O-FAIR-2F Sample Questions

O-FAIR-2F Sample Questions & Answers

Running the FAIR analysis process itself carries the most weight, next to the risk taxonomy behind loss event frequency and magnitude, estimating threat frequency and vulnerability, working out primary and secondary loss, and applying and defending the final numbers.

Launch the full O-FAIR-2F simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Open FAIR Fundamentals and Risk Concepts · Introduction to Open FAIR

    In the context of Open FAIR, which statement correctly describes the relationship between 'Threat' and 'Risk'?

    Show answer & explanation

    Correct answer: D

    Risk is derived from Loss Event Frequency (driven by Threat) and Loss Magnitude. Threat is an agent or force that acts against an asset, serving as a contributing factor to the frequency side of the Risk equation.

  2. Question 2BeginnerSelect 2

    Risk Taxonomy (O-RT 3.0.1) · FAIR Risk Taxonomy Structure

    You are presenting the FAIR taxonomy to a new risk analyst. Which two main branches would you identify as the top-level derivatives of Risk? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    Risk is the product of Loss Event Frequency (LEF) and Loss Magnitude (LM). These are the two top-level branches of the FAIR taxonomy.

    Risk is the product of Loss Event Frequency (LEF) and Loss Magnitude (LM). These are the two top-level branches of the FAIR taxonomy.

  3. Question 3Intermediate

    Risk Taxonomy (O-RT 3.0.1) · Loss Event Frequency Factors

    A security analyst is analyzing a scenario involving a DDoS attack. They determine that the attacker attempts to flood the network 50 times a year. However, due to robust DDoS mitigation controls, the network only suffers an outage (loss) 2 times a year.

    Which value represents the Threat Event Frequency (TEF) in this scenario?

    Show answer & explanation

    Correct answer: A

    TEF (Threat Event Frequency) represents the probable frequency at which a threat agent acts against an asset (attempts). In this scenario, the attempts occur 50 times per year. The 2 times per year value represents the Loss Event Frequency (LEF), which counts only the successful attempts.

  4. Question 4Intermediate

    Risk Taxonomy (O-RT 3.0.1) · Loss Event Frequency Factors

    In the FAIR taxonomy, 'Vulnerability' is strictly defined as:

    Show answer & explanation

    Correct answer: B

    FAIR defines Vulnerability specifically as the probability that a threat agent's action (Threat Event) will result in loss (Loss Event). It is a derived value based on the comparison of Threat Capability and Control Strength.

  5. Question 5Intermediate

    Risk Taxonomy (O-RT 3.0.1) · Loss Event Frequency Factors

    Consider the following Mermaid diagram representing a portion of the FAIR taxonomy. What factor correctly fills the blank box marked '???'?

    graph TD TEF[Threat Event Frequency] --> CF[Contact Frequency] TEF --> PoA[Probability of Action] LEF[Loss Event Frequency] --> TEF LEF --> V[Vulnerability] V --> TC[Threat Capability] V --> ???
    Show answer & explanation

    Correct answer: D

    In the FAIR taxonomy, Vulnerability is derived from the comparison of Threat Capability and Control Strength (sometimes referred to as Resistance Strength).

  6. Question 6Advanced

    Risk Taxonomy (O-RT 3.0.1) · Loss Magnitude Factors

    A risk analyst is evaluating the potential loss from a data breach. They categorize the costs of hiring a forensic team and providing credit monitoring to customers as 'Secondary Loss.' Is this categorization correct, and why?

    Show answer & explanation

    Correct answer: B

    Primary Loss includes costs incurred directly by the primary stakeholder in dealing with the event (e.g., forensics/investigation). Secondary Loss involves costs resulting from the reactions of secondary stakeholders (e.g., customers requiring credit monitoring). Therefore, forensic costs are Primary Response, and credit monitoring is Secondary Response.

  7. Question 7Advanced

    Loss Event Frequency Analysis · LEF Derivation and Analysis

    Case Study: SecureCorp is analyzing the risk of insider theft of trade secrets.

    Data Points:

    1. There are 2,000 employees with access.
    2. Malicious insiders historically act against the company once every 10 years.
    3. Data Loss Prevention (DLP) controls stop 90% of attempts.

    Based on this data, what is the Loss Event Frequency (LEF)?

    Show answer & explanation

    Correct answer: C

    TEF = 0.1 (Once every 10 years). Vulnerability = 10% (since controls stop 90%, 10% succeed). LEF = TEF × Vulnerability. LEF = 0.1 × 0.10 = 0.01. This equates to once every 100 years.

  8. Question 8Intermediate

    Risk Taxonomy (O-RT 3.0.1) · Loss Event Frequency Factors

    Which of the following elements combine to determine 'Threat Event Frequency' (TEF) in the FAIR taxonomy?

    Show answer & explanation

    Correct answer: D

    TEF is derived from Contact Frequency (how often the threat agent comes into contact with the asset) and Probability of Action (the likelihood they will act against the asset given contact).

  9. Question 9Intermediate

    Loss Event Frequency Analysis · Threat Event Frequency Estimation

    What does the 'Probability of Action' factor specifically measure in the FAIR model?

    Show answer & explanation

    Correct answer: D

    Probability of Action is the likelihood that a threat agent, once in contact with the asset, will actually attempt a threat event. It does not measure success (which is Vulnerability).

  10. Question 10Advanced

    Loss Event Frequency Analysis · Threat Event Frequency Estimation

    Which of the following scenarios would most likely result in a high 'Contact Frequency' but a low 'Probability of Action'?

    Show answer & explanation

    Correct answer: A

    Employees (Threat Agent) are in constant contact (High Contact Frequency) with the system. However, since they are non-malicious and the system is part of their job, the likelihood they will attempt to harm it (Probability of Action) is very low (usually limited to error).

Ready for the real thing?

The full O-FAIR-2F simulator has every exam-style question, timed mode, and instant scoring.