Risk Assessment & Mitigation Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
An incident manager discovers that a critical server has an open RDP port exposed to the internet. Using the risk equation Risk = Threat × Vulnerability × Impact, which variable does the open port MOST directly affect?
Answer: Vulnerability
An open, exposed port is a vulnerability — a weakness that increases exploitability regardless of who the threat actor is.
Which of the following BEST describes a 'black swan' event in risk management?
Answer: A rare, high-impact event that was not predicted by historical models
Black swan events are characterized by extreme rarity, severe impact, and the tendency to be rationalized in hindsight as predictable.
During a tabletop exercise, the team discovers their risk assessment missed a critical interdependency between two systems. This finding MOST directly highlights a gap in:
Answer: Business impact analysis completeness
Missed interdependencies between systems are a BIA gap — the analysis failed to map how one system's failure cascades to another.
ISO 31000 recommends that risk management should be:
Answer: Integrated into all organizational processes and decision-making
ISO 31000 positions risk management as an integrated, ongoing organizational function embedded in all processes — not a periodic standalone activity.
A Failure Mode and Effects Analysis (FMEA) assigns a Risk Priority Number (RPN) by multiplying three factors. Which combination is correct?
Answer: Severity × Occurrence × Detection
FMEA RPN = Severity × Occurrence × Detection, where each factor is scored 1–10.
When a risk treatment plan is documented, which element is MANDATORY to include for accountability purposes?
Answer: The named risk owner and target completion date for mitigation actions
A risk treatment plan must include an accountable owner and a deadline; without these, mitigation actions lack enforceability.
Which approach to risk assessment relies on historical data, loss databases, and statistical models to assign numeric probabilities?
Answer: Quantitative risk assessment
Quantitative risk assessment uses objective numerical data — actuarial tables, incident history, and financial models — to calculate precise probability and impact values.