FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration test found no critical issues, the bank can reduce monitoring spending. Which response best reflects sound cyber-resilience practice?
Management should be told that a clean penetration test is only a point-in-time result. Threats, software and configurations keep changing, so continuous monitoring and detection remain necessary. Testing and scanning complement each other, and neither justifies cutting ongoing monitoring spending.
- AAgree, because a clean test shows controls are permanently effective
- BDisagree, because testing gives a point-in-time view and threats and configurations change, so ongoing detection and monitoring remain necessaryCorrect
- CAgree, provided the test was performed by an internal team
- DDisagree, because penetration tests should be replaced entirely by vulnerability scans
Explanation
A penetration test is a snapshot limited by scope and time. New vulnerabilities, configuration changes and evolving attackers mean continuous monitoring is still needed. Replacing tests with scans is also wrong because the two are complementary.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- Under a three-lines model for cyber risk, which activity is the proper role of the second line of defence?
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?