CGRC Risk Assessment and Management 5 — Questions and Answers
Question 1: Which NIST publication provides the primary guidance for risk management in federal information systems?
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-30 (Correct answer)
- NIST SP 800-171
Correct answer: NIST SP 800-30
NIST SP 800-30 is the primary guide for conducting risk assessments for federal information systems and organizations.
Question 2: During continuous monitoring, an organization detects a new zero-day vulnerability affecting a critical system. The FIRST step should be to:
- Immediately shut down the affected system
- Assess the risk to determine likelihood and potential impact (Correct answer)
- Notify all users that the system is under attack
- Transfer responsibility to the vendor who built the system
Correct answer: Assess the risk to determine likelihood and potential impact
The first step is always to assess the risk — understanding likelihood and potential impact — before deciding on an appropriate response action.
Question 3: Which of the following is a KEY output of the risk identification phase?
- A prioritized list of risk treatment options
- A risk register containing identified risks and their attributes (Correct answer)
- An approved budget for risk mitigation activities
- A set of key risk indicators (KRIs) for ongoing monitoring
Correct answer: A risk register containing identified risks and their attributes
The risk register is the primary output of risk identification, capturing each identified risk along with its description, owner, and relevant attributes.
Question 4: A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:
- Measures past performance against business objectives
- Provides early warning signals of increasing risk exposure (Correct answer)
- Tracks financial returns on security investments
- Evaluates the effectiveness of implemented controls
Correct answer: Provides early warning signals of increasing risk exposure
KRIs are forward-looking metrics designed to signal emerging or increasing risk before it materializes, whereas KPIs measure historical performance outcomes.
Question 5: An organization operating in multiple jurisdictions must consider different regulatory requirements in its risk assessments. This cross-border complexity is an example of:
- Strategic risk
- Compliance risk (Correct answer)
- Operational risk
- Reputational risk
Correct answer: Compliance risk
Compliance risk is the risk of legal or regulatory sanctions, financial loss, or reputational harm from failure to comply with applicable laws and regulations.
Question 6: Which risk treatment option is MOST appropriate when a risk cannot be avoided, the cost to mitigate is high, and the potential impact is low?
- Transfer the risk via cyber insurance
- Implement additional preventive controls
- Accept the risk and document the decision (Correct answer)
- Avoid the activity generating the risk
Correct answer: Accept the risk and document the decision
When a risk cannot be avoided, mitigation is too costly, and the impact is low, accepting and documenting the risk is the most appropriate and cost-effective response.
Question 7: In enterprise risk management (ERM), which framework introduced the concept of risk in relation to strategy and performance?
- ISO 31000:2018
- COSO ERM 2017 (Correct answer)
- NIST Risk Management Framework
- COBIT 2019
Correct answer: COSO ERM 2017
COSO ERM 2017 (Enterprise Risk Management — Integrating with Strategy and Performance) explicitly linked risk management to strategy-setting and business performance.
Which NIST publication provides the primary guidance for risk management in federal information systems?