FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A risk manager reviewing a past cyber incident notes the firm had patched critical vulnerabilities only on systems listed in its asset inventory, and the exploited server was an undocumented legacy system. What is the most appropriate root-cause conclusion?
The root cause is an incomplete asset inventory. Vulnerability and patch management can only cover systems the firm knows exist, so the undocumented legacy server stayed unpatched and exploitable. Maintaining a complete, current inventory is the foundational control that was missing.
- AIncomplete asset inventory undermined vulnerability management coverageCorrect
- BThe firm's patches were too frequent
- CPenetration testing is unnecessary for legacy systems
- DThe firm held too much liquidity
Explanation
Patching programs only cover assets they know about. An undocumented server fell outside the process, so the root cause is the incomplete inventory. Over-frequent patching is not a cause, and the other options are irrelevant or incorrect.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- In a case review, a firm's intrusion detection system generated alerts on unusual outbound data transfers for several weeks, but no analyst …
- A regional bank's chief information security officer (CISO) reports to the chief risk officer and the board risk committee that the security…
- A bank learns that attackers compromised a software update from a trusted vendor, inserting malicious code that was then distributed to the …
- A ransomware attack encrypts a payments processor's servers for 14 hours. No data is copied out of the firm and no records are altered, but …
- A bank wants its cyber framework to follow the widely used NIST Cybersecurity Framework functions. After a phishing attack, the team activat…
- A bank's cyber risk team estimates that a ransomware event has an annual probability of 8%. If it occurs, the expected loss is USD 5 million…