wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Manajemen Risiko Exam

Total questions: 87

Worksheet time: 44mins

Name
Class
Date
1.

An example of which risk response strategy that integrates risk awareness activities seamlessly into the regular business workflow, making them an inherent part of daily operations?

a)

Mitigation

b)

Acceptance

c)

Transfer

d)

Avoidance

2.

What is the role of vulnerabilities in risk scenario development?

a)

Events that improve enterprise complexity

b)

Events that contribute to risk reduction

c)

Events contributing to impact or frequency of loss events

d)

Positive impact-generating events

3.

What should be periodically reevaluated in Risk Management?

a)

The occurrence of security events

b)

The incidence of operational errors

c)

The acceptance of residual risk

d)

The frequency of audits

4.

What is the primary purpose of KPIs in risk management?

a)

Trigger alerts when certain thresholds are met

b)

Provide early warnings of increased risk

c)

Identify underperforming aspects of an enterprise

d)

Provide late warnings of increased risk

5.

Residual risk pertains to the risk that persists:

a)

After management has implemented a response to new risks

b)

Before any risk response has been applied.

c)

In the current moment despite the application of existing risk responses.

d)

Despite continuous reassessment and modification of risk responses.

6.

What makes infrastructure assets susceptible to risks?

a)

The negative impact on enterprise efficiency

b)

The physical and IT nature, with new and outdated technologies posing risks

c)

The classification as intangible assets

d)

The valuation difficulties

7.

What is the main goal of IT risk management?

a)

Focusing on data exploitation

b)

Avoiding strategic plans

c)

Impeding value

d)

Preserving value

8.

What is the primary focus of scenario analysis in the context of risk management?

a)

Developing detailed risk scenarios

b)

Assessing the impact of different risk scenarios

c)

Identifying vulnerabilities in the IT infrastructure

d)

Classifying assets according to their importance

9.

What is the main focus of independent assurance activities in control monitoring?

a)

Updating internal control systems

b)

Conducting regular risk reporting

c)

Promptly addressing exceptions

d)

Providing independent and objective reviews

10.

What category of control is represented by employing a firewall to obstruct traffic on ports linked to malicious tools?

a)

Preventive

b)

Detective

c)

Corrective

d)

Compensating

11.

Where should an enterprise look to identify situations where documented processes and controls are not being followed?

a)

Observing a process

b)

Enterprise architecture assessments

c)

Capability maturity models

d)

Logs and trouble tickets

12.

What is a vulnerability in the context of enterprise risk?

a)

A. A strategic advantage that protects the system from potential threats

b)

B. A powerful capability that can mitigate enterprise vulnerabilities

c)

C. A weakness in a process that could expose the system to adverse threats

d)

D. A strength in a process that could expose the system to adverse threats

13.

What should scenario scales reflect?

a)

The ability to observe and recognize anything wrong

b)

The focus on worst-case events and less severe incidents

c)

The involvement of all parties in the risk scenario process

d)

The enterprise complexity and exposure

14.

What type of indicators are Key Performance Indicators (KPIs) known as?

a)

Compliance indicators

b)

Lagging indicators

c)

Process indicators

d)

Leading indicators

15.

What is risk most often associated with?

a)

Certainties and expected results

b)

Adverse impact and deviations from expected results

c)

Control and certainty

d)

Consistency and control conditions

16.

What do effective Key Risk Indicators (KRIs) provide in risk management?

a)

A comparison of KPIs and KRIs

b)

A predictive insight into potential risk events

c)

An assessment of control monitoring activities

d)

A retrospective view of risk events

17.

What are the specific metrics used to monitor controls?

a)

Thresholds for control performance

b)

Staff training

c)

Installation procedures

d)

Change management

18.

What is the detectability of risk scenarios related to?

a)

A. Frequency and impact assessment

b)

B. Scenario generation

c)

C. Systemic and contagious risks

d)

D. Visibility and recognition

19.

What defines key performance indicator (KPI) is:

a)

Are used to provide a high-level overview and measure of past performance.

b)

Are qualitative and thus hard to measure over time.

c)

Predict future statuses of controls

d)

Adjusting existing controls

20.

What is the purpose of identifying assumptions and unknown factors in a risk assessment?

a)

To create misunderstandings between IT and management

b)

To document factors impacting the risk assessment

c)

To confuse senior management

d)

To simplify the risk assessment process

21.

What does the business continuity policy contain guidelines for?

a)

Project management and compliance requirements

b)

Human resources (HR) policies and fraud risk policy

c)

Quality management and service policies

d)

Business impact analysis, contingency plans, and recovery requirements

22.

Why is it highly desirable to have a single integrated business continuity plan?

a)

To ensure that resources committed are used ineffectively

b)

To ensure that there is no confidence in surviving a disruption

c)

To ensure that no plan components need coordination

d)

To ensure proper coordination among various plan components and effective resource utilization

23.

Who ensures the involvement of the board in major decisions in an enterprise?

a)

CEO

b)

Executive committee

c)

CFO

d)

COO

24.

Why is it important for enterprises to consider external contextual factors?

a)

To understand factors outside their control

b)

To develop detection and containment capabilities

c)

To focus on user awareness training

d)

To ensure control over incidents

25.

How is risk ranking derived?

a)

By measuring the impact of IT-related problems on business services

b)

By combining all the components of risk, including threats, vulnerabilities, and impact

c)

By considering the likelihood of attack success

d)

By recognizing the threats and characteristics of a threat source

26.

What is the process of risk analysis in the context of I&T-related risks?

a)

Estimating the frequency and magnitude of risk scenarios

b)

Developing scenarios to describe potential risk events and estimate their impact

c)

Determining how often a particular risk scenario might occur during a specified period

d)

Comparing estimated risks against given risk criteria

27.

What is the purpose of defining a risk response?

a)

To eliminate or minimize risk at all costs

b)

To align risk with management's acceptable level of risk based on the risk analysis

c)

To create an exception process for managing risk

d)

To provide guidelines for risk assessment and management

28.

What should be done with regard to documenting assumptions made in scenario grouping or generalization?

a)

Avoid documenting assumptions to reduce complexity

b)

Document conflicting assumptions

c)

Document assumptions clearly

d)

Document vague assumptions

29.

What is the purpose of control tests in risk management?

a)

Implementing new controls

b)

Creating vulnerability assessments

c)

Documenting risk scenarios

d)

Assessing the current state of controls

30.

What type of metric is a lag risk indicator?

a)

Forward-looking metric providing an early warning that risk may soon be realized before an event occurs

b)

Backward-looking metric indicating risk has been realized after an event has occurred

c)

In place to prevent events from occurring

d)

Measures upper and lower limits to help an enterprise understand when a condition requires attention before the risk is realized

31.

What is a cost-effective way to mitigate enterprise risk by educating staff?

a)

Creating complex incident response plans

b)

Awareness education and training

c)

Hiring external consultants

d)

Implementing new controls

32.

What is the purpose of strategic planning in relation to risk consideration?

a)

To anticipate and mitigate risks

b)

To only react to risks

c)

To identify risks after they occur

d)

To ignore risks and react when they occur

33.

What is the purpose of risk aggregation at an enterprise level?

a)

To aggregate risk primarily at a departmental level

b)

To obtain a comprehensive view of overall risk

c)

To obscure actionable details while aggregating

d)

To focus on easily measurable but less relevant risk

34.

What do effective KRIs provide?

a)

A. Historical context, feedback on risk appetite, early warning signals

b)

B. Detailed projections and ad-hoc feedback on risks

c)

C. Late warning signals and lack of historical context

d)

D. Inaccurate data collection and undefined measurement objectives

35.

What is an example of a KRI trigger?

a)

Patching all critical patches within 30 days

b)

The development of effective risk management practices

c)

The risk of unpatched systems leading to data breaches

d)

Continuous monitoring process in the enterprise

36.

What is the primary focus of the Chief Digital Officer (CDO) in an organization?

a)

A. Digital initiatives

b)

B. Data management

c)

C. IT governance

d)

D. Risk management

37.

