Tüm alıştırma soruları
21 soru
A hospital network evaluates the financial exposure associated with a potential ransomware incident targeting its central Picture Archiving and Communication System (PACS) database server cluster. The estimated Asset Value () of the PACS cluster is . Threat intelligence and risk assessment analysts determine that a ransomware outbreak would result in an Exposure Factor () of (). Historical risk data indicates an Annualized Rate of Occurrence () of for this type of attack. What is the baseline Annualized Loss Expectancy (), in US dollars, for the PACS database cluster prior to implementing any additional security controls?
A manufacturing enterprise is conducting a quantitative risk analysis on a critical industrial control system (ICS) server. The server has an estimated Asset Value () of . A specific malware outbreak is projected to result in an Exposure Factor () of . Historical threat intelligence indicates that the Annualized Rate of Occurrence () for this type of attack is . What is the baseline Annualized Loss Expectancy () in dollars for this asset prior to implementing additional countermeasures?
An IT risk manager evaluates a critical file storage server with an estimated asset value of $90,000. A recent threat assessment determines that a localized ransomware infection would result in an Exposure Factor (EF) of 30%. What is the Single Loss Expectancy (SLE) for this server in dollars?
An organization is evaluating the annual financial exposure of a cloud storage infrastructure valued at $800,000. A recent risk assessment reveals that ransomware attacks pose a threat to this system with an estimated Exposure Factor (EF) of 0.25 (25%). Threat intelligence indicates that the Annualized Rate of Occurrence (ARO) for this type of attack vector is 0.50 (once every two years). Based on quantitative risk analysis methodology, what is the calculated Annualized Loss Expectancy (ALE) in US dollars?
A financial technology firm evaluates the potential impact of a ransomware incident on a database server valued at EF 20\% 0.20 SLE$) in dollars for this asset?
An e-commerce enterprise hosts a customer transaction database valued at $500,000. Security metrics indicate that a successful SQL injection attack has an Exposure Factor (EF) of 0.15, and threat intelligence data estimates the Annualized Rate of Occurrence (ARO) for this threat vector to be 0.40. What is the Annualized Loss Expectancy (ALE) in dollars for this database asset?
An organization relies on an Operational Technology (OT) supervisory control and data acquisition (SCADA) system valued at . Historical threat assessments indicate that an unmitigated industrial ransomware attack has an Exposure Factor (EF) of () and an Annualized Rate of Occurrence (ARO) of ( event every years).
To mitigate this risk, the security team proposes deploying an immutable network air-gap and anomaly monitoring safeguard with an annual operating cost of . With this safeguard active, the EF is reduced to () and the ARO is reduced to ( event every years).
What is the net annual cost savings (in USD) achieved by implementing this safeguard?
A healthcare organization is conducting a quantitative risk assessment on an unencrypted portable diagnostic platform. The total asset value (), including sensitive data asset valuation and regulatory non-compliance exposure, is estimated at . Security metrics indicate that a single breach incident would impact of the asset's total value (). Historical threat intelligence indicates that this specific type of breach occurs once every years ().
What is the Annual Loss Expectancy () in dollars associated with this security risk?
A logistics organization is performing a quantitative risk assessment for its automated warehouse management system, which has an Asset Value () of . Without additional security controls, a critical cyber attack is estimated to occur once every 2 years () with an Exposure Factor () of . The cybersecurity team plans to deploy an endpoint detection and response (EDR) platform alongside network microsegmentation controls, which is expected to reduce the to and the to . The total annual cost for subscription licensing and maintenance of these controls is .
What is the net annual financial value (net benefit in USD) of implementing these security controls?
A logistics company evaluates the risk of server downtime at a remote warehouse facility. The database server cluster has an Asset Value () of . An assessment indicates that a severe localized network outage would result in an Exposure Factor () of (). The Annual Rate of Occurrence () for this type of outage is estimated to be (occurring once every two years). What is the Annualized Loss Expectancy () in USD for this threat?
A financial technology enterprise evaluates a security countermeasure for its core transaction processing portal, which has an Asset Value () of . Prior to implementing the safeguard, quantitative risk assessment indicates an Exposure Factor () of and an Annualized Rate of Occurrence () of .
