APRP Risk Assessment & Mitigation 2 — Questions and Answers
Question 1: Which risk assessment methodology assigns numerical values to the likelihood and impact of a risk event to produce a prioritized risk score?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Delphi technique
- Bow-tie analysis
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical values (e.g., probability × impact) to calculate measurable risk scores for prioritization.
Question 2: A payments processor discovers that a merchant's chargeback ratio has risen from 0.4% to 1.1% over 90 days. What is the FIRST mitigation action?
- Immediately terminate the merchant account
- Place the merchant on enhanced monitoring and require a remediation plan (Correct answer)
- Increase the merchant's processing fees
- File a suspicious activity report with FinCEN
Correct answer: Place the merchant on enhanced monitoring and require a remediation plan
Enhanced monitoring and a formal remediation plan allow the processor to understand root causes before taking more severe actions like termination.
Question 3: In the context of payments risk, what does 'residual risk' mean?
- Risk that has already materialized into a loss
- Risk remaining after controls have been applied (Correct answer)
- Risk transferred to a third-party insurer
- Risk identified but not yet assessed
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that persists after mitigating controls have been implemented, representing the organization's net exposure.
Question 4: Which of the following is an example of risk transfer in a payments organization?
- Implementing real-time transaction fraud scoring
- Purchasing cyber liability insurance (Correct answer)
- Declining to process high-risk merchant categories
- Requiring merchants to use 3D Secure authentication
Correct answer: Purchasing cyber liability insurance
Cyber liability insurance transfers the financial consequences of certain risk events to the insurer rather than the organization absorbing them.
Question 5: A risk heat map is used primarily to:
- Calculate exact financial losses from fraud events
- Visually prioritize risks by plotting likelihood against impact (Correct answer)
- Map transaction flows across payment networks
- Track chargeback disputes through their lifecycle
Correct answer: Visually prioritize risks by plotting likelihood against impact
A risk heat map provides a two-dimensional visual representation that helps stakeholders quickly identify which risks warrant the most attention.
Question 6: Which control type is designed to detect a risk event AFTER it has occurred rather than prevent it?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls identify and alert stakeholders that a risk event has occurred, enabling a response, while preventive controls stop events before they happen.
Question 7: When assessing third-party payment processor risk, which document provides the most direct evidence that the vendor meets security standards?
- The vendor's marketing brochure describing security practices
- A current PCI DSS Report on Compliance (ROC) issued by a QSA (Correct answer)
- The vendor's internal IT security policy document
- A self-assessment questionnaire completed by the vendor
Correct answer: A current PCI DSS Report on Compliance (ROC) issued by a QSA
A ROC issued by a qualified security assessor (QSA) provides independent third-party validation that PCI DSS controls are in place and effective.
Which risk assessment methodology assigns numerical values to the likelihood and impact of a risk event to produce a prioritized risk score?