What do the Responsible (R), Accountable (A), Consulted (C), and Informed (I) components define in the RACI model?

a)

A. Roles and responsibilities

b)

B. Risk data collection

c)

C. Risk culture

d)

D. Risk governance

38.

What is the role of scenario generation in risk management?

a)

To assess the detectability of risk scenarios

b)

To develop a generic risk structure for reporting

c)

To gain organizational buy-in for risk scenarios

d)

To identify risks and put in place countermeasures

39.

Which statement accurately describes threat actors?

a)

Every threat is associated with a threat actor.

b)

Threat actors are limited to humans.

c)

Threat actors encompass competitors as well.

d)

Threat actors encompass a variety of potential sources beyond just humans.

40.

What is the basis for developing risk scenarios using the bottom-up approach?

a)

I&T- and non-I&T-related events

b)

Assets, systems, or applications important to the enterprise

c)

Mission strategy and business objectives

d)

Understanding business goals and impact criteria

41.

Which statement about controls is true?

a)

Controls can only be categorized as technical in a control matrix

b)

Controls are essential for risk mitigation and include both proactive and reactive measures

c)

Controls prevent, detect, and correct damage resulting from an incident but do not enable recovery

d)

Controls are not essential for risk mitigation

42.

What is the purpose of awareness training for senior management?

a)

To transfer or share risk with another enterprise

b)

To understand liability, compliance, due care, due diligence, and create a risk management culture

c)

To reduce the impact of risk

d)

To avoid risk altogether

43.

How should I&T-related risk be connected to business objectives in an enterprise?

a)

By aligning with enterprise risk management when possible

b)

By impeding the business or mission objectives

c)

By avoiding any alignment with enterprise risk management

d)

By promoting ethical and open communication

44.

What are the three aspects that information assets should be protected against?

a)

Confidentiality, integrity, and availability

b)

Destruction, disclosure, and loss

c)

Unauthorized access, improper modification, and destruction

d)

Disclosure, modification, and non-accessibility

45.

Which of the following is considered an actor in the context of I&T-related risk scenario development?

a)

Any person, thing, or entity that acts or carries out a threat

b)

Only external entities that act maliciously

c)

Only nature and external requirements

d)

Only internal entities that act accidentally

46.

What is the primary purpose of a risk register?

a)

To track and manage identified risks

b)

To communicate risk assessment results to senior management

c)

To identify and analyze risks

d)

To create a comprehensive risk assessment report

47.

What does Risk assessment evaluate?

a)

The effectiveness of IT operations

b)

The business objectives and risks

c)

The current state of controls

d)

The performance of external entities

48.

What are the benefits of using appropriate KRIs?

a)

Early warning signals, historical context, and feedback on risk appetite

b)

Immediate response signals, ad-hoc data collection, and lack of logical relationship with specific risks

c)

Late feedback signals, real-time data collection, and undefined measurement objectives

d)

Delayed response signals, future projections, and historical context

49.

Why is it important for IT and the rest of the business to establish a mutual understanding of identifying the risk that needs to be managed?

a)

To guarantee impartiality and consistency throughout the enterprise

b)

To detect critical risk scenarios at a high level

c)

To understand how adverse events may affect business or mission objectives

d)

To identify potential high-risk areas

50.

What determines the suitability of risk analysis approaches?

a)

Potential consequences of a given risk scenario

b)

Culture, resources, skills, environment, and risk appetite

c)

Frequency and magnitude of a given risk scenario

d)

Criticality and sensitivity of IT assets

51.

When is a quantitative risk analysis approach most likely to be selected?

a)

Financial constraints limit analysis resources

b)

A cost-benefit analysis is necessary.

c)

Quantifying reputation and employee morale is the aim.

d)

Regulatory compliance requires numerical assessments.

52.

Why is it beneficial to present risk in a two-dimensional diagram?

a)

To indicate very low risk offering opportunities to save costs

b)

To identify trends or common profiles for more efficient risk response activities

c)

To express evaluated risk using well-defined and unambiguous impact criteria

d)

To compare different risk assessment methods over time

53.

