โ† All CRA Flashcard Decks

Risk Mitigation and Controls Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Mitigation and Controls flashcards as text
  1. A risk architect conducts a control gap analysis. What does this process identify?

    Answer: Risks not adequately addressed by existing controls

    A control gap analysis compares existing controls against identified risks to highlight areas where controls are absent, weak, or insufficient.

  2. Which control is most effective at mitigating the risk of ransomware causing permanent data loss?

    Answer: Regular offline or immutable data backups

    Immutable or offline backups ensure data can be restored even after ransomware encrypts production systems, directly mitigating the impact of an attack.

  3. In risk control self-assessment (RCSA), who is primarily responsible for evaluating controls?

    Answer: Business unit management and process owners

    RCSA is a process where business unit managers and process owners assess the adequacy of controls within their own operations, promoting ownership of risk management.

  4. What is the purpose of a control's 'tolerable error rate' in testing?

    Answer: To establish the threshold of failure frequency above which the control is deemed ineffective

    The tolerable error rate defines the maximum acceptable failure frequency for a control; exceeding it signals the control is not operating effectively.

  5. An organization uses penetration testing to evaluate its cybersecurity posture. This is an example of which type of control assessment?

    Answer: Operating effectiveness testing

    Penetration testing actively probes systems to determine whether security controls are operating effectively in practice, making it an operating effectiveness assessment.

  6. Which principle states that controls should be proportionate to the risks they are designed to address?

    Answer: Principle of proportionality

    The principle of proportionality requires that the cost and rigor of a control be commensurate with the severity and likelihood of the risk it mitigates.

  7. A detective control identified a fraud event three months after it occurred. What should a risk architect recommend to improve the control environment?

    Answer: Add preventive controls to stop fraud before it occurs

    When detective controls identify issues too late, adding preventive controls earlier in the process reduces the opportunity for fraud to occur in the first place.