Risk chapter quiz
Risk chapter quiz
No grades. The point is to push your thinking. Tap an option to see if it lands.
A CVSS 9.8 vulnerability is found on a system. What should the Risk verdict be?
CVSS scores severity in the abstract. The Risk verdict is about the specific environment, the specific asset, and the specific case. A CVSS 9.8 on an isolated, unused system is a different decision than the same score on a production asset.
Impact and likelihood are...
Impact is 'if this is real, how bad is it.' Likelihood is 'how confident are we that this is real.' Separating them prevents the common error of letting impact bias the likelihood judgment.
A case closes as a false-positive. What should the analyst record?
A closed false-positive is a finding too. Documenting the reasoning takes minutes and compounds into sharper detection over time. The methodology treats every closure as a contribution to institutional knowledge.
The Risk verdict should include...
The Risk output should be a one-page verdict that a future reviewer can read and understand without re-doing the analysis. Open questions and recommended response are part of what makes the verdict actionable and defensible.
The RATM rubric scores a case as High asset criticality (crown-jewel database), but the only evidence is a signature match with no behavioral confirmation. The matrix reads High impact / Low likelihood. What is the default action?
Impact answers what is at stake if the finding is real; likelihood answers how confident you are that it is real. High impact with weak evidence is neither an escalation (that would let stakes inflate confidence) nor a closure (that would let weak evidence excuse a crown-jewel case). Two qualifiers from the override rules: this Low is legitimate only because the evidence was examined and leans benign — if likelihood were 'low' because telemetry was missing, unknown scores Medium and the cell becomes High/Medium, P2 within the shift. And a High-impact P3 runs the tightened high-impact clock: re-score within hours, not 24, with the queue lead aware.
Uncover confirms the adversary has reached a system outside the original Scope boundary. What does the methodology require?
Confirmed lateral movement beyond the boundary meets a canonical escalation criterion, and the break-glass rule fires from any phase the moment a criterion is confirmed. The dynamic loop still runs, refining scope is exactly what IR needs next, but it runs in parallel with containment, not instead of it. The loop is for building fidelity on unresolved cases; it is never a reason to sit on a confirmed, spreading compromise.
A SOC sees the same alert fire repeatedly across multiple developer workstations, and every investigation closes benign. What is the right response?
A single benign fire is a closure with feedback. A pattern of benign fires on the same asset class — whether false positives or benign true positives — is a signal about the detection stack itself. The methodology asks for a refined variant or a documented suppression with an owner and a review cadence, not for individual repeat closures or wholesale rule removal.
The Risk verdict for the Cursor IDE case (benign true positive) reads 'low residual risk, no escalation required.' What value does the documented closure provide?
A documented benign closure is not a non-event. It is the artifact that defends the case if the same alert fires again, surfaces detection-engineering feedback, raises program-level questions (here, about coverage gaps in macOS PCAP and USB monitoring), and provides full context if the case needs to re-open. Clarity, not escalation, is the primary outcome of effective triage.