SDI Risk Assessment & Management 3 — Questions and Answers
Question 1: Which framework is MOST commonly referenced by SDI for aligning risk management with IT service management practices?
- COBIT 2019
- ITIL 4 (Correct answer)
- ISO 31000
- NIST CSF
Correct answer: ITIL 4
ITIL 4 provides guidance on risk management as part of the service value system, making it the primary framework referenced by SDI.
Question 2: A risk that has been accepted by management but continues to be monitored is classified as:
- Closed risk
- Residual risk under watch (Correct answer)
- Transferred risk
- Eliminated risk
Correct answer: Residual risk under watch
When a risk is accepted but still monitored, it becomes a residual risk under watch to ensure conditions do not change.
Question 3: Which stakeholder role is typically assigned ownership of a risk in a service desk risk register?
- The IT auditor
- The person with accountability and authority to manage that risk (Correct answer)
- The junior analyst who identified the risk
- The external regulator
Correct answer: The person with accountability and authority to manage that risk
Risk ownership is assigned to the individual with the authority and accountability to manage or mitigate the specific risk.
Question 4: During a business impact analysis (BIA), what is the key output that directly informs risk prioritization?
- A list of all IT assets
- The criticality and recovery requirements of business services (Correct answer)
- The number of open incidents
- The current SLA compliance rate
Correct answer: The criticality and recovery requirements of business services
A BIA identifies which services are most critical and what recovery objectives they require, directly shaping how risks are prioritized.
Question 5: A service desk implements multi-factor authentication to reduce the risk of unauthorized access. This is an example of:
- Risk avoidance
- Risk transfer
- Risk mitigation (Correct answer)
- Risk acceptance
Correct answer: Risk mitigation
Adding controls such as multi-factor authentication reduces the likelihood or impact of a risk, which is risk mitigation.
Question 6: What does 'risk appetite' refer to in an SDI context?
- The budget allocated for risk management tools
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The number of risks identified in the last quarter
- The speed at which risks are resolved
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines the level and type of risk an organization is prepared to tolerate while pursuing its goals.
Question 7: Which of the following is an example of a proactive approach to risk management in a service desk?
- Reacting to incidents as they occur
- Conducting regular risk reviews before problems emerge (Correct answer)
- Escalating all risks to the CIO immediately
- Ignoring low-likelihood risks entirely
Correct answer: Conducting regular risk reviews before problems emerge
Proactive risk management involves regularly reviewing and identifying risks before they materialise as incidents or problems.
Which framework is MOST commonly referenced by SDI for aligning risk management with IT service management practices?