← All CRA Flashcard Decks

Risk Mitigation and Controls Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Mitigation and Controls flashcards as text
  1. In the context of IT risk, which control layer is responsible for ensuring only authorized users access systems?

    Answer: Logical access controls

    Logical access controls (passwords, MFA, role-based access) govern who can authenticate and what resources they can use within IT systems.

  2. A risk architect evaluates a control and finds it reduces both the likelihood and impact of a risk. This control strategy is known as:

    Answer: Risk mitigation

    Risk mitigation involves implementing controls that reduce the probability, impact, or both dimensions of a risk event.

  3. Which type of control testing involves reviewing documentation and policies without testing actual execution?

    Answer: Design effectiveness testing

    Design effectiveness testing evaluates whether a control is properly designed to address a risk, typically through inquiry and inspection of documentation.

  4. An organization contracts a third-party vendor to process customer data. Which control is most critical to mitigate third-party risk?

    Answer: Vendor due diligence and contractual SLAs with right-to-audit clauses

    Vendor due diligence combined with contractual SLAs and right-to-audit provisions ensures third parties meet security and compliance requirements.

  5. The four Ts of risk response are: Tolerate, Treat, Transfer, and:

    Answer: Terminate

    The four Ts of risk response are Tolerate (accept), Treat (mitigate), Transfer (insure/outsource), and Terminate (avoid by ceasing the activity).

  6. Which framework specifically provides guidance on designing and evaluating internal controls over financial reporting?

    Answer: COSO Internal Control — Integrated Framework

    The COSO Internal Control — Integrated Framework is the globally recognized standard for designing and evaluating internal controls, especially over financial reporting.

  7. A business continuity plan (BCP) is primarily a type of which risk response?

    Answer: Risk treatment / reduction

    A BCP is a risk treatment measure that reduces the impact of disruptions by ensuring the organization can recover and continue critical operations.