Risk Management & Mitigation Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
During a forensic investigation, an examiner discovers that a suspect encrypted files using BitLocker. Which risk mitigation approach should be prioritized to access the data?
Answer: Run a live memory acquisition to capture the decryption key
Live memory acquisition can capture the BitLocker decryption key if the system is still running, providing the most direct access to encrypted data.
An organization's risk register identifies 'chain of custody failure' as a high-probability risk. Which control best mitigates this?
Answer: Implement a standardized evidence tracking log signed at each transfer
A standardized evidence tracking log with signatures at each transfer directly addresses chain of custody integrity by creating an auditable record.
A quantitative risk assessment assigns a Single Loss Expectancy (SLE) of $50,000 and an Annualized Rate of Occurrence (ARO) of 0.4. What is the Annualized Loss Expectancy (ALE)?
Answer: $20,000
ALE = SLE × ARO = $50,000 × 0.4 = $20,000, representing the expected annual cost of the risk.
A forensic lab is assessing the risk of examiner error corrupting digital evidence. Which mitigation technique directly reduces this risk?
Answer: Implementing peer review and dual-examiner verification procedures
Peer review and dual-examiner verification catch errors before they affect evidence integrity, directly reducing the risk of examiner mistakes.
Which risk treatment option involves purchasing cyber liability insurance to cover potential data breach costs?
Answer: Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as an insurance provider.
An ACE examiner must assess the risk of tampering with a forensic image during network transmission. Which control best addresses this?
Answer: Verifying MD5/SHA hash values before and after transmission
Comparing hash values before and after transmission confirms that the forensic image has not been altered or corrupted in transit.
In risk management, the term 'residual risk' refers to:
Answer: The risk that remains after all controls have been applied
Residual risk is the level of risk that remains after security controls and mitigation measures have been implemented.