Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank experienced a data breach in which attackers exfiltrated customer records over several months. The investigation shows that a known vulnerability had an available patch for 90 days, the asset inventory did not list the affected server, and the vulnerability scanner never covered it. Which conclusion is most accurate?

The primary failure was an incomplete asset inventory. Because the server was unlisted, it escaped vulnerability scanning and patch management even though a fix had been available for 90 days. Controls depend on knowing what assets exist, so the gap undermined every downstream control.

  1. AThe primary failure was incomplete asset inventory, which made patch and scan coverage ineffective for that serverCorrect
  2. BThe primary failure was the patch vendor's delay, which the bank could not have influenced
  3. CThe breach shows that patching is not an effective control
  4. DThe breach was caused solely by insider fraud

Explanation

A patch existed, so the vendor was not the cause. The server's absence from inventory meant it was excluded from both scanning and patching, so the control chain failed at its foundation. Patching itself remains effective when applied to known assets.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions