Risk Management & Mitigation Flashcards
7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
An ACI investigator is assessing a small business with no formal IT department. Which risk assessment approach is MOST practical for this environment?
Answer: Qualitative risk assessment using high/medium/low ratings
Qualitative risk assessments are practical for resource-limited environments and provide actionable rankings without requiring extensive financial data.
What is the PRIMARY purpose of a Business Continuity Plan (BCP) in risk mitigation?
Answer: To ensure critical business functions continue during and after a disruptive event
A BCP defines procedures to maintain essential operations during disruptions, minimizing the impact of incidents on the organization.
Which metric expresses the estimated financial loss an organization can expect from a specific risk in a given year?
Answer: Annualized Loss Expectancy (ALE)
ALE = SLE × Annual Rate of Occurrence (ARO), representing the yearly expected financial cost of a specific risk.
During risk prioritization, an investigator identifies a vulnerability with HIGH likelihood but LOW impact. How should this be ranked compared to LOW likelihood but CRITICAL impact?
Answer: Low likelihood/critical impact typically ranks higher due to catastrophic potential consequences
Critical impact vulnerabilities — even with low likelihood — typically receive priority because the potential damage is catastrophic and often irreversible.
An examiner discovers that company laptops lack full-disk encryption. In risk management terms, the absence of encryption is classified as a:
Answer: Vulnerability
A vulnerability is a weakness or gap in security controls — the absence of encryption is a security weakness that can be exploited.
Which risk mitigation technique involves separating a network into distinct segments to prevent lateral movement by an attacker?
Answer: Network segmentation
Network segmentation divides a network into isolated zones so that a breach in one segment does not automatically compromise others.
A risk register is an essential tool in risk management. What information does it typically NOT contain?
Answer: The suspect's personal contact information
A risk register tracks identified risks, owners, mitigations, and ratings — it never contains personal details about individuals under investigation.