Certified Risk Architect (CRA) — Questions and Answers
Question 1: What is the main goal of enterprise risk management (ERM)?
- To avoid operational challenges.
- To reduce the workforce.
- To identify and manage risks to achieve business goals (Correct answer)
- To eliminate all risks.
Correct answer: To identify and manage risks to achieve business goals
The main goal of Enterprise Risk Management (ERM) is to holistically identify, assess, manage, and monitor all types of risks across an entire organization. ERM aims to understand and manage these risks strategically to protect and enhance organizational value. This enables the business to achieve its objectives more effectively and sustainably by making informed decisions about risk.
Question 2: A risk architect is assessing supply chain risk and uses a technique that traces each material back to its origin through every tier of suppliers. Which technique is this?
- Control Self-Assessment (CSA)
- Multi-tier Supply Chain Mapping (Correct answer)
- Root Cause Analysis (RCA)
- Failure Mode and Effects Analysis (FMEA)
Correct answer: Multi-tier Supply Chain Mapping
Multi-tier supply chain mapping traces materials and dependencies through all supplier tiers to identify hidden concentration, geographic, or geopolitical risks.
Question 3: Whistleblower protections under the Dodd-Frank Act are designed to:
- Protect employees who report violations of securities laws to the SEC from employer retaliation (Correct answer)
- Allow employees to sue competitors for market manipulation
- Grant immunity from prosecution to all employees who self-report misconduct
- Require mandatory arbitration of employment disputes
Correct answer: Protect employees who report violations of securities laws to the SEC from employer retaliation
Dodd-Frank's whistleblower provisions protect employees from retaliation and provide financial awards to those who report securities law violations to the SEC.
Question 4: What does Recovery Time Objective (RTO) define in business continuity planning?
- The total budget allocated for recovery operations
- The maximum acceptable time to restore a business function after a disruption (Correct answer)
- The maximum allowable distance to a backup facility
- The minimum number of staff required for recovery operations
Correct answer: The maximum acceptable time to restore a business function after a disruption
RTO is the maximum tolerable downtime for a critical business function, defining how quickly it must be restored to avoid unacceptable consequences.
Question 5: In a risk heat map, which scenario calls for the most urgent mitigation action?
- Low likelihood, high impact
- Low likelihood, low impact
- High likelihood, low impact
- High likelihood, high impact (Correct answer)
Correct answer: High likelihood, high impact
High likelihood combined with high impact places a risk in the critical zone of the heat map, requiring immediate and aggressive mitigation.
Question 6: What is a 'hot site' in the context of disaster recovery?
- A fully operational backup facility ready for immediate takeover if the primary site fails (Correct answer)
- A data center with elevated cooling requirements
- A temporary leased office location for displaced employees
- A site used exclusively for long-term data archival storage
Correct answer: A fully operational backup facility ready for immediate takeover if the primary site fails
A hot site is a fully equipped and operational backup facility that can immediately assume operations if the primary site becomes unavailable.
Question 7: Under the SEC's Regulation S-P, financial firms must provide customers with a clear and conspicuous notice of their privacy policies. When must the initial privacy notice be delivered?
- Within 30 days after account opening
- Only when the firm changes its privacy practices
- Annually, at any point during the calendar year
- At the time of establishing a customer relationship (Correct answer)
Correct answer: At the time of establishing a customer relationship
Regulation S-P requires firms to provide an initial privacy notice at the time of establishing a customer relationship, not after the fact.
Question 8: Which type of risk response involves partnering with another organization to share both the potential gain and loss of a risky venture?
- Risk reduction
- Risk sharing (Correct answer)
- Risk transfer
- Risk acceptance
Correct answer: Risk sharing
Risk sharing distributes the risk exposure between parties, with both bearing portions of any resulting losses or gains.
Question 9: Which correlation measure is most appropriate when assessing the relationship between two non-normally distributed risk variables?
- Covariance matrix
- Spearman rank correlation (Correct answer)
- Linear regression slope
- Pearson correlation coefficient
Correct answer: Spearman rank correlation
Spearman rank correlation is non-parametric and does not assume normality, making it suitable for non-normal distributions.
Question 10: What does Recovery Point Objective (RPO) represent in business continuity?
- The geographic location of the primary recovery facility
- The ceiling on total recovery spending
- The maximum acceptable amount of data loss measured in time (Correct answer)
- The minimum number of data backup copies required
Correct answer: The maximum acceptable amount of data loss measured in time
RPO defines the maximum tolerable data loss, representing how far back in time data can be restored from backups in a recovery scenario.
Question 11: What does NIST Special Publication 800-34 provide guidance on?
- Physical security standards for federal facilities
- Federal agency password management and authentication standards
- Contingency planning for federal information systems (Correct answer)
- Network security architecture design for government agencies
Correct answer: Contingency planning for federal information systems
NIST SP 800-34 provides guidelines for developing and implementing contingency plans for federal information systems to ensure continuity of operations.
