โ† All CRA Flashcard Decks

Risk Identification & Assessment Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Identification & Assessment flashcards as text
  1. When performing a Monte Carlo simulation for risk assessment, what does the output typically represent?

    Answer: A probability distribution of possible outcomes across thousands of simulated scenarios

    Monte Carlo simulation runs thousands of iterations with variable inputs to produce a probability distribution showing the range and likelihood of possible outcomes.

  2. A risk architect identifies that a new regulation requires data localization, preventing cross-border data transfers. This is best classified as which type of risk?

    Answer: Compliance/regulatory risk

    Data localization laws represent compliance and regulatory risk, as violations can result in fines, operational restrictions, or legal penalties.

  3. In the FAIR (Factor Analysis of Information Risk) model, what are the two primary components used to calculate risk magnitude?

    Answer: Loss Event Frequency and Loss Magnitude

    The FAIR model calculates risk as the combination of Loss Event Frequency (how often) and Loss Magnitude (how much), producing a quantitative risk value.

  4. Which of the following represents a 'secondary risk' in risk management?

    Answer: A risk that arises as a direct result of implementing a risk response

    Secondary risks are new risks that emerge as unintended consequences of implementing a risk response or mitigation action.

  5. An organization identifies that multiple independently unlikely events, if they occurred simultaneously, would create a catastrophic outcome. Which risk assessment concept describes this scenario?

    Answer: Compound risk or risk confluence

    Compound or confluent risk describes scenarios where the simultaneous occurrence of individually unlikely events combines to produce catastrophic outcomes.

  6. What is the primary purpose of a risk register in an enterprise risk management program?

    Answer: To serve as a centralized record documenting identified risks, their attributes, and assigned ownership

    The risk register is a central repository that captures all identified risks, their likelihood, impact, owners, and response strategies for tracking and governance.

  7. Which of the following best describes 'systemic risk' in the context of financial risk architecture?

    Answer: Risk that the failure of one entity can cascade through interconnected systems to cause widespread collapse

    Systemic risk is the danger that failure of one interconnected institution or market participant triggers cascading failures throughout the broader financial system.