FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Which approach best strengthens a bank's identification of emerging cyber threats?
Combining internal incident data with external threat intelligence and information sharing with peers and authorities best identifies emerging threats. Relying only on past internal logs, ignoring third-party systems, or assessing only after upgrades leaves the bank blind to new attack methods and interconnected exposures.
- AIntegrating internal incident data with external threat intelligence and sharing information with peers and authoritiesCorrect
- BRelying solely on internal incident logs from the last fiscal year
- CLimiting assessment to systems owned directly by the bank
- DAssessing cyber risk only after each major system upgrade
Explanation
Effective identification combines internal data with external threat intelligence and information sharing so new tactics are detected early. Internal logs alone are backward-looking, ignoring third-party systems omits key exposures, and event-driven assessment is too infrequent.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- During a cyber incident, a bank's crisis team debates when to notify regulators and customers. Which practice is most consistent with sound …
- A firm's cyber risk team maps its framework to the standard functions of a cyber framework. It is building an inventory of critical business…
- During a cyber risk self-assessment, a bank's business units rate their own control effectiveness as strong, yet internal audit finds repeat…
- After a significant cyber incident is contained, a firm's CISO proposes a post-incident review. Which outcome of the review is most consiste…
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank is deciding how to govern cyber risk. Which arrangement is most consistent with sound cyber-resilience practice?