π§ OLUMA CERTIFICATION ZONE IT Risk FundamentalsPractice Range 100 original questions across the six IT Risk Fundamentals domains β from what risk is to how it’s governed, found, measured, treated and watched. Pick your range and find your bearings. Risk Intro & OverviewRisk Governance & ManagementRisk IdentificationRisk Assessment & AnalysisRisk ResponseRisk Monitoring & Reporting SELECT YOUR RANGE102550100 01/100 Risk Intro & Overview In risk management terms, what is 'risk'? AA type of auditβ OFF COURSESmall detour β back on course with this:Risk combines uncertainty (likelihood) with consequence (impact) relative to what the organization is trying to achieve. BThe effect of uncertainty on objectives β a potential event and its consequenceβ RISK UNDERSTOODYou're building the foundation every risk career stands on.Risk combines uncertainty (likelihood) with consequence (impact) relative to what the organization is trying to achieve. CAny expenseβ OFF COURSESmall detour β back on course with this:Risk combines uncertainty (likelihood) with consequence (impact) relative to what the organization is trying to achieve. DA guaranteed lossβ OFF COURSESmall detour β back on course with this:Risk combines uncertainty (likelihood) with consequence (impact) relative to what the organization is trying to achieve. 02/100 Risk Intro & Overview A ransomware group targeting the healthcare sector is an example of a: AThreatβ COURSE CONFIRMEDSolid fundamentals β that's a future CRISC talking.A threat is an actor or event with the potential to cause harm. BVulnerabilityβ RECHECK THE MAPNo losses in practice. Log the lesson:A threat is an actor or event with the potential to cause harm. CRisk responseβ RECHECK THE MAPNo losses in practice. Log the lesson:A threat is an actor or event with the potential to cause harm. DControlβ RECHECK THE MAPNo losses in practice. Log the lesson:A threat is an actor or event with the potential to cause harm. 03/100 Risk Intro & Overview An internet-facing server missing critical patches is an example of a: ARisk appetiteβ EXPOSURE MISSEDAdjust your heading with this insight:A vulnerability is a weakness that a threat can exploit. BVulnerabilityβ APPETITE ALIGNEDExactly right. Risk thinking is becoming instinct.A vulnerability is a weakness that a threat can exploit. CThreatβ EXPOSURE MISSEDAdjust your heading with this insight:A vulnerability is a weakness that a threat can exploit. DKRIβ EXPOSURE MISSEDAdjust your heading with this insight:A vulnerability is a weakness that a threat can exploit. 04/100 Risk Intro & Overview Anything of value to the organization β data, systems, people, reputation β is called a(n): AThreatβ RECALIBRATEFundamentals take reps. Here's the takeaway:Assets are what risk management ultimately protects. BAssetβ SCENARIO MAPPEDClear-eyed and correct. Oluma loves to see it.Assets are what risk management ultimately protects. CExposureβ RECALIBRATEFundamentals take reps. Here's the takeaway:Assets are what risk management ultimately protects. DMetricβ RECALIBRATEFundamentals take reps. Here's the takeaway:Assets are what risk management ultimately protects. 05/100 Risk Intro & Overview Why is IT risk considered a business risk rather than just a technical issue? ATechnology failures directly harm business objectives: revenue, operations, compliance, and reputationβ IMPACT MEASUREDYou just reasoned like a risk professional.IT underpins business processes, so IT risk translates into business impact. BServers are expensiveβ REVIEW THE BASICSSmall detour β back on course with this:IT underpins business processes, so IT risk translates into business impact. CIT staff say soβ REVIEW THE BASICSSmall detour β back on course with this:IT underpins business processes, so IT risk translates into business impact. DIt isn'tβ REVIEW THE BASICSSmall detour β back on course with this:IT underpins business processes, so IT risk translates into business impact. 