Tüm alıştırma soruları

2232 soru

Soru 1641Soru

A cloud-hosted video rendering cluster maintained by a media organization has an estimated Asset Value (AVAV) of $1,500,000\$1,500,000. Operational metrics show that ransomware incidents targeting the rendering nodes have an Annualized Rate of Occurrence (AROARO) of 0.200.20 and an unmitigated Exposure Factor (EFEF) of 0.500.50. The organization deploys an automated immutable backup solution costing $25,000\$25,000 annually. With this safeguard in place, the Exposure Factor (EFEF) for ransomware attacks drops to 0.100.10, while the AROARO remains unchanged at 0.200.20. What is the net annual financial benefit (in USD) realized by implementing this security control?

Cevabı ve açıklamayı göster

Cevap: 95000

Cevap

The net annual financial benefit realized by implementing the safeguard is $95,000.
The baseline Annualized Loss Expectancy (ALE) is calculated as AV×EF×ARO=$1,500,000×0.50×0.20=$150,000AV \times EF \times ARO = \$1,500,000 \times 0.50 \times 0.20 = \$150,000. With the control active, the mitigated ALE becomes $1,500,000×0.10×0.20=$30,000\$1,500,000 \times 0.10 \times 0.20 = \$30,000, resulting in an annual loss reduction of $120,000\$120,000. Subtracting the annual safeguard maintenance cost of $25,000\$25,000 yields a net annual financial benefit of $95,000\$95,000.

Adım Adım Çözüm

1
Calculate the initial Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE)
Initial SLE = $1,500,000×0.50=$750,000\$1,500,000 \times 0.50 = \$750,000; Initial ALE = $750,000×0.20=$150,000\$750,000 \times 0.20 = \$150,000.
Establishes baseline financial risk exposure prior to implementing security controls.
2
Calculate the post-mitigation Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE)
Post-mitigation SLE = $1,500,000×0.10=$150,000\$1,500,000 \times 0.10 = \$150,000; Post-mitigation ALE = $150,000×0.20=$30,000\$150,000 \times 0.20 = \$30,000.
Determines the remaining annualized loss after applying the Exposure Factor reduction.
3
Calculate net annual benefit by subtracting safeguard cost from ALE reduction
ALE Reduction = $150,000$30,000=$120,000\$150,000 - \$30,000 = \$120,000; Net Benefit = $120,000$25,000=$95,000\$120,000 - \$25,000 = \$95,000.
Evaluates the overall cost-effectiveness of the control solution.

Anahtar Kavram

Quantitative Risk Analysis - Net Annual Safeguard Value
Soru 1642Soru

A regional hospital network is evaluating a software provider to host patient portal data in a public cloud deployment. The hospital's compliance policy mandates independent verification that the cloud vendor's security, confidentiality, and availability controls operate effectively over a continuous 12-month monitoring period. Which of the following attestation reports should the hospital request from the vendor?

Cevabı ve açıklamayı göster

Cevap: SOC 2 Type II report

Cevap

The hospital network should request a SOC 2 Type II report.
The SOC 2 Type II report aligns with the Trust Services Criteria (security, availability, confidentiality) and assesses whether controls were operating effectively throughout a specified testing window (such as 12 months).

Adım Adım Çözüm

1
Determine the subject domain of the controls required.
The requirement focuses on security, confidentiality, and availability controls for patient data rather than financial reporting controls.
SOC 2 reports directly evaluate security and privacy under the Trust Services Criteria, whereas SOC 1 reports evaluate internal controls over financial reporting.
2
Evaluate the required time scope of auditor verification.
The hospital requires verification of operational effectiveness over a continuous 12-month period.
Type II reports test and verify control execution over a sustained period, whereas Type I reports assess control design at a single point in time.

Anahtar Kavram

Distinguishing SOC Report Scope and Attestation Types
Soru 1643Soru

An international cloud technology enterprise processes user telemetry and account details for customers residing in the European Union. To comply with privacy laws governing large-scale handling of personal information, the enterprise must appoint an individual responsible for monitoring regulatory compliance, conducting privacy impact assessments, and serving as the primary liaison to supervisory authorities. Which of the following governance roles is specifically designated for these statutory duties?

Cevabı ve açıklamayı göster

Cevap: Data Protection Officer

Cevap

The role specifically designated for statutory privacy monitoring, impact assessments, and regulatory liaising is the Data Protection Officer.
The Data Protection Officer is responsible for ensuring an organization adheres to privacy laws, advising on Data Protection Impact Assessments (DPIAs), and acting as the official contact point for data protection authorities and data subjects.

Adım Adım Çözüm

1
Identify the regulatory context and required organizational duties
The scenario requires an independent role responsible for monitoring data privacy compliance and communicating with supervisory authorities under EU privacy regulations.
Privacy regulations mandate specific oversight structures when organizations handle personal data at scale.
2
Evaluate the responsibilities of standard security and data management roles
Technical roles such as Data Custodians and Database Administrators manage IT systems, while executive roles like the CISO handle overall corporate security strategy.
These operational and management roles do not satisfy the statutory mandate for independent privacy regulation oversight.
3
Select the designated statutory role matching the regulatory requirements
The Data Protection Officer (DPO) is the formal title and role defined by privacy frameworks to fulfill regulatory compliance monitoring.
The DPO role is explicitly framed with the authority and independence required by international privacy laws.

Anahtar Kavram

Data Protection Officer (DPO) role and compliance mandates under privacy regulations
Tahmini Süre:45s
Soru 1644Soru

A cloud SaaS provider is evaluating a quantitative risk mitigation strategy for its primary customer invoicing repository, which has an Asset Value (AVAV) of $400,000\$400,000. Security assessment data indicates an unmitigated ransomware threat has an Exposure Factor (EFEF) of 25%25\% and an Annual Rate of Occurrence (AROARO) of 0.50.5. The organization is considering deploying an automated threat prevention platform costing $15,000\$15,000 per year, which is expected to reduce the EFEF to 5%5\% and the AROARO to 0.10.1. What is the net annual financial benefit of implementing this security control?

Cevabı ve açıklamayı göster

Cevap: $33,000\$33,000

Cevap

The net annual financial benefit of implementing the security safeguard is $33,000\$33,000.
The net annual benefit of a security safeguard is calculated as the initial Annual Loss Expectancy (ALEALE) minus the post-mitigation ALEALE, minus the annual cost of the safeguard. The initial ALEALE is $400,000×0.25×0.5=$50,000\$400,000 \times 0.25 \times 0.5 = \$50,000. The modified ALEALE is $400,000×0.05×0.1=$2,000\$400,000 \times 0.05 \times 0.1 = \$2,000. Subtracting the modified ALEALE ($2,000\$2,000) and the control cost ($15,000\$15,000) from the initial ALEALE ($50,000\$50,000) yields a net benefit of $33,000\$33,000.

Adım Adım Çözüm

1
Calculate the initial (pre-mitigation) Annual Loss Expectancy (ALE)
Initial SLE=AV×EF=$400,000×0.25=$100,000SLE = AV \times EF = \$400,000 \times 0.25 = \$100,000. Initial ALE=SLE×ARO=$100,000×0.5=$50,000ALE = SLE \times ARO = \$100,000 \times 0.5 = \$50,000.
Determines the baseline expected financial loss per year without the safeguard.
2
Calculate the modified (post-mitigation) Annual Loss Expectancy (ALE)
Modified SLE=AV×EF=$400,000×0.05=$20,000SLE = AV \times EF = \$400,000 \times 0.05 = \$20,000. Modified ALE=SLE×ARO=$20,000×0.1=$2,000ALE = SLE \times ARO = \$20,000 \times 0.1 = \$2,000.
Determines the remaining expected annual loss after deploying the control.
3
Calculate the net annual financial benefit
Net Benefit = (Initial ALEALE - Modified ALEALE) - Annual Control Cost = ($50,000\$50,000 - $2,000\$2,000) - $15,000\$15,000 = $48,000\$48,000 - $15,000\$15,000 = $33,000\$33,000.
Subtracting both the remaining risk loss and the safeguard expense from the initial loss gives the true annual cost savings.

Anahtar Kavram

Quantitative Risk Assessment and Safeguard Cost-Benefit Analysis
Tahmini Süre:1m 30s
Soru 1645Soru

An enterprise security operations team is establishing mandatory operational controls to ensure all newly deployed Linux virtual machines meet a uniform minimum level of system hardening before entering production. The documentation must specify exact mandatory technical configurations, such as disabled vulnerable protocols, default account lockouts, and required kernel parameters. Which type of security governance document should the team implement to fulfill this requirement?

Cevabı ve açıklamayı göster

Cevap: Security baseline

Cevap

The team should implement a security baseline, which specifies the mandatory minimum configuration settings and hardening thresholds required for a given platform.
A security baseline provides a mandatory, standardized set of minimum security settings and technical hardening requirements for specific systems or platforms (such as Linux virtual machines). It ensures that all instances deployed into production meet an acceptable baseline level of security configuration.

