Repair a residual-risk treatment register

A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CISSP practice

Certification
CISSP
Format
Structured configuration
Difficulty
hard
Estimated time
30 min
Automated checks
8

The brief

Repair risk-register.json: controls is a list of selected IDs; register has one row per risk with risk, probabilityPercent, lossAmount, outageHours, approver and reviewDay. Use the 15-unit budget and retain both risks. Baseline ransomware: 20%, loss 100000, outage 12 hours, expected-loss limit 5000; normal approvers operations-director or risk-board. Baseline fraud: 10%, loss 60000, outage 1 hour, expected-loss limit 3000; normal approvers finance-director or risk-board. Both outage limits are 4 hours and cannot be waived. If computed expected loss exceeds its limit, only risk-board may accept it and review is due by day 14; otherwise review is due by day 30. Choose a future reviewDay. security-analyst has no acceptance authority. Controls and costs: immutable-backup (4) enables restore-drill but has no standalone reduction here. restore-drill (4) requires immutable-backup; ransomware loss factor 0.5 and outage factor 0.16666666666666666 (one sixth). privileged-access (5): ransomware probability factor 0.25, fraud probability factor 0.5. dual-approval (4): fraud probability factor 0.25. insurance (3): both financial loss factors 0.2, with probability and outage unchanged. isolated-service (12): ransomware probability factor 0.25, loss factor 0.4, outage factor 0.25; fraud unchanged. Unmentioned factors are 1. Multiply operative control factors within each dimension; missing prerequisites make a control inoperative. Count every selected control's cost once. Expected loss = probabilityPercent * lossAmount / 100. Round entered residuals to two decimals; authority uses expected loss before rounding. Use any funded portfolio meeting the service limits, including an authorized financial exception. These factors and delegations are read-only practice assumptions, not universal control efficacy.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • The treatment selection and register contain bounded, valid fields.
  • Every assessed risk remains in the register.
  • Selected treatments include their complete prerequisites.
  • The complete portfolio fits available funding.
  • Recorded residuals follow each treatment's actual impact dimensions.
  • The service meets its interruption requirements.
  • The actual remaining exposure is accepted by its delegated authority.
  • Residual risk has a timely future review.

Where this sits in the CISSP blueprint

Domain
Security and Risk Management
Objective
Risk Management
Skill
Assessment, Treatment and Residual Risk

Part of CISSP preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.