What does the whistle-blower policy encourage employees to do?

a)

Raise concerns and report suspicious activity

b)

Adhere to quality improvement initiatives

c)

Participate in risk scoping activities

d)

Engage in ethical communication

54.

What does an enterprise need to determine using consistent methods?

a)

The dependencies of other systems on the affected IT system

b)

The level of risk associated with a threat

c)

Results that can be compared over time

d)

As much significant risks as possible

55.

Which method calculates the expected loss from a single event or threat occurrence?

a)

Annual Loss Expectancy (ALE)

b)

Single Loss Expectancy (SLE)

c)

Value at Risk (VaR)

d)

Earnings at Risk (EaR)

56.

What does establishing risk criteria in an enterprise involve?

a)

A. Evaluation of risk appetite, risk tolerance, and risk capacity

b)

B. Determination of resource optimization

c)

C. Promotion of ethical communication

d)

D. Consistency in risk assessment methods

57.

What do threat events refer to in the context of risk scenario development?

a)

Events that contribute to reducing impact frequency

b)

Positive impact-generating events within the enterprise

c)

Circumstances or events brought about by a threat actor that can trigger loss events

d)

Circumstances or events brought about by nature or external requirements

58.

What is the primary focus of the information security policy in an enterprise?

a)

Monitoring and predicting the state of risk management

b)

Defines the boundaries within which risk management activities operate

c)

Behavioral guidelines in protecting corporate information and associated systems

d)

Sets guidelines on how to act in crisis situations and details the sequence for dealing with risk areas

59.

What can inadequate communication of risk response actions lead to?

a)

Enhanced risk response

b)

Improved strategic planning

c)

False sense of confidence

d)

Increased stakeholder communication

60.

What should be considered when aggregating risk according to the guidelines?

a)

Obscure actionable details while aggregating

b)

Aggregate risk in a single dimension only

c)

Aggregate like data consistently and meaningfully

d)

Aggregate risk primarily at the departmental level

61.

What is the main purpose of vulnerability scans?

a)

To identify vulnerabilities proactively

b)

To monitor controls

c)

To conduct self-assessment

d)

To implement new controls

62.

What is the role of risk scenarios in risk identification and assessment?

a)

To determine the business impact of a breach or loss of an asset

b)

To analyze financial assets and their potential risks

c)

To facilitate communication and understanding of potential risks

d)

To conduct interviews with potential pitfalls

63.

What is the purpose of developing enterprise-specific impact criteria in risk management?

a)

To set risk appetites, provide meaning to risk, and reflect areas relevant to business objectives

b)

To create false assurance and inconsistency

c)

To estimate the frequency and magnitude of a given risk scenario

d)

To identify risks on a system-by-system basis

64.

What is the relationship between risk and control?

a)

The relationship between risk and control is indirect

b)

Controls have no impact on managing and mitigating risk

c)

There is a direct relationship

d)

There is no relationship between risk and control

65.

What is the primary focus of risk management?

a)

Risk detection and response

b)

Resource alignment

c)

Regulatory compliance

d)

Decision-making

66.

How is the dynamic nature of risk addressed in the effective management of I&T-related risk?

a)

By avoiding any preparation for changes in the industry at large

b)

By ignoring changes in laws and regulations

c)

By minimizing assessment of key processes and associated risks

d)

By giving advance consideration to changes in the enterprise and applicable laws and regulations

67.

What do KRIs facilitate across the enterprise?

a)

Complex discussions on risk and unchanged risk awareness

b)

Limited communication on risk and decreased business objectives alignment

c)

Clear and measurable discussions on risk and improved risk awareness

d)

Vague discussions on risk and decreased risk awareness

68.

What is the purpose of Root Cause Analysis?

a)

To establish the origins of events and prevent problem recurrence

b)

To ignore events and their consequences

c)

To identify risks before they occur

d)

To analyze completed projects

69.

What is the role of the third line in the three lines of defense in IT risk management?

a)

Conducting formal inspections and verifications

b)

Offering independent testing and assurance

c)

Monitoring controls

d)

Managing risk

70.

What are preventive, detective, corrective, and compensating examples of in risk management?

a)

Control types

b)

Threats

c)

Vulnerabilities

d)

Risk states

71.

Why is asset valuation important for risk management?

a)

To assess the financial value of assets

b)

To understand the business impact of a breach or loss of an asset

c)

To evaluate the impact of assets on business reputation

d)

To identify potential threats and vulnerabilities

72.

What does KPI stand for?

a)

Key Performance Indicator

b)

Key Promise Indicator

c)

Key People Indicator

d)

Key Privacy Indicator

73.

Which method estimates the probability of losses based on statistical analysis of historical price trends and volatilities?

a)

Single Loss Expectancy (SLE)

b)

Value at Risk (VaR)

c)

Annual Loss Expectancy (ALE)

d)

Earnings at Risk (EaR)

74.

How does effective enterprise governance of I&T-related risk align with overall enterprise risk management?

a)

By treating I&T-related risk as a separate type of risk

b)

By ignoring business or mission objectives

c)

By clearly defining risk appetite and risk tolerance

d)

By limiting the consequences of I&T-related risk

75.

What is the purpose of risk monitoring and evaluation?

a)

To provide reports that are systematic and timely

b)

To collect and validate business, IT, and process goals and metrics

c)

To prevent acceptance of risk that exceeds the risk acceptance criteria set by the business

d)

To monitor processes to ensure they are performed in line with established performance metrics

76.

What is a key requirement for effective risk monitoring and evaluation?

a)

Setting flexible risk acceptance criteria

b)

Gathering data from various sources in a timely and accurate manner

c)

Creating comprehensive reports on IT performance

d)

Aligning IT-related risk with business risk

77.

Risk monitoring focuses is:

a)

Measuring and assessing inherent risk.

b)

Selecting metrics that exceed risk tolerance.

c)

Observing and assessing potential risk events.

d)

Accepting risk cant be avoided

78.

What is crucial for effective risk management in an enterprise?

a)

Implementing risk governance controls

b)

Avoiding enterprise dependencies

c)

Focusing on natural disasters

d)

Balancing costs and benefits

79.

What type of indicators are Key Performance Indicators (KPIs) known as?

a)

Lagging indicators

b)

Process indicators

c)

Compliance indicators

d)

Leading indicators

80.

What influences an enterprise's risk appetite?

a)

Resource optimization

b)

Assessor bias mitigation

c)

Dynamic nature of risk

d)

Nature of the business

81.

What should the risk assessment report and risk register document?

a)

Assessed level or priority of each risk

b)

Budget allocation for implementing risk responses

c)

General business objectives

d)

Employee feedback on risk identification

82.

Who is primarily responsible for the overall governance in most enterprises?

a)

Special enterprise structures

b)

The chairperson

c)

The stakeholders

d)

The board of directors

83.

What is the purpose of a risk map?

a)

To present risk in a two-dimensional diagram based on frequency and impact

b)

To identify trends or common profiles for more efficient risk response activities

c)

To measure the impact of IT-related problems on business services

d)

To compare risk over time using consistent methods

84.

Control monitoring is to:

a)

Determine whether controls are cost efficient

b)

Determine whether controls are functioning as designed.

c)

Verify whether controls are effectively addressing risk.

d)

Determine the type of controls needed to address risk.

85.

What information forms the basis for identifying and analyzing risk using the top-down approach?

a)

Mission strategy and business objectives

b)

Hypothetical situations envisioned by the people performing job functions

c)

Assets, systems, or applications important to the enterprise

d)

Threats or generic loss scenarios

86.

What does detectability of risk scenarios include?

a)

The involvement of all parties in the risk scenario process

b)

The visibility and recognition of anything wrong

c)

The focus on worst-case events and less severe incidents

d)

The development of relevant and manageable risk scenarios

87.

What is the purpose of asset classification in IT?

a)

To determine the sensitivity and criticality of IT assets

b)

To evaluate the impact of IT assets on business reputation

c)

To identify potential threats and vulnerabilities

d)

To assess the financial value of IT assets