Study sets
English

Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08

1 / 100.0s

Problem 1

A customer management system has a function that was previously available only internally. The company now plans to expose it on the Internet as an API for business partners. Its annual risk assessment was completed two months ago. Which action is most appropriate before release?

View explanation

Changing a system's architecture or use can change both its attack paths and the potential scope of impact. Because an internal function is becoming externally accessible, the company must identify and assess the new risks from authentication, exposure, data, and threats regardless of when the annual assessment occurred. Counting failures only after launch would not address compromise risks that should be managed before release.

Problem 2

An organization is prioritizing two risk treatments. Treatment X is expensive but reduces a major risk to an acceptable level. Treatment Y is inexpensive, but the residual risk would still exceed the organization's acceptance criteria. Which decision approach is most appropriate?

View explanation

Cost alone must not determine treatment priority. The organization should consider the untreated risk, treatment cost, and whether the remaining risk after treatment meets its acceptance criteria. Here, choosing Y solely because it is inexpensive is inappropriate because it leaves an unacceptable risk. Mandatory legal and contractual requirements also cannot be excluded from the decision.

Problem 3

A risk treatment plan for a customer information system says only, "Strengthen access control." Which set of additions would most improve the plan's executability and completion criteria?

View explanation

A risk treatment plan becomes manageable when it specifies not just what will be done, but also required resources such as people and budget, the responsible owner, the deadline, and how effectiveness will be evaluated. "Strengthen access control" or a list of candidate products and costs alone leaves ownership, timing, and completion criteria unclear. Discovery history and treatment advantages can be useful context, but they do not replace the elements required to manage execution.

Problem 4

Daily backup jobs report success, but no restore has been attempted in the past year. Which method is most appropriate for determining whether required data can be recovered within the target time?

View explanation

A successful job status does not prove that required files are readable or that the recovery procedure works. An actual restore in an isolated environment can reveal corruption, missing permissions, and procedural omissions while measuring integrity and recovery time. Backup frequency and file size alone do not verify recoverability.

Problem 5

An organization's emergency patching standard gives highest priority to "a vulnerability that is known to be exploited and affects a critical Internet-facing system." Which vulnerability should receive the highest priority?

View explanation

Under the stated standard, the customer-facing web system satisfies all three priority conditions—active exploitation, Internet exposure, and impact on a critical system. A severe vulnerability in a product the organization does not use has no direct exposure there. Even under an emergency process, approved testing and rollback arrangements should be used to manage availability risk.

Problem 6

During due diligence on a new supplier, an organization finds that it requires one year of log retention, while the supplier currently retains logs for three months. Which action is most appropriate before signing the contract?

View explanation

Before outsourcing begins, the organization should identify gaps between its security requirements and the supplier's current controls and incorporate necessary remediation into the contract. Agreeing on the method, deadline, and allocation of cost also makes ownership and operating conditions clear. Ignoring the gap because of price or relying only on an oral statement would not ensure sufficient investigation capability.

Problem 7

A supplier is found to have copied some customer data without approval to cloud storage in another region, although the contract requires domestic storage. Which ongoing supplier-management response is most appropriate?

View explanation

When actual performance differs from the contract, the organization should establish the cause, scope, and risk, then work with the contract owner to correct it. Verification after remediation prevents the response from ending with an unsupported promise. Merely deleting the requirement would resolve neither the risk of the unauthorized copy nor the contractual nonconformity.

Problem 8

An outsourcing arrangement for customer-data processing is ending. The supplier sends an email stating, "The data has been deleted." Which end-of-contract control is most appropriate?

View explanation

At contract end, the organization should identify all relevant loaned materials, operational data, copies, and backups and verify their return or disposal. If law or another requirement mandates retention, the specific data, period, and protection must be separately documented. Disabling one account does not establish that data and materials remaining with the supplier have been handled.

Problem 9

A CSIRT receives two events at the same time. One is a port scan against an isolated test device whose traffic has already been blocked. The other is suspected bulk transmission of customer data from a production server. Which initial prioritization is most appropriate?

View explanation

Initial priority should reflect information sensitivity, business impact, and the potential scope and growth of harm, not merely arrival order. Suspected ongoing bulk transmission of customer data may represent a major and expanding confidentiality impact, making prompt assessment and containment reasonable. Prioritizing one event does not justify failing to record and manage the other.

Problem 10

Customer files may have been exfiltrated after an unauthorized login. Which method is most appropriate for analyzing the intrusion path and scope of impact?

View explanation

Cause and scope should be determined by correlating multiple sources, including authentication, endpoint actions, outbound traffic, and file access, on a common timeline. Comparing the pattern with known attack techniques and indicators provides further support. User recollection can provide leads, but omissions and mistakes make it insufficient by itself to establish the intrusion path or exfiltration scope.