Risk Mitigation and Controls Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Mitigation and Controls flashcards as text
In the context of IT risk, which control layer is responsible for ensuring only authorized users access systems?
Answer: Logical access controls
Logical access controls (passwords, MFA, role-based access) govern who can authenticate and what resources they can use within IT systems.
A risk architect evaluates a control and finds it reduces both the likelihood and impact of a risk. This control strategy is known as:
Answer: Risk mitigation
Risk mitigation involves implementing controls that reduce the probability, impact, or both dimensions of a risk event.
Which type of control testing involves reviewing documentation and policies without testing actual execution?
Answer: Design effectiveness testing
Design effectiveness testing evaluates whether a control is properly designed to address a risk, typically through inquiry and inspection of documentation.
An organization contracts a third-party vendor to process customer data. Which control is most critical to mitigate third-party risk?
Answer: Vendor due diligence and contractual SLAs with right-to-audit clauses
Vendor due diligence combined with contractual SLAs and right-to-audit provisions ensures third parties meet security and compliance requirements.
The four Ts of risk response are: Tolerate, Treat, Transfer, and:
Answer: Terminate
The four Ts of risk response are Tolerate (accept), Treat (mitigate), Transfer (insure/outsource), and Terminate (avoid by ceasing the activity).
Which framework specifically provides guidance on designing and evaluating internal controls over financial reporting?
Answer: COSO Internal Control — Integrated Framework
The COSO Internal Control — Integrated Framework is the globally recognized standard for designing and evaluating internal controls, especially over financial reporting.
A business continuity plan (BCP) is primarily a type of which risk response?
Answer: Risk treatment / reduction
A BCP is a risk treatment measure that reduces the impact of disruptions by ensuring the organization can recover and continue critical operations.