← All CRA Flashcard Decks

Risk Mitigation Strategies & Controls Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Mitigation Strategies & Controls flashcards as text
  1. A risk architect is reviewing a vendor contract that includes an indemnification clause requiring the vendor to cover losses from their service failures. This is an example of:

    Answer: Contractual risk transfer

    An indemnification clause contractually shifts financial liability for the vendor's failures to the vendor, constituting a risk transfer mechanism.

  2. Which of the following represents a key weakness in relying solely on insurance as a risk mitigation strategy?

    Answer: Insurance does not cover all types of losses and may not compensate for reputational damage

    Insurance can offset direct financial losses but cannot fully compensate for reputational harm, regulatory penalties, or operational disruptions from risk events.

  3. When applying a risk mitigation hierarchy, which approach should typically be considered first before other response strategies?

    Answer: Risk elimination (avoidance)

    Risk elimination — removing the source of the risk entirely — is the most effective response and should be evaluated before less complete strategies.

  4. A control testing program finds that 30% of sampled transactions lack required manager approvals. This finding represents:

    Answer: A control operating effectiveness deficiency

    When a control is properly designed but not consistently followed in practice, the issue is an operating effectiveness deficiency rather than a design flaw.

  5. In enterprise risk management, what is the primary purpose of a Key Risk Indicator (KRI)?

    Answer: To provide early warning signals that a risk is increasing toward an unacceptable level

    KRIs are forward-looking metrics that signal when risk levels are trending toward or exceeding established thresholds, enabling proactive management.

  6. Which scenario best illustrates the concept of 'risk appetite' influencing mitigation strategy selection?

    Answer: An aggressive fintech accepting higher cyber risk than peers to accelerate product launches

    An aggressive fintech consciously accepting higher-than-average cyber risk reflects a high risk appetite driving strategic decisions about which risks to accept versus mitigate.

  7. A risk architect recommends that third-party vendors undergo annual security assessments as part of the enterprise risk program. This is primarily designed to address which risk category?

    Answer: Third-party and supply chain risk

    Annual vendor security assessments are a key control for third-party risk, ensuring that vendors' security postures do not introduce unacceptable risk to the enterprise.

Risk Mitigation Strategies & Controls Flashcards — CRA Study Cards with Answers