O-FAIR-2F Open FAIR 2 Foundation Practice Questions
Prepare for O-FAIR-2F with more than an answer.
- Exam fee
- $360 USD
- Level
- Foundation
- Valid for
- Lifetime - No expiration
Domains covered on the exam 6
- Open FAIR Fundamentals and Risk Concepts15%
- Risk Taxonomy (O-RT 3.0.1)20%
- Risk Analysis Standard (O-RA 2.0.1)25%
- Loss Event Frequency Analysis15%
- Loss Magnitude Estimation15%
- Risk Analysis Application and Interpretation10%
- 1
When estimating 'Control Strength' (CS) in FAIR, which of the following is the correct definition?
Show answer details
Correct answer: A
Control Strength (or Resistance Strength) is defined as the measure of the strength of a control as compared to a measure of the force of the threat (Threat Capability). It represents the difficulty level required to defeat the control.
- 2
In a scenario where Threat Capability (TC) is assessed as 'High' (top 2% of skilled attackers) and Control Strength (CS) is assessed as 'Low' (default passwords), what is the resulting Vulnerability?
Show answer details
Correct answer: B
If the Threat Capability exceeds the Control Strength significantly, the probability of a successful attack (Vulnerability) is very high. A skilled attacker against a weak control ensures near-certain success.
- 3
An organization relies on 'Security through Obscurity' as its primary defense. In FAIR terms, how does this affect the analysis?
Show answer details
Correct answer: A
Security through obscurity (hiding the asset) primarily reduces the Probability of Action. If the threat agent does not know the asset exists or cannot find it easily after contact, they are less likely to act against it. It does not technically increase Control Strength (resistance to force), but rather avoids the attempt.
- 4
Which form of loss captures the 'inability to deliver products or services' resulting in lost revenue?
Show answer details
Correct answer: D
Productivity Loss is the reduction in the organization's ability to generate value (e.g., revenue, services) due to an operational outage or disruption.
- 5
A breach of customer data results in a class-action lawsuit filed 12 months after the incident. How should this loss be categorized in FAIR?
Show answer details
Correct answer: D
This is a Secondary Loss because it involves external stakeholders (customers/lawyers) acting against the organization. The specific form is Fines and Judgments (legal settlements/penalties).
- 6
A Chief Risk Officer (CRO) questions the validity of a recent risk analysis because the 'Risk' value was presented as a single monetary number. According to the Open FAIR 2 Foundation standards, how should Risk be accurately defined and represented to address this concern?
Show answer details
Correct answer: D
In Open FAIR, Risk is explicitly defined as the probable frequency and probable magnitude of future loss. It is quantitative and probabilistic, meaning it should be represented as a range or distribution (e.g., a bell curve or histogram) rather than a single point estimate or a qualitative label.
- 7
While scoping a risk scenario regarding 'Theft of Customer Database,' the analyst identifies the following elements:
- Threat: Cyber Criminals
- Asset: Customer Database
- Effect: Confidentiality Loss
Which critical component of the FAIR definition of a 'Loss Scenario' is implicitly defined but must be explicitly understood to perform accurate frequency analysis?
Show answer details
Correct answer: A
While the Asset is listed, FAIR requires a clear definition of the Asset, Threat, and Effect. However, usually, a Loss Scenario is formally defined as T-A-E (Threat, Asset, Effect). The question asks what is critical for frequency analysis. In FAIR, the 'Asset' is the value liability, but the 'Method' is often part of the Threat description. Wait, strictly speaking, a Loss Scenario is defined by Threat, Asset, and Effect. If these are present, the scoping is technically complete for the 'Scenario' definition itself. However, often analysts forget the 'Method' or 'Vector' which helps estimate frequency. But according to standard definitions, Threat, Asset, and Effect are the core triad.
- 8
Which of the following statements accurately distinguishes the Open FAIR O-RA standard from the O-RT standard?
Show answer details
Correct answer: D
O-RA (Open Risk Analysis) Standard focuses on the process aspect—how to scope, collect data, and run the analysis. O-RT (Open Risk Taxonomy) Standard focuses on the terms and definitions—the hierarchy of factors like LEF, TEF, and LM.
- 9
True or False: In Open FAIR analysis, 'Accuracy' refers to the exactness of a measurement (e.g., to three decimal places), while 'Precision' refers to how close a measurement is to the true value.
Show answer details
Correct answer: B
This is False. The definitions are swapped. In FAIR (and science generally), 'Accuracy' is the closeness to the true value. 'Precision' is the level of detail or exactness (e.g., number of decimal places). FAIR emphasizes that it is better to be accurate (correct range) than precise (exact but wrong number).
- 10
An organization wants to adopt FAIR to improve its risk communication. Which of the following are primary benefits of using the Open FAIR ontology over traditional qualitative heat maps? (Select TWO)
Show answer details
Correct answer: C, D
A core benefit of FAIR is the standardized taxonomy and definitions, making analysis consistent and defensible across different analysts and timeframes.
FAIR provides financial loss exposure data, which is essential for calculating ROSI (cost of control vs. reduction in loss exposure).
