An organization uses a risk matrix with likelihood and impact scales from 1 to
5. A vulnerability has a likelihood of 4 and an impact of 5. The organization's
risk appetite is low, and the asset value is $2 million. If the annualized rate of
occurrence (ARO) is 0.3, what is the annualized loss expectancy (ALE), and
what risk response is most appropriate?
A. ALE = $300,000; risk avoidance
B. ALE = $600,000; risk mitigation
C. ALE = $300,000; risk mitigation
D. ALE = $600,000; risk avoidance
Correct Answer: B - ALE = $600,000; risk mitigation
RATIONALE
ALE = SLE × ARO. SLE = asset value × exposure factor. Assuming
exposure factor = 1 (full loss), SLE = $2,000,000. ALE = $2,000,000
× 0.3 = $600,000. Given low risk appetite and high ALE, mitigation
(reducing likelihood/impact) is most appropriate. Avoidance would
mean discontinuing the activity, which may not be feasible.
Question 2
Which of the following best describes the security property that ensures a
digital signature provides non-repudiation?
A. The signature is encrypted with the sender's private key, which only
the sender possesses.
B. The signature is encrypted with the recipient's public key, ensuring
only the recipient can verify.
C. The signature uses a symmetric key shared between sender and
receiver.
D. The signature is hashed with a salt and stored in a public ledger.
Correct Answer: A - The signature is encrypted with the sender's
private key, which only the sender possesses.
Page 2
, RATIONALE
Non-repudiation in digital signatures relies on asymmetric
cryptography: the sender signs with their private key, and anyone can
verify with the sender's public key. This proves the sender's identity
and prevents denial. Symmetric keys or recipient's public key do not
provide non-repudiation.
Question 3
A company implements a zero-trust architecture. Which of the following is the
most critical principle to enforce?
A. All internal network traffic is trusted by default.
B. Access decisions are based on continuous verification of user and
device posture.
C. VPNs are used to grant broad access to the internal network.
D. Perimeter firewalls are the primary control for preventing
unauthorized access.
Correct Answer: B - Access decisions are based on continuous
verification of user and device posture.
RATIONALE
Zero-trust eliminates implicit trust based on network location. It
requires continuous authentication and authorization of every access
request, considering user identity, device health, and context.
Traditional perimeter models (VPNs, firewalls) assume internal trust,
which contradicts zero-trust.
Question 4
In an incident response process, which phase involves determining the scope of
an incident and identifying affected systems?
A. Preparation
B. Detection and Analysis
C. Containment, Eradication, and Recovery
Page 3
, D. Post-Incident Activity
Correct Answer: B - Detection and Analysis
RATIONALE
The Detection and Analysis phase of NIST SP 800-61 involves
identifying and validating incidents, assessing scope, and determining
impact. Containment follows after analysis. Preparation is proactive,
and Post-Incident is after recovery.
Question 5
Which of the following is a key difference between RBAC and ABAC?
A. RBAC uses attributes like time and location, while ABAC uses roles.
B. ABAC grants access based on user roles, while RBAC uses resource
attributes.
C. RBAC assigns permissions based on roles, while ABAC evaluates
attributes of user, resource, and environment.
D. ABAC is only used for external users, while RBAC is for internal
users.
Correct Answer: C - RBAC assigns permissions based on roles,
while ABAC evaluates attributes of user, resource, and
environment.
RATIONALE
RBAC (Role-Based Access Control) grants access based on the user's
role within the organization. ABAC (Attribute-Based Access Control)
uses a combination of attributes (user, resource, action, environment)
to make dynamic access decisions. This allows finer-grained,
context-aware control.
Page 4