WorksheetsManajemen Risiko Exam
Total questions: 87
Worksheet time: 44mins
An example of which risk response strategy that integrates risk awareness activities seamlessly into the regular business workflow, making them an inherent part of daily operations?
Mitigation
Acceptance
Transfer
Avoidance
What is the role of vulnerabilities in risk scenario development?
Events that improve enterprise complexity
Events that contribute to risk reduction
Events contributing to impact or frequency of loss events
Positive impact-generating events
What should be periodically reevaluated in Risk Management?
The occurrence of security events
The incidence of operational errors
The acceptance of residual risk
The frequency of audits
What is the primary purpose of KPIs in risk management?
Trigger alerts when certain thresholds are met
Provide early warnings of increased risk
Identify underperforming aspects of an enterprise
Provide late warnings of increased risk
Residual risk pertains to the risk that persists:
After management has implemented a response to new risks
Before any risk response has been applied.
In the current moment despite the application of existing risk responses.
Despite continuous reassessment and modification of risk responses.
What makes infrastructure assets susceptible to risks?
The negative impact on enterprise efficiency
The physical and IT nature, with new and outdated technologies posing risks
The classification as intangible assets
The valuation difficulties
What is the main goal of IT risk management?
Focusing on data exploitation
Avoiding strategic plans
Impeding value
Preserving value
What is the primary focus of scenario analysis in the context of risk management?
Developing detailed risk scenarios
Assessing the impact of different risk scenarios
Identifying vulnerabilities in the IT infrastructure
Classifying assets according to their importance
What is the main focus of independent assurance activities in control monitoring?
Updating internal control systems
Conducting regular risk reporting
Promptly addressing exceptions
Providing independent and objective reviews
What category of control is represented by employing a firewall to obstruct traffic on ports linked to malicious tools?
Preventive
Detective
Corrective
Compensating
Where should an enterprise look to identify situations where documented processes and controls are not being followed?
Observing a process
Enterprise architecture assessments
Capability maturity models
Logs and trouble tickets
What is a vulnerability in the context of enterprise risk?
A. A strategic advantage that protects the system from potential threats
B. A powerful capability that can mitigate enterprise vulnerabilities
C. A weakness in a process that could expose the system to adverse threats
D. A strength in a process that could expose the system to adverse threats
What should scenario scales reflect?
The ability to observe and recognize anything wrong
The focus on worst-case events and less severe incidents
The involvement of all parties in the risk scenario process
The enterprise complexity and exposure
What type of indicators are Key Performance Indicators (KPIs) known as?
Compliance indicators
Lagging indicators
Process indicators
Leading indicators
What is risk most often associated with?
Certainties and expected results
Adverse impact and deviations from expected results
Control and certainty
Consistency and control conditions
What do effective Key Risk Indicators (KRIs) provide in risk management?
A comparison of KPIs and KRIs
A predictive insight into potential risk events
An assessment of control monitoring activities
A retrospective view of risk events
What are the specific metrics used to monitor controls?
Thresholds for control performance
Staff training
Installation procedures
Change management
What is the detectability of risk scenarios related to?
A. Frequency and impact assessment
B. Scenario generation
C. Systemic and contagious risks
D. Visibility and recognition
What defines key performance indicator (KPI) is:
Are used to provide a high-level overview and measure of past performance.
Are qualitative and thus hard to measure over time.
Predict future statuses of controls
Adjusting existing controls
What is the purpose of identifying assumptions and unknown factors in a risk assessment?
To create misunderstandings between IT and management
To document factors impacting the risk assessment
To confuse senior management
To simplify the risk assessment process
What does the business continuity policy contain guidelines for?
Project management and compliance requirements
Human resources (HR) policies and fraud risk policy
Quality management and service policies
Business impact analysis, contingency plans, and recovery requirements
Why is it highly desirable to have a single integrated business continuity plan?
To ensure that resources committed are used ineffectively
To ensure that there is no confidence in surviving a disruption
To ensure that no plan components need coordination
To ensure proper coordination among various plan components and effective resource utilization
Who ensures the involvement of the board in major decisions in an enterprise?
CEO
Executive committee
CFO
COO
Why is it important for enterprises to consider external contextual factors?
