FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
In a case review, a firm's intrusion detection system generated alerts on unusual outbound data transfers for several weeks, but no analyst investigated them and the exfiltration continued. Which conclusion is MOST appropriate?
The detective control existed but was ineffective due to poor monitoring and response. The system produced alerts, yet nobody investigated them, so exfiltration continued. The weakness lies in triage, staffing and escalation processes rather than in an absence of detection technology.
- AThe detective control existed but failed because of inadequate monitoring and response processesCorrect
- BThe preventive controls were too strict and blocked legitimate traffic
- CThe firm lacked any detective controls
- DThe incident is purely an inherent risk issue unrelated to controls
Explanation
Alerts were generated, so a detective control was present. The failure was in human follow-up and response procedures, such as staffing, triage and escalation. Saying no detective control existed contradicts the facts.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorizatio…
- A bank estimates that a ransomware event has a 5% annual probability. If it occurs, expected loss is USD 20 million. A new offline-backup co…
- An analyst at an asset manager discovers that an unauthorised insider changed the settlement account numbers on several pending trade instru…
- A risk manager is reviewing the bank's exposure to a malicious insider, such as a database administrator with privileged access. Compared wi…
- After a cyber incident, a bank's post-incident review finds that the response playbook was sound but staff had never rehearsed it, causing d…
- A bank's risk committee is classifying threat actors. One group aims to disrupt a bank's public website during a political controversy to pu…