CSET Risk Assessment & Management 2 — Questions and Answers
Question 1: A school district identifies that a new software system could fail during high-stakes testing. Which risk response strategy involves purchasing cybersecurity insurance to cover potential losses?
- Risk avoidance
- Risk transfer (Correct answer)
- Risk mitigation
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as an insurance provider.
Question 2: During a quantitative risk analysis, a project manager calculates Expected Monetary Value (EMV). If an event has a 30% probability of occurring and would cost $50,000, what is its EMV?
- $50,000
- $15,000 (Correct answer)
- $35,000
- $150,000
Correct answer: $15,000
EMV is calculated by multiplying the probability (0.30) by the impact ($50,000), yielding $15,000.
Question 3: Which risk analysis technique uses optimistic, pessimistic, and most likely estimates to model uncertainty in project timelines?
- Monte Carlo simulation
- PERT analysis (Correct answer)
- Fault tree analysis
- Delphi technique
Correct answer: PERT analysis
PERT (Program Evaluation and Review Technique) uses three-point estimates to calculate expected durations under uncertainty.
Question 4: A risk register entry shows a risk with HIGH likelihood and LOW impact. How should this risk be prioritized compared to a risk with LOW likelihood and HIGH impact?
- Always prioritize the high-likelihood risk
- Always prioritize the high-impact risk
- Prioritization depends on the calculated risk score for each (Correct answer)
- Both should receive equal priority
Correct answer: Prioritization depends on the calculated risk score for each
Risk prioritization is based on the overall risk score (likelihood × impact), not on either factor alone.
Question 5: In the context of information security risk management, what does the term 'vulnerability' refer to?
- The potential damage caused by a threat
- A weakness that can be exploited by a threat (Correct answer)
- The likelihood that a threat will occur
- A safeguard implemented to reduce risk
Correct answer: A weakness that can be exploited by a threat
A vulnerability is a weakness or gap in a system's defenses that a threat can exploit to cause harm.
Question 6: A project team decides to eliminate a high-risk activity from the project scope entirely. Which risk response strategy are they using?
- Risk mitigation
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk exploitation
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by removing the activity or changing the plan so the risk cannot occur.
Question 7: Which component of a comprehensive risk management plan describes the roles and responsibilities of team members in identifying and managing risks?
- Risk register
- Risk breakdown structure
- Risk response plan
- Risk management roles matrix (Correct answer)
Correct answer: Risk management roles matrix
A risk management roles matrix (or RACI chart) clarifies who is responsible, accountable, consulted, and informed for each risk management activity.
A school district identifies that a new software system could fail during high-stakes testing.
Which risk response strategy involves purchasing cybersecurity insurance to cover potential losses?