CCT Risk Management & Internal Controls 2 — Questions and Answers
Question 1: Which risk assessment technique assigns numerical probabilities and financial values to potential losses to calculate an expected monetary outcome?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Residual risk mapping
- Control self-assessment
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical data—likelihood percentages and monetary impact—to compute expected loss values such as Annual Loss Expectancy (ALE).
Question 2: A 'three lines of defense' model assigns the primary ownership of risk management to which line?
- Internal audit
- Compliance and risk functions
- Business unit management (Correct answer)
- Board of directors
Correct answer: Business unit management
The first line of defense consists of business unit management, who own and manage risks in day-to-day operations.
Question 3: When a company purchases cyber liability insurance to handle the financial impact of a data breach, it is employing which risk response strategy?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequence of a risk to a third party, such as an insurer, without eliminating the underlying risk.
Question 4: Which internal control activity involves comparing financial data against prior periods or industry benchmarks to detect anomalies?
- Physical controls
- Analytical procedures (Correct answer)
- Segregation of duties
- Authorization controls
Correct answer: Analytical procedures
Analytical procedures use comparisons and ratio analyses to identify unexpected variances that may indicate errors or fraud.
Question 5: A company identifies that a risk's likelihood is low but its potential impact is catastrophic. How should this risk typically be prioritized?
- Treated as low priority because probability is minimal
- Ignored until impact occurs
- Escalated and monitored closely due to high impact (Correct answer)
- Transferred without further analysis
Correct answer: Escalated and monitored closely due to high impact
High-impact risks require attention regardless of low probability because the potential harm to the organization can be severe or irreversible.
Question 6: What does 'inherent risk' refer to in the context of compliance risk management?
- Risk remaining after all controls are applied
- The gross risk before any controls are in place (Correct answer)
- Risk accepted by senior management
- Risk transferred to a third party
Correct answer: The gross risk before any controls are in place
Inherent risk is the raw level of risk exposure that exists before any mitigating controls or risk responses are implemented.
Question 7: Which of the following is an example of a detective control?
- Dual authorization required before a wire transfer is initiated
- Encryption of data at rest to prevent unauthorized access
- Monthly bank reconciliations to identify discrepancies (Correct answer)
- Locked server rooms to restrict physical access
Correct answer: Monthly bank reconciliations to identify discrepancies
Detective controls identify errors or irregularities after they have occurred; bank reconciliations catch discrepancies post-transaction.
Which risk assessment technique assigns numerical probabilities and financial values to potential losses to calculate an expected monetary outcome?