ATP Risk Assessment & Management 5 — Questions and Answers
Question 1: Which component of a risk management framework establishes the criteria by which risks are evaluated and prioritized?
- Risk monitoring plan
- Risk communication strategy
- Risk evaluation criteria (Correct answer)
- Risk response register
Correct answer: Risk evaluation criteria
Risk evaluation criteria define the thresholds and standards used to judge whether a risk is acceptable or requires action.
Question 2: A remote proctoring company experiences a data breach exposing examinee personally identifiable information (PII). Under applicable US regulations, the FIRST obligation of the test sponsor is typically:
- Suspend the remote proctoring contract
- Notify affected examinees and relevant authorities within required timeframes (Correct answer)
- Conduct an internal investigation before taking any external action
- Retract all score reports issued during the breach period
Correct answer: Notify affected examinees and relevant authorities within required timeframes
US breach notification laws generally require timely notification to affected individuals and regulators as the immediate priority.
Question 3: Which risk monitoring technique involves regularly reviewing key risk indicators (KRIs) to detect changes in risk exposure over time?
- Root cause analysis
- Continuous risk monitoring (Correct answer)
- Post-mortem debriefing
- Fault tree analysis
Correct answer: Continuous risk monitoring
Continuous risk monitoring tracks KRIs on an ongoing basis to provide early warning when risk exposure is increasing.
Question 4: A test program identifies that its cut score was set using an outdated job task analysis. The BEST risk response is:
- Accept the risk since job duties rarely change
- Conduct an updated job task analysis and convene a new standard-setting study (Correct answer)
- Transfer the risk to the accreditation body
- Lower the cut score to reduce candidate failure rates
Correct answer: Conduct an updated job task analysis and convene a new standard-setting study
Refreshing the job task analysis and resetting standards ensures the cut score reflects current professional requirements and maintains validity.
Question 5: When a risk response plan is developed, assigning a named 'risk owner' is important because:
- It limits legal liability to one individual
- It ensures clear accountability for monitoring and executing the mitigation strategy (Correct answer)
- It reduces the overall risk score automatically
- It transfers the risk to that individual personally
Correct answer: It ensures clear accountability for monitoring and executing the mitigation strategy
Designating a risk owner creates clear accountability so that mitigation actions are executed and the risk is actively monitored.
Question 6: Which of the following BEST illustrates the principle of 'risk-informed decision making' in a testing organization?
- Avoiding all high-risk activities regardless of potential benefit
- Using risk analysis data alongside strategic goals to guide program choices (Correct answer)
- Delegating all risk decisions to external auditors
- Making decisions based solely on historical incident data
Correct answer: Using risk analysis data alongside strategic goals to guide program choices
Risk-informed decision making integrates risk analysis with organizational objectives, ensuring decisions are neither risk-blind nor overly risk-averse.
Question 7: A certification exam switches from fixed-form to computerized adaptive testing (CAT). A NEW risk introduced by this change is:
- Increased printing and shipping costs
- Item exposure concentration on high-discrimination items (Correct answer)
- Loss of analog backup test formats
- Reduced ability to use item banks
Correct answer: Item exposure concentration on high-discrimination items
CAT algorithms frequently select high-discrimination items, which can lead to overexposure of those items if item selection rules are not carefully managed.
Which component of a risk management framework establishes the criteria by which risks are evaluated and prioritized?