Risk Mitigation Strategies & Controls Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Mitigation Strategies & Controls flashcards as text
An organization implements multi-factor authentication (MFA) for all remote access. After a breach still occurs via a stolen token, the MFA is considered a control that:
Answer: Reduced but did not eliminate residual risk
MFA reduced the likelihood of unauthorized access but did not eliminate all risk vectors, demonstrating that residual risk persists even with strong controls.
In a risk heat map, which scenario calls for the most urgent mitigation action?
Answer: High likelihood, high impact
High likelihood combined with high impact places a risk in the critical zone of the heat map, requiring immediate and aggressive mitigation.
A CRA candidate is evaluating whether to recommend a $2M control implementation to mitigate a risk with an annualized loss expectancy of $500K. What is the most appropriate recommendation?
Answer: Accept the risk because control cost exceeds expected loss
When control cost ($2M) significantly exceeds annualized loss expectancy ($500K), risk acceptance is the economically rational choice.
Which of the following best describes a 'layered defense' or 'defense in depth' strategy?
Answer: Implementing multiple overlapping controls so failure of one does not expose the asset
Defense in depth uses multiple independent controls so that an attacker or failure must defeat several barriers, reducing overall risk exposure.
Under ISO 31000:2018, the term 'risk treatment' encompasses which of the following actions?
Answer: Modifying risk through avoidance, reduction, sharing, or retention
ISO 31000 defines risk treatment as the process of selecting and implementing options to modify risk, including avoidance, reduction, sharing, and retention.
A corrective control is best exemplified by which of the following scenarios?
Answer: A backup restoration process executed after a system failure
Restoring from backup after a failure is a corrective control because it restores normal operations following a risk event.
Which risk mitigation technique is most commonly used to address concentration risk in a loan portfolio?
Answer: Portfolio diversification
Diversifying a loan portfolio across geographies, industries, and borrower types reduces concentration risk by limiting exposure to any single source of loss.