ATP Risk Assessment & Management 4 — Questions and Answers
Question 1: In risk management terminology, 'risk appetite' refers to:
- The maximum financial loss an organization can absorb
- The level of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total number of risks identified in a risk register
- The minimum security standard required by regulators
Correct answer: The level of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines how much risk an organization deliberately chooses to take on as it works toward its goals.
Question 2: A credentialing body uses statistical flagging to identify examinees whose answer patterns suggest collusion. This is an example of:
- Risk transfer
- Detective control (Correct answer)
- Preventive control
- Risk avoidance
Correct answer: Detective control
Statistical flagging detects irregularities after they have occurred, making it a detective rather than preventive control.
Question 3: Which factor MOST directly increases the inherent risk level of a high-stakes credentialing examination?
- Large item bank size
- High financial or career consequences of the credential (Correct answer)
- Use of adaptive testing algorithms
- Low candidate volume per testing window
Correct answer: High financial or career consequences of the credential
When a credential carries significant career or financial value, motivation to cheat or compromise the exam increases, raising inherent risk.
Question 4: What is the key difference between a risk and an issue in project risk management?
- A risk is certain to occur; an issue is uncertain
- A risk is a potential future event; an issue is a problem that has already occurred (Correct answer)
- A risk requires financial mitigation; an issue requires personnel action
- A risk is internal; an issue is always caused by external parties
Correct answer: A risk is a potential future event; an issue is a problem that has already occurred
Risks are uncertain future events that may affect objectives, while issues are realized problems requiring immediate response.
Question 5: A test program manager wants to prioritize risks for mitigation. Which formula is commonly used to calculate a risk score?
- Risk score = Impact + Likelihood
- Risk score = Impact × Likelihood (Correct answer)
- Risk score = Impact ÷ Likelihood
- Risk score = Likelihood − Impact
Correct answer: Risk score = Impact × Likelihood
Multiplying impact by likelihood produces a risk score that reflects both the severity and probability of an adverse event.
Question 6: Which ATP guideline area is MOST directly concerned with protecting the integrity of secure test content during shipping and storage?
- Validity evidence standards
- Chain of custody procedures (Correct answer)
- Psychometric reporting requirements
- Accessibility accommodation policies
Correct answer: Chain of custody procedures
Chain of custody procedures document and control who handles test materials at every point, protecting content integrity.
Question 7: An organization decides to outsource its test delivery to a third-party vendor. Which new risk category is MOST introduced by this decision?
- Psychometric risk
- Vendor/third-party risk (Correct answer)
- Construct validity risk
- Cut score risk
Correct answer: Vendor/third-party risk
Outsourcing introduces vendor risk, including concerns about the third party's security practices, reliability, and contractual compliance.
In risk management terminology, 'risk appetite' refers to: