← All CAD Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. A development team discovers a critical security vulnerability in a third-party library used in production. Which risk response strategy is MOST appropriate?

    Answer: Mitigate by patching or replacing the library immediately

    Mitigation involves taking immediate action to reduce the probability or impact of the risk, such as patching or replacing the vulnerable library.

  2. Which metric is used to calculate the Annual Loss Expectancy (ALE) in quantitative risk assessment?

    Answer: Single Loss Expectancy × Annualized Rate of Occurrence

    ALE = SLE × ARO, where SLE is the Single Loss Expectancy and ARO is the Annualized Rate of Occurrence.

  3. During sprint planning, a team identifies that a new API integration has uncertain requirements. What risk mitigation technique should they apply?

    Answer: Spike solution to explore feasibility before committing

    A spike is a time-boxed research task used in Agile to reduce uncertainty before committing to a full implementation.

  4. A risk register entry shows a risk with high probability but low impact. According to a standard risk matrix, how should this risk be prioritized?

    Answer: Medium — monitor and plan response

    High probability combined with low impact typically places a risk in the medium priority zone, requiring monitoring and a planned response.

  5. What is the purpose of a fallback plan in risk management?

    Answer: To execute when the primary risk response fails

    A fallback plan is a contingency response activated when the primary mitigation strategy proves ineffective.

  6. A CAD project's risk log shows a residual risk after controls are applied. What does residual risk represent?

    Answer: The risk remaining after all mitigation measures have been applied

    Residual risk is the level of risk that remains after controls and mitigations have been implemented.

  7. Which approach best describes risk avoidance in software development?

    Answer: Changing the project plan to eliminate the risky activity

    Risk avoidance involves altering plans or scope to completely remove the threat, not just reduce it.