IT Risk Management Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IT Risk Management flashcards as text
Which role is PRIMARILY responsible for accepting residual risk within an organization?
Answer: Risk owner or senior management
Risk acceptance is a management decision and must be made by the appropriate risk owner or senior management with the authority to do so.
A third-party vendor has access to sensitive customer data. Which risk management activity is MOST critical?
Answer: Performing vendor risk assessments and due diligence reviews
Third-party access requires formal vendor risk assessments to evaluate whether the vendor's controls adequately protect the organization's data.
Which of the following BEST represents the relationship between risk tolerance and risk appetite?
Answer: Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it
Risk appetite is the overall level of risk an organization is willing to pursue, while risk tolerance is the acceptable variance around that appetite for specific risks.
An IS auditor is reviewing IT risk management practices. Which finding represents the MOST significant control gap?
Answer: Risk scenarios are not linked to specific business processes
Risk scenarios disconnected from business processes cannot be properly prioritized or mitigated because their business impact is unknown.
What is the MAIN advantage of using a risk scenario approach in IT risk management?
Answer: It provides concrete, realistic examples that link threats to business impact
Risk scenarios describe specific threat events and their potential business consequences, making abstract risks tangible and easier to assess.
During a risk assessment, a CISA auditor discovers that a critical system has no documented risk treatment plan. What should the auditor recommend FIRST?
Answer: Assign a risk owner and develop a formal risk treatment plan
The immediate priority is assigning accountability and creating a formal treatment plan to address the gap in governance.
Which of the following BEST describes a risk scenario used in IT risk management frameworks like COBIT?
Answer: A narrative that connects a threat actor, event, and business impact
A risk scenario in COBIT combines a threat source, vulnerability, and resulting business impact into a coherent narrative for assessment purposes.