IT Risk Management Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IT Risk Management flashcards as text
Which risk treatment option involves transferring the financial consequences of a risk to a third party?
Answer: Risk transfer
Risk transfer shifts the financial burden of a risk to another party, such as through insurance or outsourcing contracts.
A CISA auditor finds that a company's risk register has not been updated in 18 months. What is the PRIMARY concern?
Answer: Emerging risks may not be identified or monitored
A stale risk register means new and evolving threats may go unrecognized, leaving the organization exposed to unmanaged risks.
In IT risk management, what does 'residual risk' refer to?
Answer: Risk remaining after controls are applied
Residual risk is the level of risk that remains after control measures have been implemented.
Which of the following BEST describes the purpose of a risk appetite statement?
Answer: To define the level of risk the organization is willing to accept
A risk appetite statement articulates how much risk the board and senior management are willing to tolerate in pursuit of business objectives.
An organization uses Key Risk Indicators (KRIs). What is the PRIMARY purpose of KRIs?
Answer: To provide early warning signals of increasing risk exposure
KRIs act as leading indicators that signal when risk levels are approaching thresholds, enabling proactive management.
Which risk assessment approach assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?
Answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values and formulas (e.g., ALE = ARO × SLE) to express risk in financial or statistical terms.
When performing an IT risk assessment, what does 'threat likelihood' measure?
Answer: The probability that a threat will exploit a vulnerability
Threat likelihood estimates how probable it is that a given threat will actually materialize and exploit an existing vulnerability.