← All ACI Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. An ACI investigator is assessing a small business with no formal IT department. Which risk assessment approach is MOST practical for this environment?

    Answer: Qualitative risk assessment using high/medium/low ratings

    Qualitative risk assessments are practical for resource-limited environments and provide actionable rankings without requiring extensive financial data.

  2. What is the PRIMARY purpose of a Business Continuity Plan (BCP) in risk mitigation?

    Answer: To ensure critical business functions continue during and after a disruptive event

    A BCP defines procedures to maintain essential operations during disruptions, minimizing the impact of incidents on the organization.

  3. Which metric expresses the estimated financial loss an organization can expect from a specific risk in a given year?

    Answer: Annualized Loss Expectancy (ALE)

    ALE = SLE × Annual Rate of Occurrence (ARO), representing the yearly expected financial cost of a specific risk.

  4. During risk prioritization, an investigator identifies a vulnerability with HIGH likelihood but LOW impact. How should this be ranked compared to LOW likelihood but CRITICAL impact?

    Answer: Low likelihood/critical impact typically ranks higher due to catastrophic potential consequences

    Critical impact vulnerabilities — even with low likelihood — typically receive priority because the potential damage is catastrophic and often irreversible.

  5. An examiner discovers that company laptops lack full-disk encryption. In risk management terms, the absence of encryption is classified as a:

    Answer: Vulnerability

    A vulnerability is a weakness or gap in security controls — the absence of encryption is a security weakness that can be exploited.

  6. Which risk mitigation technique involves separating a network into distinct segments to prevent lateral movement by an attacker?

    Answer: Network segmentation

    Network segmentation divides a network into isolated zones so that a breach in one segment does not automatically compromise others.

  7. A risk register is an essential tool in risk management. What information does it typically NOT contain?

    Answer: The suspect's personal contact information

    A risk register tracks identified risks, owners, mitigations, and ratings — it never contains personal details about individuals under investigation.