CISA IT Risk Management 3 — Questions and Answers
Question 1: Which ISACA framework is MOST directly aligned with IT risk management practices for CISA candidates?
- COBIT 2019 (Correct answer)
- ITIL 4
- ISO 9001
- TOGAF
Correct answer: COBIT 2019
COBIT 2019 is ISACA's primary governance and management framework, which includes specific guidance on IT risk management.
Question 2: A company's IT risk management process identifies a vulnerability but determines no credible threat exploits it. What is the MOST appropriate action?
- Immediately remediate the vulnerability
- Document it and accept the risk without controls
- Monitor it in case a credible threat emerges (Correct answer)
- Escalate to senior management for immediate action
Correct answer: Monitor it in case a credible threat emerges
Without a credible threat, the immediate risk is low, but the vulnerability should be monitored in case the threat landscape changes.
Question 3: In the context of IT risk management, what is 'inherent risk'?
- Risk remaining after controls are implemented
- Risk that cannot be mitigated under any circumstances
- Risk level before any controls are applied (Correct answer)
- Risk accepted by senior management
Correct answer: Risk level before any controls are applied
Inherent risk is the raw or gross risk that exists in the absence of any control measures.
Question 4: Which of the following is an example of a QUALITATIVE risk analysis technique?
- Calculating Annualized Loss Expectancy (ALE)
- Using a 5x5 risk heat map with High/Medium/Low ratings (Correct answer)
- Computing the Return on Security Investment (ROSI)
- Estimating Single Loss Expectancy (SLE) in dollars
Correct answer: Using a 5x5 risk heat map with High/Medium/Low ratings
A risk heat map using descriptive categories like High, Medium, and Low is a qualitative technique that does not rely on precise numerical values.
Question 5: During an IT audit, a CISA finds that risk assessments are performed annually by IT staff without business unit input. What is the GREATEST weakness?
- Assessments are not frequent enough
- Risk assessments lack business context and may miss operational risks (Correct answer)
- IT staff are not qualified to assess risk
- The assessments are not automated
Correct answer: Risk assessments lack business context and may miss operational risks
Excluding business units means assessments may miss key operational risks and fail to align with business objectives.
Question 6: What is the PRIMARY goal of IT risk communication within an organization?
- To document all risks in a central repository
- To ensure decision-makers have timely, accurate risk information (Correct answer)
- To transfer risk responsibility to risk owners
- To satisfy external regulatory requirements
Correct answer: To ensure decision-makers have timely, accurate risk information
Risk communication ensures that relevant stakeholders receive accurate information to make informed decisions about risk response.
Question 7: An organization wants to determine the financial impact of a specific risk scenario. Which formula is MOST relevant?
- Risk = Threat × Vulnerability
- ALE = ARO × SLE (Correct answer)
- Risk Score = Likelihood + Impact
- Control Effectiveness = 1 − Residual Risk
Correct answer: ALE = ARO × SLE
ALE (Annualized Loss Expectancy) = ARO (Annualized Rate of Occurrence) × SLE (Single Loss Expectancy) quantifies expected annual financial loss.
Which ISACA framework is MOST directly aligned with IT risk management practices for CISA candidates?