HR Risk Assessment & Management 3 — Questions and Answers
Question 1: A company decides to purchase cyber-liability insurance for its HR data systems. Which risk response strategy does this represent?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Purchasing insurance shifts the financial consequences of a risk event to the insurer, which is risk transfer.
Question 2: Under the NIST Risk Management Framework (RMF), which step comes IMMEDIATELY after 'Categorize'?
- Implement
- Assess
- Select (Correct answer)
- Authorize
Correct answer: Select
The RMF sequence is Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor.
Question 3: An HR system stores Social Security Numbers. Under NIST FIPS 199, what impact level would a breach of this data MOST likely be classified?
- Low
- Moderate
- High (Correct answer)
- Critical
Correct answer: High
SSNs are personally identifiable information whose unauthorized disclosure can cause severe harm, warranting a High confidentiality impact.
Question 4: A risk owner differs from a risk manager primarily because the risk owner:
- Documents risks in the risk register
- Is accountable for the outcome if the risk materializes (Correct answer)
- Monitors Key Risk Indicators daily
- Designs mitigation controls
Correct answer: Is accountable for the outcome if the risk materializes
The risk owner is the senior person accountable for ensuring the risk is managed and bears responsibility for outcomes.
Question 5: Which type of HR risk assessment evaluates the likelihood that a new hire will engage in workplace misconduct?
- Job-hazard analysis
- Pre-employment background screening risk assessment (Correct answer)
- Business impact analysis
- Threat and vulnerability assessment
Correct answer: Pre-employment background screening risk assessment
Pre-employment background screening assesses red flags that predict potential misconduct or dishonesty.
Question 6: A software company uses role-based access control (RBAC) in its HRIS. What risk does RBAC primarily address?
- The risk of payroll processing errors caused by software bugs
- The risk of employees accessing data beyond their job function (Correct answer)
- The risk of system downtime during peak processing
- The risk of data loss from hardware failure
Correct answer: The risk of employees accessing data beyond their job function
RBAC limits each user to only the data and functions their role requires, reducing unauthorized access risk.
Question 7: During a business continuity plan (BCP) review, the HR team identifies that the HRIS has an RTO of 4 hours. What does this mean?
- The system must be backed up every 4 hours
- The system must be restored and operational within 4 hours of an outage (Correct answer)
- Data loss cannot exceed 4 hours of transactions
- The system can remain offline for up to 4 business days
Correct answer: The system must be restored and operational within 4 hours of an outage
Recovery Time Objective (RTO) is the maximum tolerable downtime before the system must be restored.
A company decides to purchase cyber-liability insurance for its HR data systems.
Which risk response strategy does this represent?