Risk Assessment & Mitigation Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
A healthcare organization identifies that ransomware attacks on similar hospitals have increased 40% year-over-year. This information is BEST classified as:
Answer: Threat intelligence used to update risk likelihood scores
Industry-wide attack trend data is threat intelligence that should feed back into the organization's risk likelihood assessments.
The concept of 'defense in depth' in risk mitigation refers to:
Answer: Layering multiple independent controls so that failure of one does not result in full exposure
Defense in depth uses redundant, layered controls so an attacker must defeat multiple barriers, reducing the probability of a successful breach.
An organization's risk appetite statement says 'we will not accept any risk with an impact score above 4 on our 5-point scale.' A new project introduces a risk scored 4/5 impact × 2/5 likelihood. The CORRECT action is:
Answer: Escalate for executive decision since impact exceeds the stated appetite threshold
The impact of 4/5 exceeds the stated appetite ceiling; regardless of likelihood, this must be escalated per policy before proceeding.
Which of the following is an example of a PROACTIVE risk mitigation action?
Answer: Patching a known vulnerability before it is exploited
Patching before exploitation prevents the risk from materializing, making it a proactive (preventive) mitigation.
In the NIST Risk Management Framework (RMF), what is the purpose of the 'Categorize' step?
Answer: To classify information systems according to the potential impact of a security breach
The Categorize step in NIST RMF determines the system's security impact level (Low/Moderate/High) based on confidentiality, integrity, and availability impacts.
A risk that has been transferred via cyber insurance still requires monitoring because:
Answer: Coverage limits, exclusions, and insurer insolvency mean financial risk remains
Insurance policies have caps, exclusions, and conditions; transferred risk is not fully eliminated and residual financial exposure remains.
Which metric measures the expected monetary loss from a specific threat over a one-year period?
Answer: Annual Loss Expectancy (ALE)
ALE = SLE × Annualized Rate of Occurrence, giving the expected average yearly financial loss from a particular threat.