To understand factors outside their control
To develop detection and containment capabilities
To focus on user awareness training
To ensure control over incidents
How is risk ranking derived?
By measuring the impact of IT-related problems on business services
By combining all the components of risk, including threats, vulnerabilities, and impact
By considering the likelihood of attack success
By recognizing the threats and characteristics of a threat source
What is the process of risk analysis in the context of I&T-related risks?
Estimating the frequency and magnitude of risk scenarios
Developing scenarios to describe potential risk events and estimate their impact
Determining how often a particular risk scenario might occur during a specified period
Comparing estimated risks against given risk criteria
What is the purpose of defining a risk response?
To eliminate or minimize risk at all costs
To align risk with management's acceptable level of risk based on the risk analysis
To create an exception process for managing risk
To provide guidelines for risk assessment and management
What should be done with regard to documenting assumptions made in scenario grouping or generalization?
Avoid documenting assumptions to reduce complexity
Document conflicting assumptions
Document assumptions clearly
Document vague assumptions
What is the purpose of control tests in risk management?
Implementing new controls
Creating vulnerability assessments
Documenting risk scenarios
Assessing the current state of controls
What type of metric is a lag risk indicator?
Forward-looking metric providing an early warning that risk may soon be realized before an event occurs
Backward-looking metric indicating risk has been realized after an event has occurred
In place to prevent events from occurring
Measures upper and lower limits to help an enterprise understand when a condition requires attention before the risk is realized
What is a cost-effective way to mitigate enterprise risk by educating staff?
Creating complex incident response plans
Awareness education and training
Hiring external consultants
Implementing new controls
What is the purpose of strategic planning in relation to risk consideration?
To anticipate and mitigate risks
To only react to risks
To identify risks after they occur
To ignore risks and react when they occur
What is the purpose of risk aggregation at an enterprise level?
To aggregate risk primarily at a departmental level
To obtain a comprehensive view of overall risk
To obscure actionable details while aggregating
To focus on easily measurable but less relevant risk
What do effective KRIs provide?
A. Historical context, feedback on risk appetite, early warning signals
B. Detailed projections and ad-hoc feedback on risks
C. Late warning signals and lack of historical context
D. Inaccurate data collection and undefined measurement objectives
What is an example of a KRI trigger?
Patching all critical patches within 30 days
The development of effective risk management practices
The risk of unpatched systems leading to data breaches
Continuous monitoring process in the enterprise
What is the primary focus of the Chief Digital Officer (CDO) in an organization?
A. Digital initiatives
B. Data management
C. IT governance
D. Risk management
What do the Responsible (R), Accountable (A), Consulted (C), and Informed (I) components define in the RACI model?
A. Roles and responsibilities
B. Risk data collection
C. Risk culture
D. Risk governance
What is the role of scenario generation in risk management?
To assess the detectability of risk scenarios
To develop a generic risk structure for reporting
To gain organizational buy-in for risk scenarios
To identify risks and put in place countermeasures
Which statement accurately describes threat actors?
Every threat is associated with a threat actor.
Threat actors are limited to humans.
Threat actors encompass competitors as well.
Threat actors encompass a variety of potential sources beyond just humans.
What is the basis for developing risk scenarios using the bottom-up approach?
I&T- and non-I&T-related events
Assets, systems, or applications important to the enterprise
Mission strategy and business objectives
Understanding business goals and impact criteria
Which statement about controls is true?
Controls can only be categorized as technical in a control matrix
Controls are essential for risk mitigation and include both proactive and reactive measures
Controls prevent, detect, and correct damage resulting from an incident but do not enable recovery
Controls are not essential for risk mitigation
What is the purpose of awareness training for senior management?
To transfer or share risk with another enterprise
To understand liability, compliance, due care, due diligence, and create a risk management culture
To reduce the impact of risk
To avoid risk altogether
How should I&T-related risk be connected to business objectives in an enterprise?
By aligning with enterprise risk management when possible
By impeding the business or mission objectives
By avoiding any alignment with enterprise risk management
By promoting ethical and open communication
What are the three aspects that information assets should be protected against?
Confidentiality, integrity, and availability
Destruction, disclosure, and loss
Unauthorized access, improper modification, and destruction
Disclosure, modification, and non-accessibility
Which of the following is considered an actor in the context of I&T-related risk scenario development?
