Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alerts sat in an unmonitored queue and no one escalated them. Which control failure does this best illustrate?

This illustrates a failure in detection and response processes rather than tooling. The alerts were generated but nobody owned, triaged or escalated them, so the compromise continued for weeks. Clear ownership, monitoring staffing and escalation procedures are the missing controls.

  1. AWeakness in incident detection and response processes, not in toolingCorrect
  2. BInadequate encryption key length on stored data
  3. CInsufficient capital held against market risk
  4. DFailure of the bank's disaster recovery site to activate

Explanation

The technology detected the activity, but ineffective triage, ownership and escalation meant no response occurred. This is a process and governance failure. Encryption strength and market capital are unrelated, and no recovery site failure is described.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions