CRA Risk Mitigation and Controls 3 — Questions and Answers
Question 1: In the context of IT risk, which control layer is responsible for ensuring only authorized users access systems?
- Physical security controls
- Logical access controls (Correct answer)
- Environmental controls
- Operational controls
Correct answer: Logical access controls
Logical access controls (passwords, MFA, role-based access) govern who can authenticate and what resources they can use within IT systems.
Question 2: A risk architect evaluates a control and finds it reduces both the likelihood and impact of a risk. This control strategy is known as:
- Risk avoidance
- Risk transfer
- Risk mitigation (Correct answer)
- Risk acceptance
Correct answer: Risk mitigation
Risk mitigation involves implementing controls that reduce the probability, impact, or both dimensions of a risk event.
Question 3: Which type of control testing involves reviewing documentation and policies without testing actual execution?
- Substantive testing
- Walk-through testing
- Design effectiveness testing (Correct answer)
- Operating effectiveness testing
Correct answer: Design effectiveness testing
Design effectiveness testing evaluates whether a control is properly designed to address a risk, typically through inquiry and inspection of documentation.
Question 4: An organization contracts a third-party vendor to process customer data. Which control is most critical to mitigate third-party risk?
- Internal audit of headquarters only
- Vendor due diligence and contractual SLAs with right-to-audit clauses (Correct answer)
- Eliminating all data sharing with vendors
- Increasing cyber insurance coverage
Correct answer: Vendor due diligence and contractual SLAs with right-to-audit clauses
Vendor due diligence combined with contractual SLAs and right-to-audit provisions ensures third parties meet security and compliance requirements.
Question 5: The four Ts of risk response are: Tolerate, Treat, Transfer, and:
- Track
- Terminate (Correct answer)
- Test
- Transform
Correct answer: Terminate
The four Ts of risk response are Tolerate (accept), Treat (mitigate), Transfer (insure/outsource), and Terminate (avoid by ceasing the activity).
Question 6: Which framework specifically provides guidance on designing and evaluating internal controls over financial reporting?
- ISO 31000
- COSO Internal Control — Integrated Framework (Correct answer)
- NIST SP 800-53
- COBIT 2019
Correct answer: COSO Internal Control — Integrated Framework
The COSO Internal Control — Integrated Framework is the globally recognized standard for designing and evaluating internal controls, especially over financial reporting.
Question 7: A business continuity plan (BCP) is primarily a type of which risk response?
- Risk avoidance
- Risk transfer
- Risk treatment / reduction (Correct answer)
- Risk acceptance
Correct answer: Risk treatment / reduction
A BCP is a risk treatment measure that reduces the impact of disruptions by ensuring the organization can recover and continue critical operations.
In the context of IT risk, which control layer is responsible for ensuring only authorized users access systems?