Risk Management & Mitigation Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
An application developer is evaluating risks for a cloud migration project. Which type of risk assessment method assigns numerical values to risks?
Answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values and statistical methods to express risk in measurable terms such as dollar amounts.
A software team uses a risk burndown chart. What does this chart primarily track?
Answer: The reduction in total risk exposure across sprints
A risk burndown chart visualizes how total risk exposure decreases over time as risks are mitigated or resolved during a project.
Which of the following BEST describes a risk trigger in project management?
Answer: An early warning sign that a risk event is about to occur
A risk trigger is an indicator or symptom that signals a risk event is imminent, prompting execution of the risk response plan.
When building a new authentication module, a developer identifies dependency rot as a risk. Which mitigation technique is MOST effective?
Answer: Automated dependency scanning integrated into the CI/CD pipeline
Integrating automated dependency scanners (e.g., Dependabot, Snyk) into CI/CD continuously detects vulnerable or outdated dependencies.
A project risk has a 30% probability of occurring and an impact of $50,000. What is the Expected Monetary Value (EMV)?
Answer: $15,000
EMV = Probability × Impact = 0.30 × $50,000 = $15,000.
Which risk response strategy is being used when a company purchases cyber liability insurance for its application?
Answer: Risk transfer
Purchasing insurance transfers the financial consequences of a risk to a third party (the insurer).
In a risk management plan, what is the role of a Risk Owner?
Answer: To be accountable for monitoring and executing the response for a specific risk
A Risk Owner is assigned accountability for a specific risk, ensuring its response plan is monitored and executed appropriately.