Risk Assessment & Mitigation Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
A quantitative risk assessment assigns a risk score of 0.15 to a threat. Which formula was most likely used to calculate this value?
Answer: Impact × Likelihood on a 0–1 normalized scale
A normalized 0–1 score is produced by multiplying probability (likelihood) by impact, both scaled to a 0–1 range.
Which mitigation strategy is MOST appropriate when the cost of controlling a risk exceeds the value of the asset at risk?
Answer: Risk acceptance
When control costs outweigh asset value, risk acceptance (knowingly tolerating the risk) is the rational economic choice.
During a business impact analysis, the Recovery Point Objective (RPO) is best described as:
Answer: The point in time to which data must be restored after an incident
RPO defines the maximum age of data that must be recovered, determining backup frequency requirements.
A threat agent exploits a known unpatched vulnerability in a web application. In risk terminology, the 'vulnerability' refers to:
Answer: A weakness that can be exploited to cause harm
A vulnerability is a weakness or gap in protection that a threat agent can exploit.
Which control type is specifically designed to DETECT risks after they have materialized?
Answer: Detective controls
Detective controls identify and alert on incidents or anomalies that have already occurred.
An organization uses a 5×5 risk matrix. A risk rated 4 (high likelihood) × 5 (critical impact) is most appropriately managed by:
Answer: Immediate escalation and priority mitigation
A score of 20/25 on a 5×5 matrix is a critical risk requiring immediate escalation and priority treatment.
What is the PRIMARY purpose of a risk register in incident management?
Answer: To track identified risks, their scores, owners, and treatment status
A risk register is a living document that records all identified risks along with their assessments, owners, and mitigation plans.