ATP Risk Assessment & Management 3 — Questions and Answers
Question 1: Which of the following BEST describes residual risk?
- Risk that has been fully eliminated through controls
- Risk remaining after mitigation measures have been applied (Correct answer)
- Risk identified but not yet assigned an owner
- Risk that only affects a subset of examinees
Correct answer: Risk remaining after mitigation measures have been applied
Residual risk is the level of risk that persists even after controls and mitigation strategies have been implemented.
Question 2: A testing vendor's server outage causes a one-day interruption of online exam delivery. The FIRST step in risk response is:
- Conduct a root cause analysis
- Activate the incident response plan (Correct answer)
- Notify all affected candidates by email
- Perform a security audit of the vendor
Correct answer: Activate the incident response plan
Activating the incident response plan ensures a coordinated, pre-planned reaction that limits damage and guides recovery.
Question 3: Test security risk is MOST reduced when:
- All exams are administered at a single testing window
- Candidates sign a non-disclosure agreement only
- Multiple layers of security controls are implemented (Correct answer)
- Cut scores are kept confidential
Correct answer: Multiple layers of security controls are implemented
Defense-in-depth — using layered, overlapping security controls — is the most effective strategy for reducing test security risk.
Question 4: When conducting a threat assessment for a high-stakes credentialing exam, which group should be included as a potential internal threat source?
- Competing certification bodies
- Test center staff and item writers (Correct answer)
- Candidates who failed on a previous attempt
- Regulatory agencies overseeing the credential
Correct answer: Test center staff and item writers
Internal stakeholders such as test center staff and item writers have privileged access and represent an often-overlooked insider threat.
Question 5: Which risk quantification approach assigns numerical probabilities and financial values to estimate expected loss?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Ordinal risk ranking
- Expert judgment scoring
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical data to calculate the probability and financial magnitude of potential losses.
Question 6: A test developer discovers that a subset of items may have been compromised through social media. The BEST immediate action is:
- Cancel all scheduled exam administrations
- Remove the compromised items from active pools and flag score reports (Correct answer)
- Increase test center supervision during the next window
- Lower the passing standard to account for the breach
Correct answer: Remove the compromised items from active pools and flag score reports
Removing compromised items protects score validity while flagging affected score reports enables appropriate follow-up without disrupting all candidates.
Question 7: Which of the following is an example of a preventive risk control in assessment?
- Conducting post-administration forensic analysis of response patterns
- Requiring biometric identity verification before exam access (Correct answer)
- Invalidating scores after detecting irregularities
- Notifying licensing boards of suspected cheating
Correct answer: Requiring biometric identity verification before exam access
Preventive controls act before a risk materializes; biometric verification stops unauthorized individuals from accessing the exam.
Which of the following BEST describes residual risk?