SDI Risk Assessment & Management 2 — Questions and Answers
Question 1: Which risk treatment option involves sharing the financial impact of a risk with a third party?
- Risk avoidance
- Risk transfer (Correct answer)
- Risk acceptance
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to another party, such as through insurance or outsourcing.
Question 2: A service desk manager notices that a critical vendor is the sole supplier of a key software component. What type of risk does this represent?
- Operational risk
- Single point of failure risk (Correct answer)
- Compliance risk
- Financial risk
Correct answer: Single point of failure risk
Reliance on a single vendor for a critical component creates a single point of failure risk, threatening service continuity.
Question 3: In the context of SDI risk management, what is the PRIMARY purpose of a risk register?
- To document insurance policies
- To record, track, and manage identified risks in a structured format (Correct answer)
- To assign blame when incidents occur
- To store audit logs for compliance
Correct answer: To record, track, and manage identified risks in a structured format
A risk register is a central document used to record identified risks, their assessments, owners, and treatment plans.
Question 4: When calculating a risk score using likelihood and impact, a risk with a likelihood of 3 and an impact of 4 on a 1-5 scale would score:
- 7
- 12 (Correct answer)
- 1.33
- 34
Correct answer: 12
Risk scores are typically calculated by multiplying likelihood by impact, so 3 × 4 = 12.
Question 5: Which of the following best describes 'inherent risk' in a service desk environment?
- Risk remaining after all controls are applied
- Risk that exists before any controls or mitigations are in place (Correct answer)
- Risk introduced by implementing new controls
- Risk transferred to a third-party vendor
Correct answer: Risk that exists before any controls or mitigations are in place
Inherent risk is the level of risk that exists in the absence of any control measures or mitigations.
Question 6: A service desk team identifies that staff turnover could impact service quality. Which risk category does this BEST fit?
- Technology risk
- People risk (Correct answer)
- Legal risk
- Environmental risk
Correct answer: People risk
Risks related to staffing, skills, and human factors fall under the people risk category.
Question 7: What is the recommended first step when a new risk is identified during a service desk risk review?
- Immediately escalate to senior management
- Document and assess the risk before determining treatment (Correct answer)
- Transfer the risk to the vendor
- Close the risk as accepted without further action
Correct answer: Document and assess the risk before determining treatment
The first step is to document and assess the risk to understand its likelihood, impact, and priority before deciding on treatment.
Which risk treatment option involves sharing the financial impact of a risk with a third party?