โ† All CRA Flashcard Decks

Risk Identification Principles Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Identification Principles flashcards as text
  1. Which risk identification technique involves systematically examining each component of a system to determine how it could fail and the consequences of that failure?

    Answer: Failure Mode and Effects Analysis (FMEA)

    FMEA systematically analyzes each component to identify potential failure modes and their effects on the overall system.

  2. In risk identification, what does the term 'velocity' refer to?

    Answer: The speed at which a risk can impact the organization after it materializes

    Risk velocity describes how quickly a risk can affect the organization once it has been triggered, influencing response time requirements.

  3. A risk architect is reviewing an organization's supply chain. Which approach best identifies risks that span multiple vendors and interdependencies?

    Answer: End-to-end process mapping with cross-vendor dependency identification

    End-to-end process mapping reveals interdependencies and cascading risks across multiple vendors that isolated reviews would miss.

  4. Which of the following best describes a 'risk trigger' in the identification process?

    Answer: An early warning indicator that signals a risk event may be imminent

    A risk trigger is an early warning sign or condition that indicates a risk event is likely to occur, enabling proactive response.

  5. When using structured interviews for risk identification, what is the PRIMARY advantage over group workshops?

    Answer: Interviews allow individuals to express concerns without group influence or anchoring bias

    One-on-one interviews prevent groupthink and anchoring bias, allowing interviewees to freely share risks they might suppress in a group setting.

  6. A CRA candidate reviews an organization's risk register and finds many risks are described as 'compliance failure' or 'cyber breach.' What is the main problem with these descriptions?

    Answer: They lack root cause context and confuse risk events with risk categories

    Broad category labels without root cause context make risks difficult to assess, own, or mitigate because they do not describe specific, actionable scenarios.

  7. Which risk identification tool uses a visual representation of causal relationships between a central risk event, its causes, and its consequences simultaneously?

    Answer: Bow-tie analysis

    Bow-tie analysis places the risk event at the center, displaying threat causes on the left and consequence pathways on the right in a single diagram.