← All CIM Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. An incident manager discovers that a critical server has an open RDP port exposed to the internet. Using the risk equation Risk = Threat × Vulnerability × Impact, which variable does the open port MOST directly affect?

    Answer: Vulnerability

    An open, exposed port is a vulnerability — a weakness that increases exploitability regardless of who the threat actor is.

  2. Which of the following BEST describes a 'black swan' event in risk management?

    Answer: A rare, high-impact event that was not predicted by historical models

    Black swan events are characterized by extreme rarity, severe impact, and the tendency to be rationalized in hindsight as predictable.

  3. During a tabletop exercise, the team discovers their risk assessment missed a critical interdependency between two systems. This finding MOST directly highlights a gap in:

    Answer: Business impact analysis completeness

    Missed interdependencies between systems are a BIA gap — the analysis failed to map how one system's failure cascades to another.

  4. ISO 31000 recommends that risk management should be:

    Answer: Integrated into all organizational processes and decision-making

    ISO 31000 positions risk management as an integrated, ongoing organizational function embedded in all processes — not a periodic standalone activity.

  5. A Failure Mode and Effects Analysis (FMEA) assigns a Risk Priority Number (RPN) by multiplying three factors. Which combination is correct?

    Answer: Severity × Occurrence × Detection

    FMEA RPN = Severity × Occurrence × Detection, where each factor is scored 1–10.

  6. When a risk treatment plan is documented, which element is MANDATORY to include for accountability purposes?

    Answer: The named risk owner and target completion date for mitigation actions

    A risk treatment plan must include an accountable owner and a deadline; without these, mitigation actions lack enforceability.

  7. Which approach to risk assessment relies on historical data, loss databases, and statistical models to assign numeric probabilities?

    Answer: Quantitative risk assessment

    Quantitative risk assessment uses objective numerical data — actuarial tables, incident history, and financial models — to calculate precise probability and impact values.