Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

Which approach best strengthens a bank's identification of emerging cyber threats?

Combining internal incident data with external threat intelligence and information sharing with peers and authorities best identifies emerging threats. Relying only on past internal logs, ignoring third-party systems, or assessing only after upgrades leaves the bank blind to new attack methods and interconnected exposures.

  1. AIntegrating internal incident data with external threat intelligence and sharing information with peers and authoritiesCorrect
  2. BRelying solely on internal incident logs from the last fiscal year
  3. CLimiting assessment to systems owned directly by the bank
  4. DAssessing cyber risk only after each major system upgrade

Explanation

Effective identification combines internal data with external threat intelligence and information sharing so new tactics are detected early. Internal logs alone are backward-looking, ignoring third-party systems omits key exposures, and event-driven assessment is too infrequent.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions