CS Risk Management & Mitigation 2 — Questions and Answers
Question 1: A company's risk register shows a cyber breach with high likelihood and high impact. Which mitigation action best addresses this scenario?
- Accept the risk and document it
- Transfer risk through cyber liability insurance and implement MFA (Correct answer)
- Avoid the risk by shutting down IT systems
- Share the risk with all employees equally
Correct answer: Transfer risk through cyber liability insurance and implement MFA
Transferring high-likelihood, high-impact risks via insurance while adding controls like MFA reflects a combined mitigation and transfer strategy.
Question 2: In a Monte Carlo simulation for project risk, what does the output distribution primarily represent?
- The single most likely project outcome
- A range of possible outcomes with associated probabilities (Correct answer)
- The worst-case scenario only
- The risk owner's subjective preference
Correct answer: A range of possible outcomes with associated probabilities
Monte Carlo simulations model uncertainty by running thousands of iterations to produce a probability distribution of outcomes.
Question 3: Which risk response strategy is most appropriate when the cost of mitigating a risk exceeds its potential impact?
- Transfer
- Avoid
- Accept (Correct answer)
- Escalate
Correct answer: Accept
Risk acceptance is appropriate when mitigation costs outweigh the financial or strategic impact of the risk materializing.
Question 4: A strategist is evaluating residual risk after controls are applied. Residual risk is best defined as:
- Risk that has been fully eliminated
- Risk remaining after mitigation controls are in place (Correct answer)
- Risk transferred to a third party
- Risk identified but not yet assessed
Correct answer: Risk remaining after mitigation controls are in place
Residual risk is the level of risk that persists after all planned risk responses and controls have been implemented.
Question 5: Which framework is most commonly used for enterprise risk management (ERM) in US organizations?
- ISO 9001
- COSO ERM Framework (Correct answer)
- Six Sigma DMAIC
- Balanced Scorecard
Correct answer: COSO ERM Framework
The COSO ERM Framework is the dominant standard for enterprise risk management, widely adopted by US organizations.
Question 6: A risk appetite statement differs from a risk tolerance statement in that risk appetite:
- Is more specific and quantitative than tolerance
- Defines the broad level of risk an organization is willing to accept strategically (Correct answer)
- Applies only to financial risks
- Is set by regulators, not management
Correct answer: Defines the broad level of risk an organization is willing to accept strategically
Risk appetite reflects the overall strategic disposition toward risk-taking, while tolerance defines acceptable variance around specific risk thresholds.
Question 7: During a strategic planning session, a facilitator uses a pre-mortem technique. What is the primary purpose of this approach?
- Reviewing past project failures for lessons learned
- Imagining a future failure to proactively identify risks before they occur (Correct answer)
- Assigning blame for previous risk events
- Calculating the financial cost of realized risks
Correct answer: Imagining a future failure to proactively identify risks before they occur
A pre-mortem involves prospectively imagining a strategy has failed and then working backward to identify what could have caused it.
A company's risk register shows a cyber breach with high likelihood and high impact.
Which mitigation action best addresses this scenario?