Adım Adım Çözüm

1
Analyze the scenario requirements
The requirement calls for a mandatory document specifying minimum technical configuration settings (e.g., disabled protocols, account lockouts) for system hardening prior to production deployment.
Identifying whether requirements are high-level directives, technical specifications, operational steps, or optional recommendations dictates the correct governance tier.
2
Evaluate document types against governance definitions
A security baseline establishes mandatory minimum security configuration standards for specific operating systems or device types.
Baselines serve as the standardized technical benchmark against which system compliance and hardening are audited.

Anahtar Kavram

Security Baselines vs. Policies, Standards, Guidelines, and Procedures
Soru 1646Soru

A security administrator is managing the remediation of a critical zero-day vulnerability affecting enterprise database servers. To ensure business continuity and adhere to organizational risk management policies, the administrator must execute the patch management lifecycle in a structured sequence. Arrange the operational steps below in the correct order from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct operational sequence is: (1) Analyze vendor advisories and test the patch in an isolated staging environment, (2) Submit a formal change management request for Change Advisory Board approval, (3) Apply the patch to production servers during an authorized maintenance window, and (4) Perform post-installation vulnerability scanning and baseline configuration auditing.
The standard enterprise patch management process dictates that security patches must first be tested and validated in a staging environment. Once validated, documentation and back-out plans are submitted for Change Advisory Board review. Following formal authorization, patches are deployed to production systems during designated maintenance windows, after which post-deployment scanning confirms vulnerability closure and baseline compliance.

Adım Adım Çözüm

1
Validate patch functionality and stability in staging.
Identifies software conflicts and confirms patch effectiveness without risking production system uptime.
Security patches must be vetted in a non-production environment prior to enterprise change requests.
2
Obtain Change Advisory Board (CAB) review and operational approval.
Ensures stakeholder alignment, documents risk mitigation strategies, and authorizes execution details.
Enterprise change control protocol mandates formal review of testing evidence and back-out plans before production alterations.
3
Deploy the patch to production systems during scheduled maintenance windows.
Installs security fixes on live infrastructure while minimizing operational disruption to users.
Production changes should follow approved schedules to control operational risk.
4
Conduct post-deployment compliance verification and vulnerability scanning.
Confirms the flaw is successfully remediated and verifies that server configurations match established baselines.
Audit scanning closes the patch lifecycle by verifying technical control effectiveness.

Anahtar Kavram

Patch Management and Change Control Lifecycle Procedures
Soru 1647Soru

Match each security evaluation term on the left with its primary operational purpose or definition on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Internal Audit
External Audit
Attestation Engagement
Vulnerability Assessment

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Internal Audit matches with internal employee evaluations; External Audit matches with independent third-party evaluations; Attestation Engagement matches with formal independent practitioner opinions on assertions; Vulnerability Assessment matches with automated scanning for security weaknesses.
Each evaluation type directly matches its core operational purpose: Internal audits assess controls from within, external audits offer independent validation, attestations provide formal practitioner opinions on management assertions, and vulnerability assessments identify technical weaknesses through scanning.

Adım Adım Çözüm

1
Identify internal audit characteristics
Matched Internal Audit to evaluation performed by an organization's own employees.
Internal audits provide internal assurance for executive management.
2
Identify external audit characteristics
Matched External Audit to independent third-party evaluations.
Independence is required for third-party objective verification.
3
Identify attestation characteristics
Matched Attestation Engagement to independent practitioner issuing a written report on management assertions.
Attestations (like SOC reports) formally report on specific security claims.
4
Identify vulnerability assessment characteristics
Matched Vulnerability Assessment to automated scanning for known security weaknesses.
Vulnerability scans systematically detect flaws without exploiting them.

Anahtar Kavram

Security Audit and Assessment Types
Soru 1648Soru

An enterprise organization is updating its continuity plan for a web server. The management team defines a requirement stating that, following an outage, data restored from backup must not be older than two hours. Which of the following business continuity parameters defines this maximum acceptable data loss timeframe?

Cevabı ve açıklamayı göster

Cevap: Recovery Point Objective (RPO)

Cevap

Recovery Point Objective (RPO)
Recovery Point Objective (RPO) dictates the maximum tolerable age of unrecovered data resulting from an interruption, which determines backup frequency.

Adım Adım Çözüm

1
Identify the core metric requirement from the scenario.
The scenario specifies a maximum acceptable data loss limit of two hours prior to an outage.
Determining whether the constraint refers to system recovery duration or data loss duration isolates the correct parameter.
2
Map the requirement to standard business continuity metrics.
Recovery Point Objective (RPO) is defined as the point in time to which systems and data must be restored after a disruption.
RPO directly establishes data backup frequency and allowable data loss thresholds.