Question 12: In multi-period risk modeling, which of the following correctly describes the 'square root of time' rule for scaling VaR?
- Multiply 1-day VaR by the square root of the number of holding days assuming i.i.d. returns (Correct answer)
- Multiply 1-day VaR by the number of holding days to get multi-day VaR
- Apply the square root only when losses are negatively correlated across days
- Divide 1-year VaR by 252 to obtain daily VaR in all market conditions
Correct answer: Multiply 1-day VaR by the square root of the number of holding days assuming i.i.d. returns
Under the assumption of independent, identically distributed returns, the T-day VaR equals the 1-day VaR multiplied by √T.
Question 13: Which of the following best describes 'risk aggregation' in enterprise-wide quantitative risk management?
- Assigning a single risk owner for all identified risk categories
- Combining individual risk exposures across business units accounting for diversification and correlations (Correct answer)
- Adding up all expected losses without considering interdependencies
- Listing all identified risks in a single risk register
Correct answer: Combining individual risk exposures across business units accounting for diversification and correlations
Risk aggregation combines exposures across the enterprise while accounting for correlation and diversification benefits to derive a total risk picture.
Question 14: The governance principle of 'tone at the top' refers most directly to:
- Setting the loudest internal communication channels for risk escalation
- The board's responsibility to set IT governance standards
- Establishing loud automated alerts for breaches of risk limits
- Senior leadership's visible commitment to ethical conduct and sound risk management (Correct answer)
Correct answer: Senior leadership's visible commitment to ethical conduct and sound risk management
Tone at the top describes how senior leaders' attitudes, behaviors, and priorities shape the organization's risk culture throughout the hierarchy.
Question 15: How can technology aid in regulatory compliance?
- By automating monitoring and updates (Correct answer)
- By delaying decision-making processes.
- By eliminating the need for training.
- By reducing the need for compliance officers.
Correct answer: By automating monitoring and updates
Technology significantly aids regulatory compliance by automating various monitoring and update processes. This includes tracking regulatory changes, ensuring adherence to internal policies, generating compliance reports, and managing vast amounts of documentation. Automation reduces manual effort, improves accuracy, and enables organizations to respond quickly and efficiently to evolving compliance requirements.
Question 16: What is the primary responsibility of a Crisis Management Team (CMT)?
- To manage media subscription renewals during incidents
- To market products and services during a business crisis
- To direct and coordinate the organization's strategic response to a major incident (Correct answer)
- To process all insurance claims resulting from a crisis
Correct answer: To direct and coordinate the organization's strategic response to a major incident
The Crisis Management Team coordinates the overall organizational response to a crisis, making strategic decisions to protect people, assets, and reputation.
Question 17: Which of the following represents a key weakness in relying solely on insurance as a risk mitigation strategy?
- Insurance does not cover all types of losses and may not compensate for reputational damage (Correct answer)
- Insurance eliminates the need for preventive controls
- Insurance is only available for financial institutions
- Insurance eliminates both financial and reputational consequences of risk events
Correct answer: Insurance does not cover all types of losses and may not compensate for reputational damage
Insurance can offset direct financial losses but cannot fully compensate for reputational harm, regulatory penalties, or operational disruptions from risk events.
Question 18: Which of the following BEST describes the purpose of a 'risk universe' in enterprise risk management?
- A comprehensive inventory of all risk types the organization could potentially face across all domains (Correct answer)
- A set of risk thresholds approved by the board of directors
- A ranked list of the organization's top ten most critical active risks
- A database of all historical risk events that have already occurred in the organization
Correct answer: A comprehensive inventory of all risk types the organization could potentially face across all domains
A risk universe provides a complete catalog of potential risk categories, ensuring risk identification efforts are exhaustive and systematic rather than reactive.
Question 19: A copula function in risk modeling is used primarily to:
- Model the dependence structure between random variables independently of their marginals (Correct answer)
- Estimate the marginal distribution of individual risk variables
- Calculate the expected value of a portfolio of risks
- Convert discrete risk events into continuous probability distributions
Correct answer: Model the dependence structure between random variables independently of their marginals
Copulas capture the joint dependence structure between variables while allowing separate modeling of each variable's marginal distribution.
Question 20: In the Poisson process model for operational risk frequency, what does the parameter λ (lambda) represent?
- The average number of loss events per unit time (Correct answer)
- The probability that any single transaction results in a loss
- The expected severity of each loss event
- The maximum number of events in the observation period
Correct answer: The average number of loss events per unit time
Lambda is the rate parameter of the Poisson distribution, representing the mean number of events occurring per time period.
Question 21: Which of the following quantitative risk analysis techniques is best suited for modeling the combined effect of uncertainties in multiple project variables to estimate the probability of achieving cost and schedule objectives?