To mitigate potential impact, the security team deploys a high-availability cloud mitigation service costing annually. With this safeguard active, the Exposure Factor () drops to , but automated threat scanning raises the effective Annualized Rate of Occurrence () to .
What is the net annual cost benefit (net safeguard value in USD) realized by deploying this cloud mitigation service?
An organization evaluates the financial impact of a potential security breach on its primary cloud backup repository. The repository has an estimated Asset Value () of . Security analysts determine that a severe ransomware infection would result in an Exposure Factor () of . What is the Single Loss Expectancy () in dollars for this asset?
An enterprise risk analyst is conducting a quantitative risk assessment for a Payment Card Industry (PCI) transaction processing gateway. The asset value () of the server cluster is . Threat intelligence estimates an Annualized Rate of Occurrence () of for a severe security breach, with an unmitigated Exposure Factor () of .
To mitigate this risk, the organization deploys a continuous security monitoring and automated data protection control costing annually. This control reduces the Exposure Factor () to while the remains unchanged.
What is the net annual financial benefit (in USD) of implementing this security control?
An e-commerce enterprise is performing a quantitative risk assessment for its core order processing cluster, which has an estimated Asset Value () of . Security metrics indicate that a ransomware incident affecting this cluster has an Annualized Rate of Occurrence () of and an Exposure Factor () of . To mitigate this risk, the enterprise plans to deploy an Endpoint Detection and Response (EDR) control costing annually. This safeguard will reduce the to without affecting the . What is the net annual financial benefit, in dollars, of implementing this security safeguard?
A cloud-hosted video rendering cluster maintained by a media organization has an estimated Asset Value () of . Operational metrics show that ransomware incidents targeting the rendering nodes have an Annualized Rate of Occurrence () of and an unmitigated Exposure Factor () of . The organization deploys an automated immutable backup solution costing annually. With this safeguard in place, the Exposure Factor () for ransomware attacks drops to , while the remains unchanged at . What is the net annual financial benefit (in USD) realized by implementing this security control?
An enterprise data center hosts a critical database server with an estimated Asset Value () of . Historical threat data indicates that power surge events occur once every 4 years (), with each unmitigated event carrying an Exposure Factor () of . To mitigate this risk, the organization installs an industrial surge protection system that reduces the Exposure Factor to , without altering the frequency of occurrence. What is the new Annualized Loss Expectancy (), in dollars, after implementing this control?
A fintech company operates a cloud-based API gateway handling micro-transactions, with an estimated Asset Value () of . A risk assessment identifies that unmitigated Distributed Denial of Service (DDoS) attacks have an Exposure Factor () of and an Annualized Rate of Occurrence () of . The organization deploys an automated Web Application Firewall (WAF) that reduces the Exposure Factor to . The total annual operational cost of maintaining the WAF is . What is the net annual financial benefit (in dollars) realized by implementing this security control?
An enterprise cloud service provider assesses a critical customer database system with an estimated Asset Value () of . Quantitative risk analysis indicates that an unmitigated database security breach has an Annual Rate of Occurrence () of and results in an Annual Loss Expectancy () of . What is the Exposure Factor (), expressed as a percentage, for this potential security incident?
A financial institution is performing a quantitative risk assessment on its central Hardware Security Module (HSM) cluster used for payment cryptographic operations. The HSM cluster has an estimated Asset Value () of . A risk analysis team determines that a major key exposure incident would have an Exposure Factor () of . Threat intelligence models project an Annualized Rate of Occurrence () of for such an incident. What is the calculated Annualized Loss Expectancy () in US dollars for the HSM cluster?
A logistics enterprise operates an automated fleet dispatch server with an Asset Value () of . Historical security data indicates that severe malware incidents impact this server once every four years (), resulting in an Exposure Factor () of . To mitigate this risk, the organization plans to deploy an Endpoint Detection and Response (EDR) control that will reduce the Exposure Factor () to , while the remains unchanged. The total annual cost to license and maintain the EDR solution is . What is the net annual financial benefit (in USD) of implementing the EDR safeguard?