Any person, thing, or entity that acts or carries out a threat
Only external entities that act maliciously
Only nature and external requirements
Only internal entities that act accidentally
What is the primary purpose of a risk register?
To track and manage identified risks
To communicate risk assessment results to senior management
To identify and analyze risks
To create a comprehensive risk assessment report
What does Risk assessment evaluate?
The effectiveness of IT operations
The business objectives and risks
The current state of controls
The performance of external entities
What are the benefits of using appropriate KRIs?
Early warning signals, historical context, and feedback on risk appetite
Immediate response signals, ad-hoc data collection, and lack of logical relationship with specific risks
Late feedback signals, real-time data collection, and undefined measurement objectives
Delayed response signals, future projections, and historical context
Why is it important for IT and the rest of the business to establish a mutual understanding of identifying the risk that needs to be managed?
To guarantee impartiality and consistency throughout the enterprise
To detect critical risk scenarios at a high level
To understand how adverse events may affect business or mission objectives
To identify potential high-risk areas
What determines the suitability of risk analysis approaches?
Potential consequences of a given risk scenario
Culture, resources, skills, environment, and risk appetite
Frequency and magnitude of a given risk scenario
Criticality and sensitivity of IT assets
When is a quantitative risk analysis approach most likely to be selected?
Financial constraints limit analysis resources
A cost-benefit analysis is necessary.
Quantifying reputation and employee morale is the aim.
Regulatory compliance requires numerical assessments.
Why is it beneficial to present risk in a two-dimensional diagram?
To indicate very low risk offering opportunities to save costs
To identify trends or common profiles for more efficient risk response activities
To express evaluated risk using well-defined and unambiguous impact criteria
To compare different risk assessment methods over time
What does the whistle-blower policy encourage employees to do?
Raise concerns and report suspicious activity
Adhere to quality improvement initiatives
Participate in risk scoping activities
Engage in ethical communication
What does an enterprise need to determine using consistent methods?
The dependencies of other systems on the affected IT system
The level of risk associated with a threat
Results that can be compared over time
As much significant risks as possible
Which method calculates the expected loss from a single event or threat occurrence?
Annual Loss Expectancy (ALE)
Single Loss Expectancy (SLE)
Value at Risk (VaR)
Earnings at Risk (EaR)
What does establishing risk criteria in an enterprise involve?
A. Evaluation of risk appetite, risk tolerance, and risk capacity
B. Determination of resource optimization
C. Promotion of ethical communication
D. Consistency in risk assessment methods
What do threat events refer to in the context of risk scenario development?
Events that contribute to reducing impact frequency
Positive impact-generating events within the enterprise
Circumstances or events brought about by a threat actor that can trigger loss events
Circumstances or events brought about by nature or external requirements
What is the primary focus of the information security policy in an enterprise?
Monitoring and predicting the state of risk management
Defines the boundaries within which risk management activities operate
Behavioral guidelines in protecting corporate information and associated systems
Sets guidelines on how to act in crisis situations and details the sequence for dealing with risk areas
What can inadequate communication of risk response actions lead to?
Enhanced risk response
Improved strategic planning
False sense of confidence
Increased stakeholder communication
What should be considered when aggregating risk according to the guidelines?
Obscure actionable details while aggregating
Aggregate risk in a single dimension only
Aggregate like data consistently and meaningfully
Aggregate risk primarily at the departmental level
What is the main purpose of vulnerability scans?
To identify vulnerabilities proactively
To monitor controls
To conduct self-assessment
To implement new controls
What is the role of risk scenarios in risk identification and assessment?
To determine the business impact of a breach or loss of an asset
To analyze financial assets and their potential risks
To facilitate communication and understanding of potential risks
To conduct interviews with potential pitfalls
What is the purpose of developing enterprise-specific impact criteria in risk management?
To set risk appetites, provide meaning to risk, and reflect areas relevant to business objectives
To create false assurance and inconsistency
To estimate the frequency and magnitude of a given risk scenario
To identify risks on a system-by-system basis
What is the relationship between risk and control?
The relationship between risk and control is indirect
Controls have no impact on managing and mitigating risk
There is a direct relationship
There is no relationship between risk and control
What is the primary focus of risk management?
