Skip to content

FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Which feature best describes threat-led penetration testing as used in digital resilience frameworks?

Threat-led penetration testing consists of controlled, simulated attacks on live critical systems, designed from realistic threat intelligence about actors likely to target the institution. It tests detection and response as well as defenses, unlike routine scans or paper-based policy reviews.

  1. AA purely theoretical review of policies without live systems
  2. BA statutory audit of financial statements for IT expenses
  3. CA random vulnerability scan run annually by the vendor of the software
  4. DControlled simulated attacks on live production systems, based on realistic threat intelligence about actors targeting the institutionCorrect

Explanation

Threat-led testing uses intelligence on relevant threat actors to design realistic, controlled attacks on critical live systems, testing both defenses and response. A routine scan or paper review lacks this realism.

Did you get it right without looking?

One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.

More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions