Risk Management & Mitigation Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
A forensic lab's disaster recovery plan specifies a Recovery Point Objective (RPO) of 4 hours. What does this mean?
Answer: No more than 4 hours of data can be lost in a recovery scenario
RPO defines the maximum acceptable amount of data loss measured in time; a 4-hour RPO means backups must occur at least every 4 hours.
Which of the following is an example of a 'detective' control in a forensic lab's risk mitigation strategy?
Answer: Reviewing audit logs to identify unauthorized access attempts
Detective controls identify and alert on events that have already occurred, such as reviewing audit logs to spot unauthorized access after the fact.
During an ACE examination, an examiner identifies that a suspect's cloud storage account contains potential evidence. What risk must be mitigated before legal acquisition?
Answer: Risk of evidence destruction due to account termination or file deletion
Cloud evidence can be deleted or accounts terminated; legal preservation orders (holds) should be sought immediately to mitigate this evidence destruction risk.
An organization implements multi-factor authentication (MFA) for access to its forensic case management system. This control primarily mitigates which risk?
Answer: Credential compromise leading to unauthorized logical access
MFA significantly reduces the risk of unauthorized access caused by compromised passwords by requiring a second verification factor.
Which term describes the documented process for responding to and recovering from a specific type of security incident in a forensic organization?
Answer: Playbook (or runbook)
A playbook or runbook provides step-by-step procedures for responding to and recovering from a defined incident type, reducing response time and errors.
A risk assessment reveals that an outdated forensic tool has a known vulnerability exploitable via USB input. The vendor no longer supports the tool. Which is the BEST mitigation?
Answer: Apply compensating controls such as disabling USB ports and air-gapping the workstation
When patching is not possible, compensating controls like disabling USB ports and air-gapping the system reduce exposure without replacing the unsupported tool.
In the context of digital forensics risk management, 'due diligence' refers to:
Answer: Proactively identifying and addressing risks before harm occurs
Due diligence requires proactively researching, identifying, and mitigating risks before they cause harm, demonstrating responsible and thorough risk management.