Risk Management & Mitigation Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
A forensic examiner is called to respond to a ransomware incident. Which immediate action best mitigates further data loss risk?
Answer: Isolate affected systems from the network to prevent spread
Network isolation prevents ransomware from propagating to additional systems while preserving the existing state for forensic analysis.
Which framework is most commonly referenced for IT risk management and aligns closely with digital forensics operational risk controls?
Answer: NIST SP 800-30
NIST SP 800-30 provides a comprehensive guide to risk assessment that is widely applied to IT and digital forensics environments.
An examiner's workstation is compromised by malware mid-investigation. Which risk was insufficiently mitigated?
Answer: Examiner workstation integrity risk
Malware on the examiner's workstation represents a failure to mitigate workstation integrity risk, which can contaminate forensic analysis results.
A risk assessment reveals that the probability of unauthorized physical access to evidence storage is 'high' but the impact is 'low.' How should this risk typically be prioritized?
Answer: Treat as medium priority and schedule remediation
High probability combined with low impact generally yields a medium overall risk rating, warranting planned remediation rather than immediate action.
Which of the following best describes a 'threat' in the context of risk management for a forensic lab?
Answer: A potential cause of an unwanted incident that could harm assets
A threat is any potential cause of an unwanted incident, such as a malicious actor, natural disaster, or human error, that could exploit vulnerabilities.
What is the purpose of a Business Impact Analysis (BIA) in a forensic lab's risk management program?
Answer: To determine the criticality of lab functions and acceptable downtime
A BIA identifies which lab functions are most critical, their recovery time objectives, and the business impact if those functions are disrupted.
An ACE examiner receives a hard drive that shows signs of physical damage. Which risk mitigation step should be taken before attempting logical acquisition?
Answer: Send the drive to a clean room for physical recovery assessment
Physically damaged drives risk further data loss if operated without assessment; a clean room specialist can evaluate and stabilize the drive before acquisition.