FRM Part II · FRM Exam Part II · Risk Mitigation
A bank's cyber-risk manager wants to limit the damage if an attacker compromises one employee's credentials, so that the attacker cannot move freely across the bank's systems. Which mitigation approach most directly addresses this objective?
Network segmentation combined with least-privilege access is best. It confines what a compromised credential can reach, limiting lateral movement and containing the impact. Training lowers likelihood, insurance only transfers loss, and longer log retention helps investigation, but none of them restrict the attacker's movement.
- AIncreasing the frequency of annual phishing awareness training
- BNetwork segmentation combined with least-privilege access rightsCorrect
- CPurchasing additional cyber insurance cover
- DExtending log retention from 12 to 24 months
Explanation
Segmentation and least privilege restrict what a compromised account can reach, limiting lateral movement and containing impact. Training reduces the chance of compromise but does not limit spread. Insurance transfers financial loss only. Longer log retention aids forensics but does not constrain the attacker.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- A bank classifies its systems into tiers. A risk manager proposes giving the payment-processing system, which would cause severe losses with…
- A bank relies on a single cloud provider for its core trading platform. A risk manager is asked to address concentration risk in this third-…
- A bank's operations team reviews its payment-release process. A single clerk can create a new beneficiary, approve the payment and release f…
- A risk manager is evaluating insurance as an operational risk mitigant and notes that the insurer may take a long time to pay, may dispute c…
- A bank discovers that ransomware has encrypted production servers. Backups exist, but they are stored on the same network domain with the sa…
- A risk manager is evaluating whether buying cyber insurance adequately mitigates a bank's exposure to a major data breach. Which limitation …