CGRC Risk Assessment and Management 2 — Questions and Answers
Question 1: Which risk assessment methodology uses probability and impact ratings to calculate a risk score?
- Delphi technique
- Qualitative risk assessment
- Quantitative risk assessment
- Semi-quantitative risk assessment (Correct answer)
Correct answer: Semi-quantitative risk assessment
Semi-quantitative risk assessment combines numerical scales for probability and impact to produce a risk score without requiring precise monetary values.
Question 2: A company identifies that a vendor handling PII could be breached. This scenario best represents which risk concept?
- Residual risk
- Inherent risk
- Third-party risk (Correct answer)
- Aggregate risk
Correct answer: Third-party risk
Third-party risk refers to the potential for harm arising from a vendor, supplier, or partner relationship where sensitive data or processes are involved.
Question 3: In NIST SP 800-30, which step immediately follows risk identification?
- Risk monitoring
- Risk framing
- Risk analysis (Correct answer)
- Risk response
Correct answer: Risk analysis
NIST SP 800-30 defines the risk management process as: framing, assessing (identify then analyze), responding, and monitoring — so analysis follows identification.
Question 4: An organization determines that the cost of a control exceeds the potential loss it would prevent. The BEST action is to:
- Transfer the risk to a third party
- Accept the residual risk (Correct answer)
- Implement the control anyway for compliance
- Eliminate the underlying threat
Correct answer: Accept the residual risk
When control costs exceed potential losses, accepting the residual risk is the rational response based on cost-benefit analysis.
Question 5: Which of the following BEST describes the concept of risk appetite?
- The maximum risk an organization can withstand before insolvency
- The total risk exposure before controls are applied
- The amount of risk an organization is willing to accept in pursuit of objectives (Correct answer)
- The residual risk after all controls have been implemented
Correct answer: The amount of risk an organization is willing to accept in pursuit of objectives
Risk appetite is the broad-based amount of risk an organization is willing to accept in pursuit of its mission and strategic goals.
Question 6: When conducting a Business Impact Analysis (BIA), which metric defines the maximum tolerable downtime before significant harm occurs?
- Recovery Point Objective (RPO)
- Mean Time to Repair (MTTR)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Recovery Time Objective (RTO)
Correct answer: Maximum Tolerable Downtime (MTD)
MTD (also called Maximum Tolerable Period of Disruption) is the longest time a business function can be unavailable before causing unacceptable consequences.
Question 7: A risk register entry shows a threat with HIGH likelihood but LOW impact. How should this risk typically be prioritized?
- Highest priority — high likelihood demands immediate mitigation
- Medium priority — monitor and apply cost-effective controls (Correct answer)
- Lowest priority — low impact means the risk can be ignored
- Transfer immediately to an insurer
Correct answer: Medium priority — monitor and apply cost-effective controls
High likelihood / low impact risks warrant medium priority: they occur often but don't cause severe harm, so cost-effective monitoring and controls are appropriate.
Which risk assessment methodology uses probability and impact ratings to calculate a risk score?