CGRC Risk Assessment and Management 3 — Questions and Answers
Question 1: Which quantitative risk metric represents the expected monetary loss from a specific threat occurring once?
- Annualized Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Exposure Factor (EF)
- Annualized Rate of Occurrence (ARO)
Correct answer: Single Loss Expectancy (SLE)
SLE = Asset Value × Exposure Factor, representing the dollar loss expected from a single threat event.
Question 2: An organization uses insurance to shift financial exposure from a cyberattack to a third party. This is an example of:
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequence of a risk to another party, most commonly through insurance or contractual indemnification.
Question 3: In ISO 31000, which component provides the mandate and commitment for risk management?
- Risk communication and consultation
- Risk treatment
- Establishing the context
- Principles and framework (Correct answer)
Correct answer: Principles and framework
ISO 31000 structures risk management into Principles, Framework, and Process — the framework provides the mandate and commitment from leadership.
Question 4: A CGRC professional performing a risk assessment notices that two separate low-level risks, when combined, create a high-impact exposure. This is best described as:
- Compound risk
- Aggregate risk (Correct answer)
- Cascading risk
- Residual risk
Correct answer: Aggregate risk
Aggregate risk refers to the combined effect of multiple individual risks that together create a larger overall exposure than each risk alone would suggest.
Question 5: Which control type is BEST suited to reduce the likelihood of a threat exploiting a vulnerability?
- Detective control
- Corrective control
- Compensating control
- Preventive control (Correct answer)
Correct answer: Preventive control
Preventive controls reduce the likelihood that a threat will successfully exploit a vulnerability by blocking or discouraging the threat.
Question 6: During risk treatment, an organization decides to stop offering a high-risk product line to eliminate exposure. This strategy is:
- Risk transfer
- Risk mitigation
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance means eliminating the activity or condition that gives rise to the risk entirely, removing exposure rather than managing it.
Question 7: Which of the following BEST describes a vulnerability in the context of risk assessment?
- A potential event that could cause harm to an asset
- A weakness that could be exploited by a threat (Correct answer)
- The likelihood that a threat will occur in a given period
- The financial impact resulting from a successful attack
Correct answer: A weakness that could be exploited by a threat
A vulnerability is a weakness or gap in protection that a threat could exploit to cause harm to an asset.
Which quantitative risk metric represents the expected monetary loss from a specific threat occurring once?