Anahtar Kavram

Recovery Point Objective (RPO) vs. Recovery Time Objective (RTO)
Tahmini Süre:45s
Soru 1649Soru

A governance team at an online retail company is reviewing its security documentation hierarchy to ensure operational compliance across all engineering units. Which of the following governance document types establish mandatory requirements that all employees and system configurations must follow? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: High-level organizational security policies; Specific technical baseline security standards

Cevap

The mandatory governance document types are high-level organizational security policies and specific technical baseline security standards.
High-level organizational security policies and specific technical baseline security standards represent compulsory components of a security framework. Policies set top-down management directives that require compliance across the entity, while standards define mandatory operational parameters and baseline controls. In contrast, guidelines, implementation whitepapers, and vendor best practices offer discretionary suggestions rather than enforceable obligations.

Adım Adım Çözüm

1
Analyze the governance documentation hierarchy to separate mandatory controls from discretionary guidance.
Policies and standards/baselines carry mandatory compliance requirements across the organization.
Executive policies establish overarching business expectations, while standards mandate technical configurations and measurable compliance targets.
2
Evaluate guidelines, whitepapers, and vendor best practices against mandatory enforcement criteria.
These document types provide non-binding recommendations and reference information.
Guidelines and whitepapers offer implementation flexibility and operational advice without imposing compulsory requirements.

Anahtar Kavram

Mandatory vs. Discretionary Governance Documents
Soru 1650Soru

A security operations team is triaging high-priority alerts generated by a Network Intrusion Detection System (NIDS) placed between an enterprise web tier and an internal database subnet. The NIDS logs show multiple HTTP requests containing payload strings such as `UNION SELECT username, password_hash FROM user_credentials--`. Which of the following statements correctly interpret this network security monitoring alert and identify an appropriate remediation control? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The alert indicates an attempted SQL injection attack targeting backend database storage.; The security team should implement input validation and configure web application firewall rules to filter malicious database syntax.

Cevap

The alert accurately identifies a SQL injection attack targeting database infrastructure, and the appropriate response involves implementing web application filtering and input validation controls.
The NIDS log entry contains classic SQL command syntax ('UNION SELECT'), which signifies a SQL injection attempt aimed at extracting confidential database records. To remediate web application layer attacks like SQL injection, organizations must implement input validation, prepared statements, and Web Application Firewall (WAF) filtering to detect and block malicious database queries.

Adım Adım Çözüm

1
Analyze the NIDS alert payload syntax
The string 'UNION SELECT... FROM...' matches relational database query syntax used in database data exfiltration attempts.
Recognizing command syntax in network alerts distinguishes SQL injection from client-side script execution.
2
Differentiate web application attack types
Identify the attack as server/database targeted (SQLi) rather than end-user browser targeted (XSS).
Proper threat classification ensures the application of correct defense controls.
3
Select effective technical mitigation controls
Apply application-layer security controls including WAF rules and parameterized database queries.
WAFs inspect layer 7 HTTP traffic to block SQL commands, addressing application-level vulnerability root causes.

Anahtar Kavram

Network Intrusion Alert Interpretation and Web Application Attack Remediation
Tahmini Süre:1m 30s
Soru 1651Soru

A multinational biomedical company operating in the United States and the European Union processes continuous telemetry from connected medical devices. During a compliance audit, the enterprise privacy team notes a structural conflict between HIPAA administrative audit logging mandates, which require immutable retention of user access records for six years, and GDPR data subject rights, which grant individuals the right to erasure of personal data. Which technical implementation best satisfies both legal mandates without violating regulatory compliance?

Cevabı ve açıklamayı göster

Cevap: Maintain immutable access and transaction audit logs for the mandated retention period while pseudonymizing or anonymizing personal identifiers within the target records upon receiving a verified erasure request.

Cevap

Maintain immutable access and transaction audit logs for the mandated retention period while pseudonymizing or anonymizing personal identifiers within the target records upon receiving a verified erasure request.
The correct strategy preserves mandatory HIPAA security access logs while satisfying GDPR principles by removing PII connections through anonymization or pseudonymization. Under GDPR, the right to erasure is qualified by legal obligations (such as statutory log retention requirements). Anonymizing personal identifiers within audit logs maintains audit integrity without preserving identifiable personal data.

Adım Adım Çözüm

1
Analyze regulatory obligations under HIPAA and GDPR.
HIPAA requires strict 6-year retention of administrative and security audit logs to track PHI access. GDPR Article 17 mandates the right to erasure for personal data upon data subject request.
Understanding the precise scope of each regulatory framework is essential to identify overlapping and conflicting requirements.
2
Evaluate exceptions to GDPR erasure rights when legal/regulatory retention duties exist.
GDPR right to erasure is not absolute and contains explicit exceptions for compliance with a legal obligation or the establishment, exercise, or defense of legal claims.
Regulatory compliance frameworks allow data retention for mandatory audit and security purposes provided personal identification links are minimized or removed.
3
Select the control mechanism that balances immutable log retention with privacy principles.
Anonymizing or pseudonymizing the PII in audit records removes personal identifiers while retaining necessary technical audit logs for statutory retention periods.
This dual-control strategy satisfies audit trail immutability requirements without unlawfully maintaining identifiable personal data.

Anahtar Kavram

Balancing statutory audit log retention obligations with legal data subject erasure rights through technical controls like pseudonymization and anonymization.
Soru 1652Soru

An organization is preparing for an independent external audit to verify that its operational security controls have functioned effectively throughout the previous fiscal year. The Lead Auditor requires evidence and reports that demonstrate control performance over this extended timeframe rather than at a single point in time. Which of the following evidence sources or attestation types satisfy the auditor's requirement? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A SOC 2 Type II attestation report evaluating the operational effectiveness of security controls over the specified 12-month window; Historical log management records and continuous monitoring evidence collected across the full 12-month timeframe

Cevap

The correct selections are the SOC 2 Type II attestation report evaluating control effectiveness over the 12-month window and historical log management records collected continuously across the 12-month timeframe.
The requirement specifically calls for demonstrating operational security control effectiveness over an extended 12-month period. A SOC 2 Type II attestation report specifically covers operational effectiveness over a designated timeframe, and continuous historical log management records provide empirical evidence of ongoing control execution across that entire period.

Adım Adım Çözüm

1
Analyze the audit requirement specified in the scenario
The scenario requires evidence demonstrating operational control effectiveness across an extended period (12 months), excluding single point-in-time evaluations.
Audits distinguishing between period-of-time performance and point-in-time design require longitudinal evidence.
2
Evaluate the attestation report options against the period-of-time criteria
A SOC 2 Type II report specifically evaluates operational effectiveness over a period of time, whereas a Type I report only evaluates design at a point in time.
Type II audits test whether controls actually functioned over time.
3
Evaluate the operational evidence options against the period-of-time criteria
Continuous log records spanning 12 months fulfill the longitudinal evidence requirement, whereas a single point-in-time vulnerability scan fails to reflect operational continuity.
Audit logs collected continuously demonstrate persistent control execution.

Anahtar Kavram

Distinguishing period-of-time attestation reports and evidence (SOC 2 Type II, continuous logs) from point-in-time evaluations (SOC 2 Type I, single vulnerability scans).
Soru 1653Soru

An organization requires an independent, formal evaluation performed by an accredited third-party organization to verify that its information security controls conform to established compliance standards. Which of the following processes best satisfies this requirement?

Cevabı ve açıklamayı göster

Cevap: External security audit

Cevap

The external security audit provides an independent, accredited third-party evaluation of security controls against formal compliance standards.
An external security audit involves an independent, qualified third party evaluating an enterprise's control environment to confirm compliance with official standards, regulations, or frameworks.

Adım Adım Çözüm

1
Identify the organizational requirement
The organization needs an independent, formal third-party evaluation to verify compliance standards.
Understanding the core requirement differentiates formal compliance evaluations from operational security testing.
2
Evaluate the role of an external security audit
An external security audit is conducted by an independent third party to formally assess compliance against frameworks or regulations.
External audits provide objective, certified attestation regarding compliance adherence.
3
Compare against alternative testing types
Vulnerability assessments and penetration tests measure security posture and exploitable flaws, while internal assessments lack external independence.
Technical testing methods do not replace formal audit attestations.

Anahtar Kavram

Independent Third-Party Security Audits
Soru 1654Soru

Match each security audit, assessment, or attestation type on the left with its primary operational purpose or defining characteristic on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

SOC 1 Type II Report
SOC 2 Type I Report
SOC 3 Report
External Penetration Test Attestation

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

SOC 1 Type II Report pairs with evaluating ICFR controls over a specified period. SOC 2 Type I Report pairs with assessing control design against Trust Services Criteria at a specific point in time. SOC 3 Report pairs with providing a publicly distributable summary for general audiences. External Penetration Test Attestation pairs with delivering offensive technical validation through active vulnerability exploitation.
SOC 1 reports focus on financial reporting controls (ICFR), with Type II testing effectiveness over time. SOC 2 Type I focuses on security control design at a single point in time. SOC 3 reports are high-level, public summaries of SOC 2 criteria. External penetration test attestations represent hands-on, offensive security exercises that validate defensive controls against actual exploit attempts.

Adım Adım Çözüm

1
Differentiate financial audits (SOC 1) from security criteria audits (SOC 2 and SOC 3)
Identified that SOC 1 focuses specifically on controls impacting financial reporting, while SOC 2 and SOC 3 address Trust Services Criteria such as security and availability.
SOC 1 reports are mandated when a service organization's activities directly influence client financial statements.
2
Distinguish between Type I and Type II attestation scopes
Determined that Type I assesses control design at a specific point in time, whereas Type II tests control operating effectiveness over a defined duration.
Type I provides immediate snapshot baseline assurance, while Type II proves operational consistency over time.
3
Separate public reporting from technical assessment attestations
Matched SOC 3 to public executive summaries and Penetration Testing to active offensive security assessments.
SOC 3 enables broad marketing and customer confidence without exposing internal architecture, whereas penetration testing validates defensive control efficacy through simulated exploits.

Anahtar Kavram

Distinction between SOC report categories (SOC 1 vs SOC 2 vs SOC 3), report types (Type I vs Type II), and offensive security attestations.
Soru 1655Soru

An enterprise logistics company maintains an on-premises automated warehouse control system. A recent quantitative risk assessment revealed that a ransomware attack against the system's unpatched legacy operational technology (OT) controllers presents a Single Loss Expectancy (SLESLE) of $600,000\$600,000 with an Annual Rate of Occurrence (AROARO) of 0.250.25, yielding an inherent Annual Loss Expectancy (ALEALE) of $150,000\$150,000. Because vendor patches do not exist for the legacy OT controllers, complete system decommissioning is commercially unviable. The Chief Information Security Officer (CISO) approves a multi-part risk response: purchasing a targeted cyber insurance policy with a $20,000\$20,000 annual premium that covers up to $500,000\$500,000 of operational interruption losses per event, while deploying compensating network microsegmentation and passive anomaly detection at an annual cost of $15,000\$15,000. If the technical compensating controls successfully reduce the AROARO to 0.050.05, which of the following statements correctly evaluates the financial impact and risk response strategies implemented by the organization?

Cevabı ve açıklamayı göster

Cevap: The organization deployed risk mitigation to reduce threat frequency, achieving a net annual financial benefit of $105,000\$105,000 from technical controls, while using risk transference to address residual financial exposure.

Cevap

The organization deployed risk mitigation to reduce threat frequency, achieving a net annual financial benefit of $105,000\$105,000 from technical controls, while using risk transference to address residual financial exposure.
The correct response accurately applies quantitative risk analysis formulas and risk terminology. The inherent ALE is $600,000×0.25=$150,000\$600,000 \times 0.25 = \$150,000. Technical controls lower the ARO to 0.050.05, producing a post-control ALE of $600,000×0.05=$30,000\$600,000 \times 0.05 = \$30,000. The loss reduction of $120,000\$120,000 minus the control cost of $15,000\$15,000 yields a net annual financial benefit of $105,000\$105,000. Implementing controls to lower occurrence frequency represents Risk Mitigation, whereas purchasing cyber insurance shifts financial loss liability to an insurer, representing Risk Transference.

Adım Adım Çözüm

1
Calculate the inherent Annual Loss Expectancy (ALE)
ALEinherent=SLE×AROinitial=$600,000×0.25=$150,000\text{ALE}_{\text{inherent}} = \text{SLE} \times \text{ARO}_{\text{initial}} = \$600,000 \times 0.25 = \$150,000
Establishing baseline annual expected losses prior to control deployment.
2
Calculate the residual ALE following technical control deployment
ALEresidual=SLE×AROnew=$600,000×0.05=$30,000\text{ALE}_{\text{residual}} = \text{SLE} \times \text{ARO}_{\text{new}} = \$600,000 \times 0.05 = \$30,000
Determining annual expected loss after reducing threat occurrence frequency via microsegmentation and detection.
3
Calculate the net annual financial benefit of the mitigation controls
Net Benefit=(ALEinherentALEresidual)Control Cost=($150,000$30,000)$15,000=$105,000\text{Net Benefit} = (\text{ALE}_{\text{inherent}} - \text{ALE}_{\text{residual}}) - \text{Control Cost} = (\$150,000 - \$30,000) - \$15,000 = \$105,000
Subtracting annual control maintenance costs from the total annual loss reduction gives the net monetary value of the safeguard.
4
Classify the complementary risk response strategies
Technical controls reduce likelihood (Risk Mitigation), while cyber insurance shifts monetary impact to a third party (Risk Transference).
Selecting security controls and financial hedging options maps directly to CompTIA Security+ risk response definitions.

