FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A firm's business continuity plan relies on a single cloud provider for both production and backup data. Which weakness does this most clearly create for recovery?
This creates concentration risk: a failure or compromise at the single cloud provider could take down both production and backup data, leaving no independent recovery path. Provider certification does not remove third-party dependence, and co-location does not improve recovery objectives.
- AConcentration risk, because one provider failure or compromise could disable both production and backupsCorrect
- BExcess redundancy that increases recovery time
- CReduced RPO because backups are co-located
- DElimination of third-party risk because the provider is certified
Explanation
Keeping production and backups with one provider creates a single point of failure and concentration risk. An incident at the provider could affect both, defeating recovery. Certification does not remove third-party risk, and co-location does not improve RPO.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank's cyber risk team estimates that a ransomware event has an annual probability of 8%. If it occurs, the expected loss is USD 5 million…
- A bank classifies threat actors by motivation. Which pairing of actor and typical primary motivation is most accurate?
- After a breach, a review finds that attackers who compromised one employee's credentials moved freely from the corporate network into the pa…
- After a ransomware incident, a bank finds that attackers first sent employees emails mimicking an internal HR notice, harvested credentials,…
- A regional bank's security team observes a group that has quietly maintained access to its payment-switch network for eleven months, exfiltr…
- Which feature of cyber risk most complicates its quantification relative to other operational risk categories?