CRP Risk Assessment & Business Impact Analysis 3 — Questions and Answers
Question 1: Which qualitative risk analysis technique uses a predefined scale (e.g., Low/Medium/High) to rate both likelihood and impact?
- Monte Carlo simulation
- Fault tree analysis
- Risk matrix (heat map) (Correct answer)
- Decision tree analysis
Correct answer: Risk matrix (heat map)
A risk matrix plots likelihood against impact using categorical scales to produce a visual risk heat map.
Question 2: What distinguishes a 'threat' from a 'vulnerability' in the context of risk assessment?
- A threat is internal; a vulnerability is external
- A threat is the potential cause of harm; a vulnerability is a weakness that can be exploited (Correct answer)
- A threat has a known probability; a vulnerability does not
- A threat is quantifiable; a vulnerability is always qualitative
Correct answer: A threat is the potential cause of harm; a vulnerability is a weakness that can be exploited
Threats are potential harmful events or actors, while vulnerabilities are weaknesses in assets or controls that threats can exploit.
Question 3: During a BIA, which of the following is considered a non-financial impact category?
- Lost revenue during downtime
- Cost to activate an alternate site
- Reputational damage and customer confidence erosion (Correct answer)
- Regulatory fine for missed reporting deadline
Correct answer: Reputational damage and customer confidence erosion
Reputational damage is a non-financial (intangible) impact that must be captured alongside quantifiable financial losses.
Question 4: Which risk assessment method uses expert elicitation and Delphi techniques to reach consensus on risk ratings?
- Quantitative risk analysis
- Qualitative risk analysis (Correct answer)
- Bow-tie analysis
- Failure Mode and Effects Analysis (FMEA)
Correct answer: Qualitative risk analysis
Qualitative risk analysis relies on expert judgment and structured techniques like Delphi to assign categorical ratings when hard data is unavailable.
Question 5: An organization's critical process has an RPO of 4 hours. Which backup strategy BEST meets this requirement?
- Weekly full backups only
- Daily incremental backups with a 24-hour rotation
- Continuous data replication with near-real-time synchronization (Correct answer)
- Monthly snapshots stored offsite
Correct answer: Continuous data replication with near-real-time synchronization
Continuous replication minimizes data loss to seconds or minutes, easily satisfying a 4-hour RPO.
Question 6: Which BIA component identifies the minimum staffing level and resources needed to resume a critical function?
- Minimum Business Continuity Objective (MBCO) (Correct answer)
- Recovery Time Objective
- Maximum Tolerable Downtime
- Recovery Point Objective
Correct answer: Minimum Business Continuity Objective (MBCO)
MBCO specifies the minimum level of service that must be maintained or restored to satisfy business obligations during a disruption.
Question 7: A risk that has been identified, evaluated, and deliberately left in place without additional controls is said to be:
- Mitigated risk
- Residual risk
- Accepted risk (Correct answer)
- Transferred risk
Correct answer: Accepted risk
Accepted risk is a documented decision to retain a risk because the cost of treatment exceeds the expected impact.
Which qualitative risk analysis technique uses a predefined scale (e.g., Low/Medium/High) to rate both likelihood and impact?