CSET Risk Assessment & Management 4 — Questions and Answers
Question 1: A safety officer conducts a Failure Mode and Effects Analysis (FMEA). What is the primary output of this analysis?
- A list of stakeholders responsible for each risk
- A ranking of failure modes by their Risk Priority Number (RPN) (Correct answer)
- A Monte Carlo probability distribution
- A cost-benefit analysis of mitigation options
Correct answer: A ranking of failure modes by their Risk Priority Number (RPN)
FMEA produces Risk Priority Numbers (RPN) by multiplying severity, occurrence, and detectability ratings to rank failure modes.
Question 2: Which risk management framework, widely used in IT and organizational settings, categorizes controls as preventive, detective, and corrective?
- PMBOK
- COSO ERM
- ISO 31000
- NIST Cybersecurity Framework (Correct answer)
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework organizes security controls into categories including preventive, detective, and corrective control types.
Question 3: A project team identifies a risk and decides to monitor it without taking immediate action because the potential impact is very low. This approach is called:
- Risk exploitation
- Passive risk acceptance (Correct answer)
- Risk transference
- Active risk avoidance
Correct answer: Passive risk acceptance
Passive risk acceptance means acknowledging a risk and choosing not to act unless it materializes, typically because it has low impact.
Question 4: In a risk assessment, a 'threat agent' is best defined as:
- The weakness in a system that can be exploited
- The entity or force that can exploit a vulnerability (Correct answer)
- The potential loss resulting from a risk event
- The safeguard designed to reduce risk
Correct answer: The entity or force that can exploit a vulnerability
A threat agent is the actor—human, natural, or technical—capable of intentionally or unintentionally exploiting a vulnerability.
Question 5: A district technology coordinator uses a decision tree to evaluate two possible responses to a cybersecurity risk. What does a decision tree primarily help with in risk management?
- Identifying all possible risks in a project
- Visually mapping outcomes and expected values of different decisions (Correct answer)
- Assigning accountability for each risk to a team member
- Documenting the history of past risk events
Correct answer: Visually mapping outcomes and expected values of different decisions
A decision tree maps possible choices and their probabilistic outcomes, allowing comparison of expected values to support decision-making.
Question 6: What distinguishes 'secondary risks' from 'residual risks' in project risk management?
- Secondary risks are less important; residual risks are more important
- Secondary risks arise as a direct result of implementing a risk response; residual risks remain after responses are applied (Correct answer)
- Secondary risks are external; residual risks are internal
- Secondary risks occur after project closure; residual risks occur during planning
Correct answer: Secondary risks arise as a direct result of implementing a risk response; residual risks remain after responses are applied
Secondary risks are new risks created by the act of implementing a risk response, while residual risks are those that remain despite mitigation.
Question 7: According to ISO 31000, which step immediately follows 'risk identification' in the risk assessment process?
- Risk treatment
- Risk communication
- Risk analysis (Correct answer)
- Risk monitoring
Correct answer: Risk analysis
ISO 31000 defines risk assessment as comprising risk identification, risk analysis, and risk evaluation in that sequence.
A safety officer conducts a Failure Mode and Effects Analysis (FMEA).
What is the primary output of this analysis?