CRA Risk Mitigation Strategies & Controls 2 — Questions and Answers
Question 1: A bank implements a policy requiring dual authorization for all wire transfers above $50,000. Which control type does this represent?
- Corrective control
- Detective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Dual authorization is a preventive control because it stops unauthorized transactions before they occur.
Question 2: Which risk mitigation strategy is most appropriate when the cost of control implementation exceeds the expected loss from the risk?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk reduction
Correct answer: Risk acceptance
Risk acceptance is chosen when mitigation costs outweigh the potential financial impact of the risk.
Question 3: An organization purchases cyber liability insurance to offset potential data breach losses. This is an example of:
- Risk reduction
- Risk transfer (Correct answer)
- Risk avoidance
- Risk elimination
Correct answer: Risk transfer
Insurance shifts the financial burden of a risk event to a third party, making it a risk transfer strategy.
Question 4: Which of the following best describes a compensating control?
- A control that detects risk events after they occur
- An alternative control used when the primary control is not feasible (Correct answer)
- A control that corrects damage after a risk event
- A control that prevents risk events from occurring
Correct answer: An alternative control used when the primary control is not feasible
Compensating controls serve as substitutes when primary controls cannot be implemented due to technical or business constraints.
Question 5: In the NIST Risk Management Framework, which step involves selecting and implementing security controls?
- Categorize
- Select
- Implement (Correct answer)
- Authorize
Correct answer: Implement
The Implement step in NIST RMF focuses on putting chosen security controls into practice within the information system.
Question 6: A company decides to exit a high-risk product line because the inherent risk cannot be economically controlled. This is an example of:
- Risk transfer
- Risk reduction
- Risk acceptance
- Risk avoidance (Correct answer)
Correct answer: Risk avoidance
Risk avoidance involves eliminating the activity that creates the risk exposure entirely.
Question 7: Which metric best measures the effectiveness of risk mitigation controls over time?
- Gross risk exposure
- Key Risk Indicator (KRI) trend analysis (Correct answer)
- Return on equity
- Control design adequacy rating
Correct answer: Key Risk Indicator (KRI) trend analysis
KRI trend analysis tracks changes in risk levels over time, directly reflecting whether mitigation efforts are reducing exposure.
A bank implements a policy requiring dual authorization for all wire transfers above $50,000.
Which control type does this represent?