Distinction between SOC report categories (SOC 1 vs SOC 2 vs SOC 3), report types (Type I vs Type II), and offensive security attestations.
Question 1655Question

An enterprise logistics company maintains an on-premises automated warehouse control system. A recent quantitative risk assessment revealed that a ransomware attack against the system's unpatched legacy operational technology (OT) controllers presents a Single Loss Expectancy (SLESLE) of $600,000\$600,000 with an Annual Rate of Occurrence (AROARO) of 0.250.25, yielding an inherent Annual Loss Expectancy (ALEALE) of $150,000\$150,000. Because vendor patches do not exist for the legacy OT controllers, complete system decommissioning is commercially unviable. The Chief Information Security Officer (CISO) approves a multi-part risk response: purchasing a targeted cyber insurance policy with a $20,000\$20,000 annual premium that covers up to $500,000\$500,000 of operational interruption losses per event, while deploying compensating network microsegmentation and passive anomaly detection at an annual cost of $15,000\$15,000. If the technical compensating controls successfully reduce the AROARO to 0.050.05, which of the following statements correctly evaluates the financial impact and risk response strategies implemented by the organization?

Show answer & explanation

Answer: The organization deployed risk mitigation to reduce threat frequency, achieving a net annual financial benefit of $105,000\$105,000 from technical controls, while using risk transference to address residual financial exposure.

Answer

The organization deployed risk mitigation to reduce threat frequency, achieving a net annual financial benefit of $105,000\$105,000 from technical controls, while using risk transference to address residual financial exposure.
The correct response accurately applies quantitative risk analysis formulas and risk terminology. The inherent ALE is $600,000×0.25=$150,000\$600,000 \times 0.25 = \$150,000. Technical controls lower the ARO to 0.050.05, producing a post-control ALE of $600,000×0.05=$30,000\$600,000 \times 0.05 = \$30,000. The loss reduction of $120,000\$120,000 minus the control cost of $15,000\$15,000 yields a net annual financial benefit of $105,000\$105,000. Implementing controls to lower occurrence frequency represents Risk Mitigation, whereas purchasing cyber insurance shifts financial loss liability to an insurer, representing Risk Transference.

Step-by-Step Solution

1
Calculate the inherent Annual Loss Expectancy (ALE)
ALEinherent=SLE×AROinitial=$600,000×0.25=$150,000\text{ALE}_{\text{inherent}} = \text{SLE} \times \text{ARO}_{\text{initial}} = \$600,000 \times 0.25 = \$150,000
Establishing baseline annual expected losses prior to control deployment.
2
Calculate the residual ALE following technical control deployment
ALEresidual=SLE×AROnew=$600,000×0.05=$30,000\text{ALE}_{\text{residual}} = \text{SLE} \times \text{ARO}_{\text{new}} = \$600,000 \times 0.05 = \$30,000
Determining annual expected loss after reducing threat occurrence frequency via microsegmentation and detection.
3
Calculate the net annual financial benefit of the mitigation controls
Net Benefit=(ALEinherentALEresidual)Control Cost=($150,000$30,000)$15,000=$105,000\text{Net Benefit} = (\text{ALE}_{\text{inherent}} - \text{ALE}_{\text{residual}}) - \text{Control Cost} = (\$150,000 - \$30,000) - \$15,000 = \$105,000
Subtracting annual control maintenance costs from the total annual loss reduction gives the net monetary value of the safeguard.
4
Classify the complementary risk response strategies
Technical controls reduce likelihood (Risk Mitigation), while cyber insurance shifts monetary impact to a third party (Risk Transference).
Selecting security controls and financial hedging options maps directly to CompTIA Security+ risk response definitions.

Key Concept

Quantitative Risk Assessment and Risk Response Strategy Selection
Estimated Time:2m 0s
Question 1656Question

An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.

Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).

Select all that apply

Show answer & explanation

Answer: Vishing, by using spoofed phone calls to verbally pressure the employee into bypassing controls.; Pretexting, by constructing a fraudulent narrative of a time-sensitive vendor contract to justify ignoring standard procedures.

