ACI Risk Management & Mitigation 3 — Questions and Answers
Question 1: An investigator finds that an employee accessed sensitive HR files outside business hours for 30 consecutive days. In risk terms, this pattern is BEST classified as:
- An external threat
- An insider threat indicator (Correct answer)
- A false positive anomaly
- A policy exception
Correct answer: An insider threat indicator
Repeated after-hours access to sensitive data by an authorized user is a classic insider threat behavioral indicator.
Question 2: Which document formally authorizes an investigator to proceed with a digital forensic examination and limits legal risk to the organization?
- Chain of custody form
- Non-disclosure agreement
- Written authorization or consent form (Correct answer)
- Incident response playbook
Correct answer: Written authorization or consent form
Written authorization or consent ensures the investigation is legally sanctioned and protects the investigator and organization from unauthorized search claims.
Question 3: A risk mitigation plan identifies that patching a critical vulnerability will take 30 days. What should the organization implement in the interim?
- Accept the risk and wait for the patch
- Implement compensating controls to reduce exposure (Correct answer)
- Outsource the affected system to a third party
- Delete the vulnerable application immediately
Correct answer: Implement compensating controls to reduce exposure
Compensating controls (such as additional monitoring, network segmentation, or access restrictions) reduce risk exposure while a permanent fix is pending.
Question 4: During an investigation into a data breach, the ACI examiner must determine which assets were affected. What is this process called?
- Risk appetite definition
- Asset inventory and classification (Correct answer)
- Threat modeling
- Business impact analysis (BIA)
Correct answer: Asset inventory and classification
Asset inventory and classification identifies and categorizes all resources so investigators can determine what was exposed or compromised.
Question 5: Which type of risk analysis assigns numeric values to likelihood and impact to produce a quantitative risk score?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Subjective risk ranking
- Delphi method assessment
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical values (e.g., Annual Loss Expectancy) to objectively measure and compare risks.
Question 6: An organization decides not to use cloud storage due to concerns about data sovereignty and compliance risk. This is an example of:
- Risk transference
- Risk reduction
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance involves eliminating the activity or technology that creates the risk entirely, rather than managing it.
Question 7: In forensic investigations, maintaining a strict chain of custody is a risk mitigation practice primarily designed to prevent:
- Hardware damage during transport
- Evidence being ruled inadmissible in court (Correct answer)
- Data corruption from malware
- Unauthorized software installation
Correct answer: Evidence being ruled inadmissible in court
A documented chain of custody proves evidence integrity and continuity, preventing defense attorneys from successfully challenging its admissibility.
An investigator finds that an employee accessed sensitive HR files outside business hours for 30 consecutive days.
In risk terms, this pattern is BEST classified as: