โ† All ACT Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real ACT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. An ACT trainer is setting up a training lab with loaner MacBooks. What is the most important risk to mitigate regarding data from previous participants?

    Answer: Erasing and reinstalling macOS to remove all prior participant data before each cohort

    Erasing and reimaging loaners between cohorts ensures no residual personal or sensitive data from previous participants remains on the devices.

  2. During an Apple Business Essentials training, a participant's account is inadvertently granted Device Manager role. What risk does delayed role correction create?

    Answer: The participant could modify or wipe organization devices before the error is caught

    An unintended Device Manager role gives the participant power to modify or remotely wipe organizational devices, making swift correction critical.

  3. A trainer is demonstrating Apple Remote Desktop to a group. What consent-related risk must be mitigated before observing participant screens?

    Answer: Participants must be informed and consent before their screens are observed or controlled remotely

    Remote observation of participant screens without explicit informed consent violates privacy expectations and may breach applicable laws.

  4. When a training environment's Time Machine backup drive fails mid-session, which risk management principle should guide the trainer's immediate response?

    Answer: Pause demos involving data changes until an alternative backup solution is confirmed

    Continuing data-change demonstrations without a working backup exposes participants and training assets to unrecoverable loss if an error occurs.

  5. An organization requests that ACT training include demonstrating how to bypass Gatekeeper for an internal unsigned app. What risk must the trainer communicate?

    Answer: Bypassing Gatekeeper for one app trains users to habitually allow untrusted software, increasing malware risk

    Demonstrating Gatekeeper bypass normalizes trusting unsigned software, which can lead users to unknowingly install malware in real-world scenarios.

  6. A participant accidentally enables Remote Login (SSH) on a training Mac and leaves it enabled at session end. What ongoing risk does this create?

    Answer: The device remains accessible over the network, creating an unauthorized access vector

    An unintended open SSH service exposes the Mac to unauthorized remote access by anyone on the same network.

  7. A corporate client asks that all training session recordings be stored in a shared Google Drive folder accessible by all employees. What risk should the trainer flag?

    Answer: Broad access to recordings may expose sensitive demo data or organizational configurations shown during training

    Recordings can contain sensitive system configurations, credentials, or workflows inadvertently captured during demos, making broad access a data exposure risk.