01. Which party's response to a loss event would generate secondary loss for the organization analyzed?
a) An internal team that works overtime to restore the affected service
b) A supplier that replaces the equipment destroyed in the event and invoices for the work
c) A regulator that opens an investigation and imposes a penalty
d) A threat agent that repeats the same action a second time
02. How is the analysis that Open FAIR supports best characterized?
a) Qualitative appraisal of information risk, resolving to an agreed severity rating per finding
b) Technical assessment of information systems, resolving to a list of exploitable weaknesses
c) Statistical study of past security incidents, resolving to the count observed in each period
d) Quantitative analysis of information risk, resolving to probable frequency and probable financial loss
03. Two analysts disagree about whether "threat community" is a defined term or an informal one.
What settles it, and how?
a) The Risk Analysis (O-RA) Standard, since the term is first encountered during scoping
b) The Risk Taxonomy (O-RT) Standard, which defines it as a formal element
c) Local convention, since the standards leave community definitions to each team
d) Neither standard, since the term belongs to threat intelligence practice
04. Monitoring shows that an automated scanner reaches a public web service many times a day, but that the agent behind it follows up with an attack only against services advertising a payment function.
Which factors do the two halves of that observation bear on?
a) How often the service is reached bears on Contact Frequency, and the selectivity bears on Probability of Action
b) How often the service is reached bears on Threat Event Frequency, and the selectivity bears on Vulnerability
c) How often the service is reached bears on Probability of Action, and the selectivity bears on Contact Frequency
d) How often the service is reached bears on Threat Capability, and the selectivity bears on Resistance Strength
05. Why does the Open FAIR Body of Knowledge need both of its standards rather than either one alone?
a) One standard applies to cyber scenarios and the other to operational scenarios
b) A method needs defined factors to operate on, and defined factors need a method to be estimated
c) One standard is used by contributors and the other by the analyst leading the work
d) One standard governs the estimate, and the other governs how results are presented and used
06. Over a year the number of intrusion attempts against a service is unchanged, but the share of attempts that reach data has fallen sharply.
Which factor has moved?
a) Threat Event Frequency, since fewer attempts now matter
b) Contact Frequency, since the agent reaches the service less effectively
c) Loss Magnitude, since less data is reached per attempt
d) Vulnerability, since a smaller proportion of acts now succeeds
07. After a breach an organization pays a forensics firm to investigate and outside counsel to advise it.
Which form of loss covers those two payments?
a) Response, because both are costs of managing the event after it occurred
b) Replacement, because both payments restore the organization to its position before the event
c) Productivity, because both consume resources that would otherwise support the business
d) Fines and Judgments, because both payments arise from the organization's legal exposure
08. Press coverage of a breach is followed by a measurable fall in renewals over the next two quarters.
Which form of loss best accounts for the lost renewals?
a) Productivity
b) Secondary Loss
c) Reputation
d) Competitive Advantage
09. During a two-day outage a call center cannot take orders, and a supplier is paid to help restore the platform.
Which two forms of loss are in play?
a) Replacement and Fines and Judgments
b) Productivity and Replacement
c) Response and Reputation
d) Productivity and Response
10. What does Loss Magnitude describe in the Open FAIR taxonomy?
a) The probable amount of loss arising from a loss event
b) The proportion of an asset's value that a loss event destroys
c) The probable amount of loss the organization will bear over a year
d) The severity rating assigned to a loss event once it has occurred