CISA IT Risk Management 4 — Questions and Answers
Question 1: Which role is PRIMARILY responsible for accepting residual risk within an organization?
- IT security manager
- Chief Information Officer (CIO)
- Risk owner or senior management (Correct answer)
- External auditor
Correct answer: Risk owner or senior management
Risk acceptance is a management decision and must be made by the appropriate risk owner or senior management with the authority to do so.
Question 2: A third-party vendor has access to sensitive customer data. Which risk management activity is MOST critical?
- Conducting an annual penetration test on internal systems
- Performing vendor risk assessments and due diligence reviews (Correct answer)
- Encrypting all internal databases
- Implementing multi-factor authentication for employees
Correct answer: Performing vendor risk assessments and due diligence reviews
Third-party access requires formal vendor risk assessments to evaluate whether the vendor's controls adequately protect the organization's data.
Question 3: Which of the following BEST represents the relationship between risk tolerance and risk appetite?
- Risk tolerance is broader than risk appetite
- Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it (Correct answer)
- Risk tolerance and risk appetite are interchangeable terms
- Risk appetite applies to individual risks; tolerance applies to overall strategy
Correct answer: Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it
Risk appetite is the overall level of risk an organization is willing to pursue, while risk tolerance is the acceptable variance around that appetite for specific risks.
Question 4: An IS auditor is reviewing IT risk management practices. Which finding represents the MOST significant control gap?
- Risk assessments are performed every 18 months instead of annually
- Risk scenarios are not linked to specific business processes (Correct answer)
- Risk register entries lack a target remediation date
- Risk owners have not formally acknowledged their responsibilities
Correct answer: Risk scenarios are not linked to specific business processes
Risk scenarios disconnected from business processes cannot be properly prioritized or mitigated because their business impact is unknown.
Question 5: What is the MAIN advantage of using a risk scenario approach in IT risk management?
- It eliminates the need for quantitative risk calculations
- It provides concrete, realistic examples that link threats to business impact (Correct answer)
- It satisfies regulatory requirements without further analysis
- It replaces the need for a risk register
Correct answer: It provides concrete, realistic examples that link threats to business impact
Risk scenarios describe specific threat events and their potential business consequences, making abstract risks tangible and easier to assess.
Question 6: During a risk assessment, a CISA auditor discovers that a critical system has no documented risk treatment plan. What should the auditor recommend FIRST?
- Immediately shut down the system until a plan is in place
- Assign a risk owner and develop a formal risk treatment plan (Correct answer)
- Transfer the risk to a third-party provider immediately
- Accept the risk and document it in the audit report
Correct answer: Assign a risk owner and develop a formal risk treatment plan
The immediate priority is assigning accountability and creating a formal treatment plan to address the gap in governance.
Question 7: Which of the following BEST describes a risk scenario used in IT risk management frameworks like COBIT?
- A description of a past security incident
- A narrative that connects a threat actor, event, and business impact (Correct answer)
- A list of controls that prevent a specific risk
- A financial model that calculates potential losses
Correct answer: A narrative that connects a threat actor, event, and business impact
A risk scenario in COBIT combines a threat source, vulnerability, and resulting business impact into a coherent narrative for assessment purposes.
Which role is PRIMARILY responsible for accepting residual risk within an organization?