Risk Management & Mitigation Flashcards
7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
During a digital forensic investigation, an examiner discovers that the suspect's hard drive is failing. Which risk mitigation step should be taken FIRST?
Answer: Create a forensic image of the drive before it fails completely
Creating a forensic image first preserves evidence before the drive fails, protecting evidentiary integrity.
Which framework is most commonly referenced by ACI investigators when assessing organizational cybersecurity risk posture?
Answer: NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cybersecurity risks.
A company experiences repeated phishing attacks targeting employees. Which risk mitigation strategy addresses the ROOT CAUSE most effectively?
Answer: Conduct recurring security awareness training
Security awareness training targets the human element, which is the root cause of phishing susceptibility.
In risk management terminology, what does 'residual risk' refer to?
Answer: The risk remaining after controls and mitigations have been implemented
Residual risk is the level of risk that persists even after all planned risk mitigation controls have been applied.
An ACI investigator recommends purchasing cyber liability insurance for a client. This is an example of which risk response strategy?
Answer: Risk transference
Purchasing insurance transfers the financial impact of a risk to a third party (the insurer).
Which of the following BEST describes a 'threat actor' in the context of digital forensic risk assessment?
Answer: An individual or group with the capability and intent to cause harm
A threat actor is any entity — individual, group, or organization — with both motivation and capability to exploit vulnerabilities.
When performing a risk assessment, what is the formula used to calculate risk level?
Answer: Risk = Threat × Vulnerability × Impact
Risk is calculated by multiplying threat (likelihood of exploitation), vulnerability (weakness), and impact (consequence) together.