← All ACI Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. An investigator finds that an employee accessed sensitive HR files outside business hours for 30 consecutive days. In risk terms, this pattern is BEST classified as:

    Answer: An insider threat indicator

    Repeated after-hours access to sensitive data by an authorized user is a classic insider threat behavioral indicator.

  2. Which document formally authorizes an investigator to proceed with a digital forensic examination and limits legal risk to the organization?

    Answer: Written authorization or consent form

    Written authorization or consent ensures the investigation is legally sanctioned and protects the investigator and organization from unauthorized search claims.

  3. A risk mitigation plan identifies that patching a critical vulnerability will take 30 days. What should the organization implement in the interim?

    Answer: Implement compensating controls to reduce exposure

    Compensating controls (such as additional monitoring, network segmentation, or access restrictions) reduce risk exposure while a permanent fix is pending.

  4. During an investigation into a data breach, the ACI examiner must determine which assets were affected. What is this process called?

    Answer: Asset inventory and classification

    Asset inventory and classification identifies and categorizes all resources so investigators can determine what was exposed or compromised.

  5. Which type of risk analysis assigns numeric values to likelihood and impact to produce a quantitative risk score?

    Answer: Quantitative risk analysis

    Quantitative risk analysis uses numerical values (e.g., Annual Loss Expectancy) to objectively measure and compare risks.

  6. An organization decides not to use cloud storage due to concerns about data sovereignty and compliance risk. This is an example of:

    Answer: Risk avoidance

    Risk avoidance involves eliminating the activity or technology that creates the risk entirely, rather than managing it.

  7. In forensic investigations, maintaining a strict chain of custody is a risk mitigation practice primarily designed to prevent:

    Answer: Evidence being ruled inadmissible in court

    A documented chain of custody proves evidence integrity and continuity, preventing defense attorneys from successfully challenging its admissibility.