Risk Assessment & Mitigation Flashcards
7 cards from real RIMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
Which of the following events would MOST likely trigger a formal risk reassessment of an existing risk register?
Answer: A significant merger or acquisition announcement
Material organizational changes such as mergers or acquisitions fundamentally alter the risk profile, triggering a formal reassessment to capture new, changed, or eliminated risks.
In fault tree analysis (FTA), the 'top event' represents:
Answer: The undesired outcome being analyzed by tracing contributing causes downward
FTA starts with a specific undesired top event (e.g., system failure) and works backward through logic gates to identify all potential contributing causes.
A risk manager recommends redesigning a manufacturing process to eliminate employee exposure to a toxic chemical entirely. This strategy is BEST classified as:
Answer: Risk avoidance
Eliminating the hazard entirely by redesigning the process so the toxic chemical is no longer used constitutes risk avoidance — the activity creating the risk no longer exists.
Which metric is used in quantitative risk analysis to express the annualized financial exposure from a specific risk?
Answer: Annualized Loss Expectancy (ALE)
Annualized Loss Expectancy (ALE) = Single Loss Expectancy × Annual Rate of Occurrence, providing the expected annual financial impact of a specific risk.
A company buys a put option to hedge against a decline in commodity prices. In risk management terms, this is an example of:
Answer: Risk transfer using a financial instrument
Using derivatives like put options to shift the financial consequences of an adverse price movement to a counterparty is a form of financial risk transfer.
What distinguishes 'secondary risks' from 'residual risks' in risk management?
Answer: Secondary risks arise as a direct result of implementing a risk response; residual risks remain after treatment
Secondary risks are new risks introduced by the mitigation action itself, while residual risks are what remain of the original risk after controls are applied.
In the COSO ERM framework, 'risk response' options include all of the following EXCEPT:
Answer: Eliminate
COSO ERM identifies four risk responses: accept, avoid, reduce, and share (transfer) — 'eliminate' is not a listed category because risk can rarely be completely eliminated.