GRC Risk Management & Mitigation Strategies 2 — Questions and Answers
Question 1: Which risk response strategy involves shifting the financial impact of a risk to a third party?
- Avoidance
- Acceptance
- Transfer (Correct answer)
- Mitigation
Correct answer: Transfer
Risk transfer moves the financial burden to another party, such as purchasing insurance or outsourcing a risky function.
Question 2: A company decides not to enter a new market because the associated risks exceed its risk appetite. This is an example of which strategy?
- Risk mitigation
- Risk avoidance (Correct answer)
- Risk acceptance
- Risk transfer
Correct answer: Risk avoidance
Risk avoidance involves eliminating the risk entirely by choosing not to engage in the activity that creates it.
Question 3: In quantitative risk analysis, what does Annualized Loss Expectancy (ALE) represent?
- Maximum possible loss from a single event
- Expected monetary loss per year for a given risk (Correct answer)
- Cost of implementing a control
- Total asset value at risk
Correct answer: Expected monetary loss per year for a given risk
ALE is calculated as Single Loss Expectancy (SLE) multiplied by the Annualized Rate of Occurrence (ARO).
Question 4: Which type of risk control is designed to detect and record security incidents after they occur?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Deterrent control
Correct answer: Detective control
Detective controls identify and log incidents that have already happened, such as intrusion detection systems and audit logs.
Question 5: A risk register is primarily used to:
- Automate risk responses
- Document, track, and monitor identified risks (Correct answer)
- Calculate insurance premiums
- Assign liability to third parties
Correct answer: Document, track, and monitor identified risks
A risk register is a centralized document that records risk details, owners, likelihood, impact, and mitigation actions for ongoing tracking.
Question 6: What is the primary purpose of a Business Impact Analysis (BIA)?
- Identify regulatory penalties
- Determine the financial and operational impact of disruptions to critical functions (Correct answer)
- Rank vendors by risk score
- Calculate the cost of security controls
Correct answer: Determine the financial and operational impact of disruptions to critical functions
A BIA identifies critical business processes and quantifies the potential impact of their disruption to prioritize recovery efforts.
Question 7: Which term describes the risk that remains after all controls and mitigation strategies have been applied?
- Inherent risk
- Residual risk (Correct answer)
- Secondary risk
- Control risk
Correct answer: Residual risk
Residual risk is the level of risk that persists even after risk responses and controls have been implemented.
Which risk response strategy involves shifting the financial impact of a risk to a third party?