โ† All CRM Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. A records manager is asked to assess the risk of a third-party vendor handling confidential records. Which document is MOST critical to review?

    Answer: The vendor's data processing agreement and security certifications

    Data processing agreements and security certifications (e.g., SOC 2, ISO 27001) confirm that a vendor has adequate controls to protect confidential records.

  2. Which of the following is the MOST significant risk associated with poor records classification?

    Answer: Misapplication of retention schedules leading to premature destruction or over-retention

    Incorrect classification causes the wrong retention schedule to be applied, risking either premature destruction of legally required records or costly over-retention.

  3. An organization operates in multiple U.S. states with different data privacy laws. The records risk this creates is BEST characterized as:

    Answer: Regulatory/jurisdictional compliance risk

    Operating across multiple jurisdictions with varying privacy laws creates regulatory compliance risk, requiring harmonized records policies or jurisdiction-specific procedures.

  4. Which mitigation control BEST addresses the risk of records loss due to a ransomware attack?

    Answer: Immutable, air-gapped backups with tested restoration procedures

    Immutable, air-gapped backups cannot be encrypted by ransomware and, when regularly tested, ensure rapid recovery without paying ransom.

  5. The principle of 'defense in depth' applied to records risk mitigation means:

    Answer: Layering multiple independent controls so that failure of one does not result in total loss

    Defense in depth uses overlapping layers of controls so that if one layer fails, others continue to protect records integrity and availability.

  6. A records manager notices that risk assessments are conducted only at project initiation and never revisited. The MOST significant problem with this approach is:

    Answer: It fails to account for new risks that emerge as organizational conditions change

    Risk environments change continuously; a one-time assessment quickly becomes outdated and fails to identify new threats or changes in impact and likelihood.

  7. Which factor would MOST increase the impact rating of a risk involving the loss of employee personally identifiable information (PII)?

    Answer: The organization is subject to HIPAA, state breach notification laws, and GDPR simultaneously

    Being subject to multiple overlapping regulations (HIPAA, state laws, GDPR) amplifies the legal, financial, and reputational consequences of a PII breach.