Answer

The attack directly demonstrates vishing (using spoofed voice calls to pressure the employee) and pretexting (fabricating a time-sensitive contract scenario to bypass authorization protocols).
The scenario highlights two distinct social engineering techniques: vishing, which occurs when the attacker places a voice call pretending to be the CEO to pressure the staff member, and pretexting, which involves inventing a false scenario regarding an urgent vendor contract to persuade the staff member to bypass standard security verification.

Step-by-Step Solution

1
Analyze the communication channels used in the scenario.
Identified direct email impersonation accompanied by a phone call targeting the employee.
Social engineering attack classification depends heavily on the medium and delivery vector utilized by the threat actor.
2
Evaluate the verbal phone call component.
The phone call represents vishing (voice phishing).
Vishing specifically refers to social engineering conducted via voice telephone systems.
3
Evaluate the false narrative and justification used to bypass security controls.
The fabricated time-sensitive vendor contract represents pretexting.
Pretexting involves establishing an invented situation or identity to manipulate the target into compliance.

Key Concept

Identifying Social Engineering Vectors and Techniques
Question 1657Question

Match each social engineering incident scenario on the left with the specific social engineering attack vector utilized on the right.

Click a left item, then click its matching right item

Items

An attacker leaves malware-laden USB flash drives scattered around an enterprise facility parking lot, relying on curiosity to prompt employees to plug them into networked workstations.
An adversary compromises a legitimate third-party industry news portal frequently visited by an enterprise's defense research team to infect visiting users.
An attacker contacts a system administrator while pretending to be an external compliance auditor and invents an urgent regulatory story to request privileged user access logs.
An adversary intercepts a scheduled physical delivery of server hardware by convincing the logistics driver to deliver the shipment to a secondary unauthorized warehouse.

Matches

Show answer & explanation

Answer

Baiting corresponds to leaving malware-laden drives in parking lots; Watering Hole Attack corresponds to compromising industry news sites visited by targets; Pretexting corresponds to inventing an auditor persona to obtain logs; Diversion Theft corresponds to re-routing physical shipments.
Each attack vector relies on distinct physical or psychological mechanisms: baiting uses physical curiosity lures; watering hole attacks exploit trust in common third-party websites; pretexting builds a false authoritative scenario to extract data; and diversion theft manipulates logistics to intercept physical equipment.

Step-by-Step Solution

1
Analyze the first scenario involving physical media placed in parking lots to exploit victim curiosity.
Identify this as Baiting because it promises a lure (curiosity/free media) to deliver malicious payloads.
Baiting specifically leverages physical or digital enticement to convince victims to compromise security.
2
Analyze the second scenario involving a compromised third-party website regularly visited by target personnel.
Identify this as a Watering Hole Attack.
Watering hole attacks profile target web habits and infect a trusted watering hole site.
3
Analyze the third scenario where an attacker creates a false persona and fake urgency to extract information.
Identify this as Pretexting.
Pretexting requires constructing a believable role and scenario (the pretext) to trick a target into providing data or access.
4
Analyze the fourth scenario where physical shipments are rerouted during transit.
Identify this as Diversion Theft.
Diversion theft specifically targets transport, courier, or delivery supply chains to intercept physical assets.

Key Concept

Social Engineering Attack Vectors and Methods
Question 1658Question

Match each Business Impact Analysis (BIA) and business continuity metric on the left to its corresponding operational definition on the right.

Click a left item, then click its matching right item

Items

Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Mean Time Between Failures (MTBF)
Mean Time to Repair (MTTR)

Matches

Show answer & explanation

Answer

Recovery Time Objective matches the targeted maximum duration of system downtime. Recovery Point Objective matches the maximum acceptable time period of data loss. Mean Time Between Failures matches the statistical average operational time before breaking down. Mean Time to Repair matches the average time required to diagnose, fix, and restore a component.
Each business continuity term is accurately paired with its primary metric definition: Recovery Time Objective defines maximum allowed service disruption time; Recovery Point Objective defines allowable data loss age; Mean Time Between Failures measures operational lifespan between breakdowns; and Mean Time to Repair measures mean resolution duration.

