Repair a residual-risk treatment register
A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
Try this labAll CISSP practice
- Certification
- CISSP
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 30 min
- Automated checks
- 8
The brief
Repair risk-register.json: controls is a list of selected IDs; register has one row per risk with risk, probabilityPercent, lossAmount, outageHours, approver and reviewDay. Use the 15-unit budget and retain both risks. Baseline ransomware: 20%, loss 100000, outage 12 hours, expected-loss limit 5000; normal approvers operations-director or risk-board. Baseline fraud: 10%, loss 60000, outage 1 hour, expected-loss limit 3000; normal approvers finance-director or risk-board. Both outage limits are 4 hours and cannot be waived. If computed expected loss exceeds its limit, only risk-board may accept it and review is due by day 14; otherwise review is due by day 30. Choose a future reviewDay. security-analyst has no acceptance authority. Controls and costs: immutable-backup (4) enables restore-drill but has no standalone reduction here. restore-drill (4) requires immutable-backup; ransomware loss factor 0.5 and outage factor 0.16666666666666666 (one sixth). privileged-access (5): ransomware probability factor 0.25, fraud probability factor 0.5. dual-approval (4): fraud probability factor 0.25. insurance (3): both financial loss factors 0.2, with probability and outage unchanged. isolated-service (12): ransomware probability factor 0.25, loss factor 0.4, outage factor 0.25; fraud unchanged. Unmentioned factors are 1. Multiply operative control factors within each dimension; missing prerequisites make a control inoperative. Count every selected control's cost once. Expected loss = probabilityPercent * lossAmount / 100. Round entered residuals to two decimals; authority uses expected loss before rounding. Use any funded portfolio meeting the service limits, including an authorized financial exception. These factors and delegations are read-only practice assumptions, not universal control efficacy.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- The treatment selection and register contain bounded, valid fields.
- Every assessed risk remains in the register.
- Selected treatments include their complete prerequisites.
- The complete portfolio fits available funding.
- Recorded residuals follow each treatment's actual impact dimensions.
- The service meets its interruption requirements.
- The actual remaining exposure is accepted by its delegated authority.
- Residual risk has a timely future review.
Where this sits in the CISSP blueprint
- Domain
- Security and Risk Management
- Objective
- Risk Management
- Skill
- Assessment, Treatment and Residual Risk
Part of CISSP preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.