Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A risk manager reviewing a past cyber incident notes the firm had patched critical vulnerabilities only on systems listed in its asset inventory, and the exploited server was an undocumented legacy system. What is the most appropriate root-cause conclusion?

The root cause is an incomplete asset inventory. Vulnerability and patch management can only cover systems the firm knows exist, so the undocumented legacy server stayed unpatched and exploitable. Maintaining a complete, current inventory is the foundational control that was missing.

  1. AIncomplete asset inventory undermined vulnerability management coverageCorrect
  2. BThe firm's patches were too frequent
  3. CPenetration testing is unnecessary for legacy systems
  4. DThe firm held too much liquidity

Explanation

Patching programs only cover assets they know about. An undocumented server fell outside the process, so the root cause is the incomplete inventory. Over-frequent patching is not a cause, and the other options are irrelevant or incorrect.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions