← All ACI Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. An organization's risk appetite statement declares they will accept no more than a 5% probability of a data breach per year. This statement PRIMARILY guides:

    Answer: Decision-making about which risks to mitigate versus accept

    Risk appetite defines the level of risk an organization is willing to tolerate, directly guiding prioritization and investment in controls.

  2. During a post-incident review, investigators recommend implementing multi-factor authentication (MFA). MFA addresses which component of the risk equation?

    Answer: It reduces vulnerability by making credential theft less exploitable

    MFA reduces the vulnerability of single-password authentication by requiring an additional verification factor, making stolen credentials less useful.

  3. Which principle requires that users be granted ONLY the permissions necessary to perform their job duties, minimizing insider risk?

    Answer: Principle of least privilege

    The principle of least privilege limits access rights to the minimum necessary, reducing the attack surface and insider threat potential.

  4. An ACI examiner is assessing ransomware risk for a hospital. Which asset classification would make patient records the HIGHEST priority for protection?

    Answer: Critical assets — directly tied to patient safety and regulatory compliance

    Patient records in a hospital are critical assets because their compromise creates patient safety risks, HIPAA liability, and potential life-threatening disruptions.

  5. What is the MAIN distinction between a vulnerability assessment and a penetration test in the context of risk mitigation?

    Answer: A vulnerability assessment identifies weaknesses; a penetration test actively attempts to exploit them

    Vulnerability assessments scan and identify weaknesses, while penetration tests go further by actively attempting exploitation to validate real-world impact.

  6. An investigator discovers that an employee exfiltrated data just before resigning. Which risk mitigation process, if implemented, would MOST likely have detected this in real time?

    Answer: Data Loss Prevention (DLP) monitoring

    DLP solutions monitor and alert on unauthorized data transfers in real time, allowing organizations to detect exfiltration as it happens.

  7. After completing a digital forensic investigation, an ACI investigator provides a final report with risk mitigation recommendations. What should the FINAL step of this reporting process include?

    Answer: Providing actionable, prioritized recommendations and an executive summary

    An effective forensic report concludes with prioritized, actionable recommendations and an executive summary so leadership can make informed risk mitigation decisions.