FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank applies a defence-in-depth approach to protect a customer database. Which combination best illustrates multiple, independent layers of control?
Network segmentation, encryption of data at rest, and strong authentication with activity monitoring best show defence in depth. They are diverse and independent layers, so failure of one does not expose the database. The other options rely on one control or share a common point of failure.
- ANetwork segmentation, encryption of data at rest, and strong authentication with activity monitoringCorrect
- BThree different firewalls from one vendor all managed by one administrator with a shared password
- CAnnual staff cyber awareness training only
- DA single, highly advanced perimeter firewall
Explanation
Defence in depth uses diverse, complementary controls at different levels so one failure does not expose the asset. Segmentation, encryption and authentication with monitoring are independent layers. Multiple firewalls with a shared credential share a single point of failure, and single-control options give no layering.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A risk manager wants to test whether the bank's cyber defences and response would hold up against a realistic, targeted attack by a skilled …
- Which element is most important for a cyber-resilience strategy to be credible to the board and regulators?
- A bank's cyber risk team is building an inventory as the first step of its cyber risk identification process. Which activity best reflects t…
- A regulator asks a bank how its cyber-resilience approach keeps pace with changing threats. Which practice would provide the strongest evide…
- A payments firm maps its cyber-resilience framework to the five functions commonly used in cyber guidance: identify, protect, detect, respon…
- A bank's cyber risk team is building its inventory for cyber risk identification. Which step best reflects the range of practices observed f…