FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Which feature best describes threat-led penetration testing as used in digital resilience frameworks?
Threat-led penetration testing consists of controlled, simulated attacks on live critical systems, designed from realistic threat intelligence about actors likely to target the institution. It tests detection and response as well as defenses, unlike routine scans or paper-based policy reviews.
- AA purely theoretical review of policies without live systems
- BA statutory audit of financial statements for IT expenses
- CA random vulnerability scan run annually by the vendor of the software
- DControlled simulated attacks on live production systems, based on realistic threat intelligence about actors targeting the institutionCorrect
Explanation
Threat-led testing uses intelligence on relevant threat actors to design realistic, controlled attacks on critical live systems, testing both defenses and response. A routine scan or paper review lacks this realism.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A bank defines an impact tolerance for its payments service: the maximum tolerable disruption is 4 hours. A scenario test shows the service …
- A financial stability authority is weighing capital buffers against operational-resilience requirements as a response to systemic cyber risk…
- A regulator considers using capital requirements as a tool against cyber risk. Which is the strongest argument that capital alone is an insu…
- A supervisor argues that digital transformation changes the nature of operational risk in finance compared with traditional disruptions such…
- A regulator is designing a policy toolkit for digital resilience in the financial sector. It considers five tools: (1) mandatory incident re…
- An insurer considers offering cyber coverage to many banks that all depend on the same software vendor. Which is the main concern for the in…