CGRC Risk Assessment and Management 4 — Questions and Answers
Question 1: An Annualized Loss Expectancy (ALE) is calculated as:
- Asset Value × Annualized Rate of Occurrence
- Single Loss Expectancy ÷ Annualized Rate of Occurrence
- Single Loss Expectancy × Annualized Rate of Occurrence (Correct answer)
- Exposure Factor × Annualized Rate of Occurrence
Correct answer: Single Loss Expectancy × Annualized Rate of Occurrence
ALE = SLE × ARO; it represents the expected annual monetary loss from a specific threat given how often that threat is expected to occur.
Question 2: Which risk assessment approach is MOST appropriate when precise data is unavailable but expert judgment can be gathered?
- Quantitative Monte Carlo simulation
- Qualitative risk assessment (Correct answer)
- Fault tree analysis
- Failure Mode and Effects Analysis (FMEA)
Correct answer: Qualitative risk assessment
Qualitative risk assessment uses expert judgment and descriptive scales (High/Medium/Low) when hard data is unavailable or cost-prohibitive to gather.
Question 3: A risk owner is PRIMARILY responsible for:
- Documenting every risk in the enterprise risk register
- Accepting, mitigating, or transferring risks within their area (Correct answer)
- Auditing the effectiveness of controls across the organization
- Setting the organization's overall risk appetite
Correct answer: Accepting, mitigating, or transferring risks within their area
A risk owner is accountable for managing a specific risk, including deciding on treatment options within their domain and monitoring outcomes.
Question 4: Which of the following BEST distinguishes risk tolerance from risk appetite?
- Risk tolerance is set by regulators; risk appetite is set internally
- Risk appetite is the strategic willingness to accept risk; risk tolerance is the acceptable variance around that level (Correct answer)
- Risk tolerance is broader and applies enterprise-wide; risk appetite applies to individual projects
- They are interchangeable terms in modern GRC frameworks
Correct answer: Risk appetite is the strategic willingness to accept risk; risk tolerance is the acceptable variance around that level
Risk appetite is the overall desired level of risk, while risk tolerance defines the acceptable deviation above or below that appetite in practice.
Question 5: An organization performs a threat analysis and finds that employees are the most frequent source of incidents. This category of threat source is called:
- Environmental threat
- Structural threat
- Accidental threat
- Insider threat (Correct answer)
Correct answer: Insider threat
Insider threats originate from current or former employees, contractors, or business partners who misuse authorized access, whether maliciously or accidentally.
Question 6: In the context of CGRC, a risk heat map is PRIMARILY used to:
- Calculate precise financial losses from each identified risk
- Visually communicate risk likelihood and impact to stakeholders (Correct answer)
- Document the technical details of every vulnerability
- Assign legal liability for risk events to specific departments
Correct answer: Visually communicate risk likelihood and impact to stakeholders
A risk heat map provides a visual matrix of risks plotted by likelihood and impact, making it easy for stakeholders to prioritize and communicate risk posture.
Question 7: Which statement BEST describes residual risk?
- The risk that exists before any controls are implemented
- The risk that remains after all planned risk treatment measures have been applied (Correct answer)
- The risk transferred to an insurance provider
- The risk identified during an audit but not yet assigned to an owner
Correct answer: The risk that remains after all planned risk treatment measures have been applied
Residual risk is what remains after controls and other risk treatments have been applied; it is the risk an organization accepts going forward.
An Annualized Loss Expectancy (ALE) is calculated as: