CSET Risk Assessment & Management 5 — Questions and Answers
Question 1: A school principal implements a new sign-in procedure to reduce unauthorized access to campus. This is an example of which type of risk control?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are implemented before an incident to reduce the likelihood or impact of a risk event occurring.
Question 2: In business continuity planning, what is the 'Recovery Time Objective' (RTO)?
- The maximum data loss an organization can tolerate
- The maximum acceptable time to restore a system after disruption (Correct answer)
- The cost to recover from a disaster
- The probability that a disaster will occur within a year
Correct answer: The maximum acceptable time to restore a system after disruption
RTO defines the target time within which a business process or system must be restored after a disruption to avoid unacceptable consequences.
Question 3: Which of the following best describes a 'risk appetite' in organizational risk management?
- The maximum risk an organization can absorb before failure
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total cost of all identified risks in a project
- The minimum acceptable rate of return on a risky investment
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the level and type of risk an organization intentionally accepts while pursuing its strategic goals.
Question 4: A risk assessment reveals that installing a new server room poses a fire risk. Installing a fire suppression system is an example of which risk response?
- Risk avoidance
- Risk acceptance
- Risk transference
- Risk mitigation (Correct answer)
Correct answer: Risk mitigation
Risk mitigation reduces the probability or impact of a risk event by implementing controls, such as fire suppression systems.
Question 5: During risk monitoring, a project team tracks 'risk triggers.' What are risk triggers?
- The financial cost of a risk event
- Warning signs or conditions that indicate a risk is about to occur (Correct answer)
- The stakeholders responsible for managing a specific risk
- The specific actions taken after a risk has occurred
Correct answer: Warning signs or conditions that indicate a risk is about to occur
Risk triggers are observable indicators or conditions that signal a risk event is imminent or has started to materialize.
Question 6: A quantitative risk analysis technique that runs thousands of simulations to model the probability distribution of project outcomes is called:
- PERT analysis
- Sensitivity analysis
- Monte Carlo simulation (Correct answer)
- Delphi technique
Correct answer: Monte Carlo simulation
Monte Carlo simulation iteratively samples input variables across their probability distributions to produce a range of possible outcomes.
Question 7: A CSET candidate reviews a scenario where a district accepts a risk because the cost of mitigation exceeds the potential loss. This decision is best classified as:
- Risk exploitation
- Informed risk acceptance (Correct answer)
- Risk avoidance
- Risk transference
Correct answer: Informed risk acceptance
Informed risk acceptance occurs when decision-makers consciously choose to accept a risk after determining that the cost to mitigate it outweighs the potential loss.
A school principal implements a new sign-in procedure to reduce unauthorized access to campus.
This is an example of which type of risk control?