Step-by-Step Solution

1
Differentiate downtime metrics from data loss metrics.
Recovery Time Objective (RTO) governs acceptable downtime duration, whereas Recovery Point Objective (RPO) governs tolerable data loss back-time.
RTO focuses on service restoration timing, while RPO determines necessary backup frequency to limit lost transactions.
2
Differentiate failure frequency metrics from service restoration metrics.
Mean Time Between Failures (MTBF) measures continuous uptime reliability, whereas Mean Time to Repair (MTTR) measures mean duration of maintenance.
MTBF quantifies how often failures occur over time, while MTTR quantifies how quickly repairs are completed.

Key Concept

Business Impact Analysis Operational Metrics (RTO, RPO, MTBF, MTTR)
Estimated Time:1m 0s
Question 1659Question

An enterprise online payment gateway has established a Maximum Tolerable Downtime (MTD) of 44 hours and a Recovery Point Objective (RPO) of 1515 minutes for its transactional core. During a disaster recovery test following a simulated primary facility outage, engineers observe that data replication occurs at 1010-minute intervals, secondary virtual infrastructure deployment requires 22 hours, and database state restoration and integrity verification require an additional 2.52.5 hours before operations can resume. Which of the following statements accurately evaluates the organization's current business continuity posture?

Show answer & explanation

Answer: The calculated Recovery Time Objective (RTO) of 4.54.5 hours exceeds the Maximum Tolerable Downtime (MTD), creating unacceptable operational risk.

Answer

The calculated Recovery Time Objective (RTO) of 4.54.5 hours exceeds the Maximum Tolerable Downtime (MTD), creating unacceptable operational risk.
The scenario describes infrastructure deployment (22 hours) and system restoration/verification (2.52.5 hours), yielding a total recovery duration (RTO) of 4.54.5 hours. Because MTD is the absolute limit of acceptable outage time (44 hours), an RTO of 4.54.5 hours violates MTD criteria.

Step-by-Step Solution

1
Calculate the total Recovery Time Objective (RTO) from the scenario metrics.
Infrastructure deployment (22 hours) ++ State restoration and integrity verification (2.52.5 hours) == 4.54.5 hours total recovery time.
RTO includes the overall timeframe necessary to restore systems and data to an operational state.
2
Evaluate the Recovery Point Objective (RPO) metric against replication frequency.
Replication interval is 1010 minutes, which is within the allowable 1515-minute RPO threshold.
Data loss is bounded by the 1010-minute replication gap, satisfying the RPO requirement.
3
Compare total RTO against Maximum Tolerable Downtime (MTD).
Total RTO (4.54.5 hours) >> MTD (44 hours).
An RTO exceeding MTD indicates the system cannot be recovered before irreparable business damage occurs.

Key Concept

Alignment of Recovery Time Objective (RTO) and Maximum Tolerable Downtime (MTD) in Business Impact Analysis
Question 1660Question

An enterprise logistics organization is updating its security governance documentation framework following an audit review. As part of this initiative, the information security team publishes a document outlining recommended best practices for securing remote home-office wireless routers. The document offers advisory tips for optimizing router posture but explicitly leaves compliance to the discretion of individual employees. Which of the following document types within the security governance hierarchy best categorizes this publication?

Show answer & explanation

Answer: Guideline

Answer

The published document is a Guideline because it provides advisory recommendations and best practices with discretionary compliance rather than mandatory enforcement.
In security governance, Guidelines represent advisory, non-mandatory documentation that offers recommendations and best practices. Because the logistics organization's document provides router security advice while leaving compliance optional for employees, it strictly meets the definition of a Guideline.

Step-by-Step Solution

1
Analyze the operational intent and enforcement nature of the document in the scenario.
The document contains recommended best practices and tips where compliance is explicitly discretionary.
Governance documents are categorized primarily by whether they are mandatory or advisory.
2
Evaluate the governance document hierarchy definitions against the scenario characteristics.
Guidelines are optional/discretionary best practices; Policies define high-level management intent; Standards establish mandatory requirements; Baselines define minimum mandatory configurations; Procedures detail step-by-step instructions.
Identifying the distinct enforcement level of each governance tier determines the proper classification.
3
Select the governance document type that matches optional recommendations.
Guideline is the correct document type.
Only guidelines represent non-mandatory recommendations within standard security policy frameworks.

Key Concept

Security Governance Policy Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
PreviousPage 83 / 112Next
All practice questions — CompTIA Security+ | Examkin