← All APRP Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. Which risk assessment methodology assigns numerical values to the likelihood and impact of a risk event to produce a prioritized risk score?

    Answer: Quantitative risk analysis

    Quantitative risk analysis uses numerical values (e.g., probability × impact) to calculate measurable risk scores for prioritization.

  2. A payments processor discovers that a merchant's chargeback ratio has risen from 0.4% to 1.1% over 90 days. What is the FIRST mitigation action?

    Answer: Place the merchant on enhanced monitoring and require a remediation plan

    Enhanced monitoring and a formal remediation plan allow the processor to understand root causes before taking more severe actions like termination.

  3. In the context of payments risk, what does 'residual risk' mean?

    Answer: Risk remaining after controls have been applied

    Residual risk is the level of risk that persists after mitigating controls have been implemented, representing the organization's net exposure.

  4. Which of the following is an example of risk transfer in a payments organization?

    Answer: Purchasing cyber liability insurance

    Cyber liability insurance transfers the financial consequences of certain risk events to the insurer rather than the organization absorbing them.

  5. A risk heat map is used primarily to:

    Answer: Visually prioritize risks by plotting likelihood against impact

    A risk heat map provides a two-dimensional visual representation that helps stakeholders quickly identify which risks warrant the most attention.

  6. Which control type is designed to detect a risk event AFTER it has occurred rather than prevent it?

    Answer: Detective control

    Detective controls identify and alert stakeholders that a risk event has occurred, enabling a response, while preventive controls stop events before they happen.

  7. When assessing third-party payment processor risk, which document provides the most direct evidence that the vendor meets security standards?

    Answer: A current PCI DSS Report on Compliance (ROC) issued by a QSA

    A ROC issued by a qualified security assessor (QSA) provides independent third-party validation that PCI DSS controls are in place and effective.