Anahtar Kavram

Quantitative Risk Assessment and Risk Response Strategy Selection
Tahmini Süre:2m 0s
Soru 1656Soru

An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.

Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Vishing, by using spoofed phone calls to verbally pressure the employee into bypassing controls.; Pretexting, by constructing a fraudulent narrative of a time-sensitive vendor contract to justify ignoring standard procedures.

Cevap

The attack directly demonstrates vishing (using spoofed voice calls to pressure the employee) and pretexting (fabricating a time-sensitive contract scenario to bypass authorization protocols).
The scenario highlights two distinct social engineering techniques: vishing, which occurs when the attacker places a voice call pretending to be the CEO to pressure the staff member, and pretexting, which involves inventing a false scenario regarding an urgent vendor contract to persuade the staff member to bypass standard security verification.

Adım Adım Çözüm

1
Analyze the communication channels used in the scenario.
Identified direct email impersonation accompanied by a phone call targeting the employee.
Social engineering attack classification depends heavily on the medium and delivery vector utilized by the threat actor.
2
Evaluate the verbal phone call component.
The phone call represents vishing (voice phishing).
Vishing specifically refers to social engineering conducted via voice telephone systems.
3
Evaluate the false narrative and justification used to bypass security controls.
The fabricated time-sensitive vendor contract represents pretexting.
Pretexting involves establishing an invented situation or identity to manipulate the target into compliance.

Anahtar Kavram

Identifying Social Engineering Vectors and Techniques
Soru 1657Soru

Match each social engineering incident scenario on the left with the specific social engineering attack vector utilized on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An attacker leaves malware-laden USB flash drives scattered around an enterprise facility parking lot, relying on curiosity to prompt employees to plug them into networked workstations.
An adversary compromises a legitimate third-party industry news portal frequently visited by an enterprise's defense research team to infect visiting users.
An attacker contacts a system administrator while pretending to be an external compliance auditor and invents an urgent regulatory story to request privileged user access logs.
An adversary intercepts a scheduled physical delivery of server hardware by convincing the logistics driver to deliver the shipment to a secondary unauthorized warehouse.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Baiting corresponds to leaving malware-laden drives in parking lots; Watering Hole Attack corresponds to compromising industry news sites visited by targets; Pretexting corresponds to inventing an auditor persona to obtain logs; Diversion Theft corresponds to re-routing physical shipments.
Each attack vector relies on distinct physical or psychological mechanisms: baiting uses physical curiosity lures; watering hole attacks exploit trust in common third-party websites; pretexting builds a false authoritative scenario to extract data; and diversion theft manipulates logistics to intercept physical equipment.

Adım Adım Çözüm

1
Analyze the first scenario involving physical media placed in parking lots to exploit victim curiosity.
Identify this as Baiting because it promises a lure (curiosity/free media) to deliver malicious payloads.
Baiting specifically leverages physical or digital enticement to convince victims to compromise security.
2
Analyze the second scenario involving a compromised third-party website regularly visited by target personnel.
Identify this as a Watering Hole Attack.
Watering hole attacks profile target web habits and infect a trusted watering hole site.
3
Analyze the third scenario where an attacker creates a false persona and fake urgency to extract information.
Identify this as Pretexting.
Pretexting requires constructing a believable role and scenario (the pretext) to trick a target into providing data or access.
4
Analyze the fourth scenario where physical shipments are rerouted during transit.
Identify this as Diversion Theft.
Diversion theft specifically targets transport, courier, or delivery supply chains to intercept physical assets.

Anahtar Kavram

Social Engineering Attack Vectors and Methods
Soru 1658Soru

Match each Business Impact Analysis (BIA) and business continuity metric on the left to its corresponding operational definition on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Mean Time Between Failures (MTBF)
Mean Time to Repair (MTTR)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Recovery Time Objective matches the targeted maximum duration of system downtime. Recovery Point Objective matches the maximum acceptable time period of data loss. Mean Time Between Failures matches the statistical average operational time before breaking down. Mean Time to Repair matches the average time required to diagnose, fix, and restore a component.
Each business continuity term is accurately paired with its primary metric definition: Recovery Time Objective defines maximum allowed service disruption time; Recovery Point Objective defines allowable data loss age; Mean Time Between Failures measures operational lifespan between breakdowns; and Mean Time to Repair measures mean resolution duration.

Adım Adım Çözüm

1
Differentiate downtime metrics from data loss metrics.
Recovery Time Objective (RTO) governs acceptable downtime duration, whereas Recovery Point Objective (RPO) governs tolerable data loss back-time.
RTO focuses on service restoration timing, while RPO determines necessary backup frequency to limit lost transactions.
2
Differentiate failure frequency metrics from service restoration metrics.
Mean Time Between Failures (MTBF) measures continuous uptime reliability, whereas Mean Time to Repair (MTTR) measures mean duration of maintenance.
MTBF quantifies how often failures occur over time, while MTTR quantifies how quickly repairs are completed.

Anahtar Kavram

Business Impact Analysis Operational Metrics (RTO, RPO, MTBF, MTTR)
Tahmini Süre:1m 0s
Soru 1659Soru

An enterprise online payment gateway has established a Maximum Tolerable Downtime (MTD) of 44 hours and a Recovery Point Objective (RPO) of 1515 minutes for its transactional core. During a disaster recovery test following a simulated primary facility outage, engineers observe that data replication occurs at 1010-minute intervals, secondary virtual infrastructure deployment requires 22 hours, and database state restoration and integrity verification require an additional 2.52.5 hours before operations can resume. Which of the following statements accurately evaluates the organization's current business continuity posture?

Cevabı ve açıklamayı göster

Cevap: The calculated Recovery Time Objective (RTO) of 4.54.5 hours exceeds the Maximum Tolerable Downtime (MTD), creating unacceptable operational risk.

Cevap

The calculated Recovery Time Objective (RTO) of 4.54.5 hours exceeds the Maximum Tolerable Downtime (MTD), creating unacceptable operational risk.
The scenario describes infrastructure deployment (22 hours) and system restoration/verification (2.52.5 hours), yielding a total recovery duration (RTO) of 4.54.5 hours. Because MTD is the absolute limit of acceptable outage time (44 hours), an RTO of 4.54.5 hours violates MTD criteria.

Adım Adım Çözüm

1
Calculate the total Recovery Time Objective (RTO) from the scenario metrics.
Infrastructure deployment (22 hours) ++ State restoration and integrity verification (2.52.5 hours) == 4.54.5 hours total recovery time.
RTO includes the overall timeframe necessary to restore systems and data to an operational state.
2
Evaluate the Recovery Point Objective (RPO) metric against replication frequency.
Replication interval is 1010 minutes, which is within the allowable 1515-minute RPO threshold.
Data loss is bounded by the 1010-minute replication gap, satisfying the RPO requirement.
3
Compare total RTO against Maximum Tolerable Downtime (MTD).
Total RTO (4.54.5 hours) >> MTD (44 hours).
An RTO exceeding MTD indicates the system cannot be recovered before irreparable business damage occurs.

Anahtar Kavram

Alignment of Recovery Time Objective (RTO) and Maximum Tolerable Downtime (MTD) in Business Impact Analysis
Soru 1660Soru

An enterprise logistics organization is updating its security governance documentation framework following an audit review. As part of this initiative, the information security team publishes a document outlining recommended best practices for securing remote home-office wireless routers. The document offers advisory tips for optimizing router posture but explicitly leaves compliance to the discretion of individual employees. Which of the following document types within the security governance hierarchy best categorizes this publication?

Cevabı ve açıklamayı göster

Cevap: Guideline

Cevap

The published document is a Guideline because it provides advisory recommendations and best practices with discretionary compliance rather than mandatory enforcement.
In security governance, Guidelines represent advisory, non-mandatory documentation that offers recommendations and best practices. Because the logistics organization's document provides router security advice while leaving compliance optional for employees, it strictly meets the definition of a Guideline.

Adım Adım Çözüm

1
Analyze the operational intent and enforcement nature of the document in the scenario.
The document contains recommended best practices and tips where compliance is explicitly discretionary.
Governance documents are categorized primarily by whether they are mandatory or advisory.
2
Evaluate the governance document hierarchy definitions against the scenario characteristics.
Guidelines are optional/discretionary best practices; Policies define high-level management intent; Standards establish mandatory requirements; Baselines define minimum mandatory configurations; Procedures detail step-by-step instructions.
Identifying the distinct enforcement level of each governance tier determines the proper classification.
3
Select the governance document type that matches optional recommendations.
Guideline is the correct document type.
Only guidelines represent non-mandatory recommendations within standard security policy frameworks.

Anahtar Kavram

Security Governance Policy Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
ÖncekiSayfa 83 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin