Risk Assessment & Mitigation Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
Which scenario BEST illustrates the concept of 'residual risk'?
Answer: The risk remaining after all mitigation measures have been applied
Residual risk is the exposure that remains after controls and mitigations have been applied to the inherent risk.
A CIM professional is conducting a risk assessment and needs to prioritize risks for treatment. Which criterion should be applied FIRST?
Answer: The combination of likelihood and impact scores
Risk prioritization is fundamentally based on the product of likelihood and impact, identifying which risks pose the greatest overall threat.
An organization mandates that all third-party vendors complete a security questionnaire before contract award. This is an example of:
Answer: Supply chain risk mitigation
Vetting vendors through security questionnaires is a proactive supply chain risk mitigation practice.
When applying the DREAD risk scoring model, which of the following is NOT one of the five scoring categories?
Answer: Asset criticality
DREAD stands for Damage, Reproducibility, Exploitability, Affected users, and Discoverability — asset criticality is not a DREAD dimension.
In the context of risk treatment, 'risk transfer' is MOST effectively achieved through:
Answer: Purchasing cyber liability insurance or outsourcing to a third party
Risk transfer shifts the financial consequences of a risk to another party, typically via insurance or contractual agreements.
Which threat modeling framework categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Answer: STRIDE
STRIDE is a Microsoft-developed threat modeling framework using six threat categories as its mnemonic.
A risk owner is PRIMARILY responsible for:
Answer: Making decisions about risk treatment and ensuring mitigation actions are completed
The risk owner has accountability for deciding how the risk is treated and ensuring that agreed mitigation actions are executed.