SPHR HR Risk Management 5 — Questions and Answers
Question 1: An organization experiences a ransomware attack that encrypts all HR records. From a risk management perspective, this event most directly represents which type of risk materializing?
- Strategic risk due to competitive intelligence loss
- Operational risk from a cybersecurity control failure (Correct answer)
- Financial risk due to insurance premium increases
- Reputational risk from negative press coverage
Correct answer: Operational risk from a cybersecurity control failure
A ransomware attack exploiting inadequate cybersecurity controls is a textbook operational risk event, where an internal process or system failure causes disruption.
Question 2: The FMLA's 'key employee' exception allows an employer to deny restoration to which category of employee?
- Any employee who has been on leave for more than 10 weeks
- A salaried employee among the highest-paid 10% whose restoration would cause substantial and grievous economic injury (Correct answer)
- Any manager-level employee absent during a critical business period
- Employees who did not provide adequate medical certification
Correct answer: A salaried employee among the highest-paid 10% whose restoration would cause substantial and grievous economic injury
FMLA permits employers to deny reinstatement to 'key employees' — salaried employees in the top 10% of earners — if restoration would cause substantial and grievous economic injury to the employer.
Question 3: A company is assessing the risk of a hostile work environment claim. Which factor most significantly increases legal exposure?
- The company has no formal diversity training program
- Management was aware of the harassing conduct and failed to take prompt corrective action (Correct answer)
- The harassing employee is a peer rather than a supervisor
- The complainant did not use the formal internal grievance procedure
Correct answer: Management was aware of the harassing conduct and failed to take prompt corrective action
Employer liability for hostile work environment is greatly increased when management knew or should have known about the conduct and failed to act promptly.
Question 4: Which scenario best illustrates the risk management concept of 'risk transfer' in HR?
- Requiring all employees to complete annual safety training
- Purchasing employment practices liability (EPL) insurance to shift the financial burden of claims to an insurer (Correct answer)
- Conducting a thorough pre-employment background check process
- Establishing a joint health and safety committee with employee representation
Correct answer: Purchasing employment practices liability (EPL) insurance to shift the financial burden of claims to an insurer
Purchasing EPL insurance transfers the financial consequences of employment-related claims from the organization to the insurer.
Question 5: When evaluating third-party background check vendors, an employer must ensure the vendor complies with which federal law to minimize legal risk?
- The Privacy Act of 1974
- The Fair Credit Reporting Act (FCRA) (Correct answer)
- The Gramm-Leach-Bliley Act
- The Computer Fraud and Abuse Act
Correct answer: The Fair Credit Reporting Act (FCRA)
The FCRA governs consumer reports used for employment purposes, requiring specific disclosures, candidate consent, and adverse action procedures from both the employer and the vendor.
Question 6: An HR leader is presenting to the board about talent risk. Which data point most effectively communicates flight risk among high performers?
- Gross voluntary turnover rate for all employees
- Regrettable attrition rate segmented by performance tier and tenure (Correct answer)
- Total cost of turnover as a percentage of revenue
- Average tenure across the entire organization
Correct answer: Regrettable attrition rate segmented by performance tier and tenure
Regrettable attrition segmented by performance and tenure isolates the loss of critical talent and provides a focused, actionable view of flight risk for the board.
Question 7: A pharmaceutical company's HR team is developing controls for the risk of employees in sensitive roles leaking proprietary research. Which layered control set is most comprehensive?
- Non-disclosure agreements only, combined with exit interviews
- NDAs, role-based access controls on data systems, security awareness training, and post-employment garden leave provisions (Correct answer)
- Background checks at hire and annual performance reviews
- Mandatory drug testing and open-office seating policies
Correct answer: NDAs, role-based access controls on data systems, security awareness training, and post-employment garden leave provisions
A layered approach combining legal agreements, technical access controls, behavioral training, and garden leave addresses the risk from multiple dimensions throughout the employment lifecycle.
An organization experiences a ransomware attack that encrypts all HR records.
From a risk management perspective, this event most directly represents which type of risk materializing?