Skip to content

FRM Part II · FRM Exam Part II · Risk Mitigation

A bank's cyber-risk manager wants to limit the damage if an attacker compromises one employee's credentials, so that the attacker cannot move freely across the bank's systems. Which mitigation approach most directly addresses this objective?

Network segmentation combined with least-privilege access is best. It confines what a compromised credential can reach, limiting lateral movement and containing the impact. Training lowers likelihood, insurance only transfers loss, and longer log retention helps investigation, but none of them restrict the attacker's movement.

  1. AIncreasing the frequency of annual phishing awareness training
  2. BNetwork segmentation combined with least-privilege access rightsCorrect
  3. CPurchasing additional cyber insurance cover
  4. DExtending log retention from 12 to 24 months

Explanation

Segmentation and least privilege restrict what a compromised account can reach, limiting lateral movement and containing impact. Training reduces the chance of compromise but does not limit spread. Insurance transfers financial loss only. Longer log retention aids forensics but does not constrain the attacker.

Did you get it right without looking?

One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.

More Risk Mitigation questions