Risk detection and response
Resource alignment
Regulatory compliance
Decision-making
How is the dynamic nature of risk addressed in the effective management of I&T-related risk?
By avoiding any preparation for changes in the industry at large
By ignoring changes in laws and regulations
By minimizing assessment of key processes and associated risks
By giving advance consideration to changes in the enterprise and applicable laws and regulations
What do KRIs facilitate across the enterprise?
Complex discussions on risk and unchanged risk awareness
Limited communication on risk and decreased business objectives alignment
Clear and measurable discussions on risk and improved risk awareness
Vague discussions on risk and decreased risk awareness
What is the purpose of Root Cause Analysis?
To establish the origins of events and prevent problem recurrence
To ignore events and their consequences
To identify risks before they occur
To analyze completed projects
What is the role of the third line in the three lines of defense in IT risk management?
Conducting formal inspections and verifications
Offering independent testing and assurance
Monitoring controls
Managing risk
What are preventive, detective, corrective, and compensating examples of in risk management?
Control types
Threats
Vulnerabilities
Risk states
Why is asset valuation important for risk management?
To assess the financial value of assets
To understand the business impact of a breach or loss of an asset
To evaluate the impact of assets on business reputation
To identify potential threats and vulnerabilities
What does KPI stand for?
Key Performance Indicator
Key Promise Indicator
Key People Indicator
Key Privacy Indicator
Which method estimates the probability of losses based on statistical analysis of historical price trends and volatilities?
Single Loss Expectancy (SLE)
Value at Risk (VaR)
Annual Loss Expectancy (ALE)
Earnings at Risk (EaR)
How does effective enterprise governance of I&T-related risk align with overall enterprise risk management?
By treating I&T-related risk as a separate type of risk
By ignoring business or mission objectives
By clearly defining risk appetite and risk tolerance
By limiting the consequences of I&T-related risk
What is the purpose of risk monitoring and evaluation?
To provide reports that are systematic and timely
To collect and validate business, IT, and process goals and metrics
To prevent acceptance of risk that exceeds the risk acceptance criteria set by the business
To monitor processes to ensure they are performed in line with established performance metrics
What is a key requirement for effective risk monitoring and evaluation?
Setting flexible risk acceptance criteria
Gathering data from various sources in a timely and accurate manner
Creating comprehensive reports on IT performance
Aligning IT-related risk with business risk
Risk monitoring focuses is:
Measuring and assessing inherent risk.
Selecting metrics that exceed risk tolerance.
Observing and assessing potential risk events.
Accepting risk cant be avoided
What is crucial for effective risk management in an enterprise?
Implementing risk governance controls
Avoiding enterprise dependencies
Focusing on natural disasters
Balancing costs and benefits
What type of indicators are Key Performance Indicators (KPIs) known as?
Lagging indicators
Process indicators
Compliance indicators
Leading indicators
What influences an enterprise's risk appetite?
Resource optimization
Assessor bias mitigation
Dynamic nature of risk
Nature of the business
What should the risk assessment report and risk register document?
Assessed level or priority of each risk
Budget allocation for implementing risk responses
General business objectives
Employee feedback on risk identification
Who is primarily responsible for the overall governance in most enterprises?
Special enterprise structures
The chairperson
The stakeholders
The board of directors
What is the purpose of a risk map?
To present risk in a two-dimensional diagram based on frequency and impact
To identify trends or common profiles for more efficient risk response activities
To measure the impact of IT-related problems on business services
To compare risk over time using consistent methods
Control monitoring is to:
Determine whether controls are cost efficient
Determine whether controls are functioning as designed.
Verify whether controls are effectively addressing risk.
Determine the type of controls needed to address risk.
What information forms the basis for identifying and analyzing risk using the top-down approach?
Mission strategy and business objectives
Hypothetical situations envisioned by the people performing job functions
Assets, systems, or applications important to the enterprise
Threats or generic loss scenarios
What does detectability of risk scenarios include?
The involvement of all parties in the risk scenario process
The visibility and recognition of anything wrong
The focus on worst-case events and less severe incidents
The development of relevant and manageable risk scenarios
What is the purpose of asset classification in IT?
To determine the sensitivity and criticality of IT assets
To evaluate the impact of IT assets on business reputation
To identify potential threats and vulnerabilities
To assess the financial value of IT assets