- Sensitivity Analysis
- Expected Monetary Value (EMV)
- Monte Carlo Simulation (Correct answer)
- Decision Tree Analysis
Correct answer: Monte Carlo Simulation
Monte Carlo Simulation is a technique that runs a project model thousands of times, each time with different random values for the uncertain variables (like task durations or costs). This process generates a probability distribution of possible outcomes for the entire project, making it ideal for understanding the combined impact of multiple uncertainties on objectives like cost and schedule.
Question 22: The 'materiality' threshold in financial reporting is BEST defined as:
- Any amount exceeding $1 million regardless of context
- Only items flagged by external auditors
- Information whose omission or misstatement could influence users' economic decisions (Correct answer)
- Items that exceed 5% of net income by GAAP standards
Correct answer: Information whose omission or misstatement could influence users' economic decisions
Materiality is a qualitative and quantitative concept defined as information whose omission or misstatement could influence the decisions of reasonable users.
Question 23: An organization purchases cyber liability insurance to offset potential data breach losses. This is an example of:
- Risk reduction
- Risk elimination
- Risk transfer (Correct answer)
- Risk avoidance
Correct answer: Risk transfer
Insurance shifts the financial burden of a risk event to a third party, making it a risk transfer strategy.
Question 24: What is the primary function of Key Risk Indicators (KRIs) in a risk technology system?
- To provide early warning signals of increasing risk exposure (Correct answer)
- To monitor customer purchasing behavior
- To measure employee productivity levels
- To calculate financial returns on investments
Correct answer: To provide early warning signals of increasing risk exposure
KRIs serve as early warning metrics that signal when risk levels are approaching unacceptable thresholds, enabling proactive risk management.
Question 25: In assessing the financial stability of its loan portfolio, a commercial bank is primarily concerned with the potential for loss resulting from a borrower's inability to repay their debt obligations. This specific type of financial risk is best defined as:
- Operational Risk
- Credit Risk (Correct answer)
- Liquidity Risk
- Market Risk
Correct answer: Credit Risk
Credit risk is specifically defined as the risk of financial loss arising from a borrower or counterparty failing to meet their contractual obligations to repay a debt. Market risk relates to losses from market price movements, liquidity risk to the inability to meet short-term cash obligations, and operational risk to failures in internal processes, people, and systems.
Question 26: What is the key distinction between 'inherent risk' and 'residual risk' in the risk identification and assessment process?
- Inherent risk is quantified while residual risk is qualitative
- Inherent risk applies only to financial risks while residual risk applies to operational risks
- Inherent risk exists before any controls are applied; residual risk remains after controls are in place (Correct answer)
- Residual risk is always lower than inherent risk by a fixed percentage
Correct answer: Inherent risk exists before any controls are applied; residual risk remains after controls are in place
Inherent risk is the raw exposure level without controls, while residual risk reflects the exposure that persists after existing controls are factored in.
Question 27: Which section of the Dodd-Frank Act created the Financial Stability Oversight Council (FSOC) to identify and respond to systemic risks to U.S. financial stability?
- Title I (Correct answer)
- Title VII
- Title X
- Title II
Correct answer: Title I
Title I of the Dodd-Frank Act established FSOC and authorized it to designate nonbank financial companies as systemically important financial institutions (SIFIs).
Question 28: When conducting a compliance risk assessment, which scenario best illustrates 'inherent risk' as opposed to 'residual risk'?
- The risk accepted by the board after reviewing audit findings
- The risk transferred to a third-party vendor through contract
- The risk remaining after controls have been applied and tested
- The risk level before any controls or mitigating factors are considered (Correct answer)
Correct answer: The risk level before any controls or mitigating factors are considered
Inherent risk is the raw exposure to a compliance violation before any controls, policies, or mitigating activities are factored in.
Question 29: What is the primary role of senior management in a business continuity program?
- To manage IT help desk operations during active recovery scenarios
- To personally conduct and lead all business continuity tests and exercises
- To personally author all detailed technical recovery procedures
- To provide strategic direction, resources, and accountability for the BCP program (Correct answer)
Correct answer: To provide strategic direction, resources, and accountability for the BCP program
Senior management champions the BCP program, ensures adequate resources, sets risk tolerance, and holds the organization accountable for maintaining continuity capabilities.
Question 30: In TPRM, what does the term 'vendor lifecycle management' encompass?
- Monitoring vendor financial performance from IPO through potential acquisition
- Managing only the contract negotiation and execution phases of vendor relationships
- Overseeing vendor relationships from initial due diligence through offboarding and termination (Correct answer)
- Tracking vendor product development cycles and release schedules
Correct answer: Overseeing vendor relationships from initial due diligence through offboarding and termination
Vendor lifecycle management covers all stages of a vendor relationship, including selection, due diligence, onboarding, ongoing monitoring, and offboarding.
Certified Risk Architect (CRA)
The Certified Risk Architect (CRA) credential validates expertise in designing and implementing enterprise risk management frameworks, covering business continuity, regulatory compliance, quantitative risk analysis, mitigation strategies, and risk technology.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds