CCP Risk Management & Assessment Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP Risk Management & Assessment flashcards as text
What is the primary purpose of a Business Impact Analysis (BIA)?
Answer: To determine critical business functions and their recovery priorities
A BIA identifies critical business functions, their dependencies, and the impact of disruptions to guide recovery prioritization.
Which metric defines the maximum acceptable downtime for a system following a disaster?
Answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) specifies the maximum time allowed to restore a system or process after a disruption.
In the NIST Risk Management Framework (RMF), which step involves choosing appropriate security controls?
Answer: Select
The Select step in NIST RMF involves choosing security controls tailored to the system's risk categorization.
Which type of risk assessment assigns numerical probabilities and financial values to risk outcomes?
Answer: Quantitative
Quantitative risk assessments use numerical data and monetary metrics to express risk in measurable financial terms.
How is Annual Loss Expectancy (ALE) calculated?
Answer: SLE multiplied by ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly financial loss.
When the cost of mitigating a risk exceeds the value of the asset at risk, which risk response is most appropriate?
Answer: Risk acceptance
Risk acceptance is rational when the cost to mitigate a risk outweighs the potential financial loss from the risk event.