06/100 Risk Intro & Overview Which is an example of IT risk creating opportunity cost (value not realized)? AA power outageβ OFF COURSENo losses in practice. Log the lesson:IT risk includes failing to benefit from technology, not only losses from incidents. BStolen laptopsβ OFF COURSENo losses in practice. Log the lesson:IT risk includes failing to benefit from technology, not only losses from incidents. CA breach fineβ OFF COURSENo losses in practice. Log the lesson:IT risk includes failing to benefit from technology, not only losses from incidents. DBeing too slow or risk-averse to adopt beneficial technology competitors use wellβ RESPONSE CHOSENThat's the answer a seasoned analyst would give.IT risk includes failing to benefit from technology, not only losses from incidents. 07/100 Risk Intro & Overview Likelihood answers which question about a risk? AHow bad would it be?β RECHECK THE MAPAdjust your heading with this insight:Likelihood is the probability dimension; impact is the consequence dimension. BWho caused it?β RECHECK THE MAPAdjust your heading with this insight:Likelihood is the probability dimension; impact is the consequence dimension. CHow probable is it?β INDICATOR GREENYou're building the foundation every risk career stands on.Likelihood is the probability dimension; impact is the consequence dimension. DWhat does it cost to fix?β RECHECK THE MAPAdjust your heading with this insight:Likelihood is the probability dimension; impact is the consequence dimension. 08/100 Risk Intro & Overview Impact answers which question about a risk? AHow severe would the consequences be?β LESSON LOGGEDSolid fundamentals β that's a future CRISC talking.Impact measures the magnitude of harm to objectives if the event occurs. BWhich team owns it?β EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Impact measures the magnitude of harm to objectives if the event occurs. CWhen is the audit?β EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Impact measures the magnitude of harm to objectives if the event occurs. DHow probable is it?β EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Impact measures the magnitude of harm to objectives if the event occurs. 09/100 Risk Intro & Overview The combination of all risks an organization currently faces is its: ARisk transferβ RECALIBRATESmall detour β back on course with this:The risk profile is the current overall risk landscape/portfolio. BRisk profileβ BEARINGS TRUEExactly right. Risk thinking is becoming instinct.The risk profile is the current overall risk landscape/portfolio. CRisk appetiteβ RECALIBRATESmall detour β back on course with this:The risk profile is the current overall risk landscape/portfolio. DRisk responseβ RECALIBRATESmall detour β back on course with this:The risk profile is the current overall risk landscape/portfolio. 10/100 Risk Intro & Overview Which of these illustrates reputational impact from an IT event? AA completed patch cycleβ REVIEW THE BASICSNo losses in practice. Log the lesson:Beyond direct costs, incidents can erode trust β often the most lasting damage. BA disk running hotβ REVIEW THE BASICSNo losses in practice. Log the lesson:Beyond direct costs, incidents can erode trust β often the most lasting damage. CCustomers losing trust after a publicized data breachβ REGISTER CURRENTClear-eyed and correct. Oluma loves to see it.Beyond direct costs, incidents can erode trust β often the most lasting damage. DA password changeβ REVIEW THE BASICSNo losses in practice. Log the lesson:Beyond direct costs, incidents can erode trust β often the most lasting damage. CHECKPOINT β 10 DOWN, KEEP CLIMBING 11/100 Risk Intro & Overview 'Zero risk' as a business goal is: AA standard KPIβ OFF COURSEAdjust your heading with this insight:Risk can be reduced and managed, never eliminated; management aims for informed acceptance. BRequired by lawβ OFF COURSEAdjust your heading with this insight:Risk can be reduced and managed, never eliminated; management aims for informed acceptance. CAchievable with enough budgetβ OFF COURSEAdjust your heading with this insight:Risk can be reduced and managed, never eliminated; management aims for informed acceptance. DUnrealistic β the goal is keeping risk within acceptable levels while pursuing objectivesβ RISK UNDERSTOODYou just reasoned like a risk professional.Risk can be reduced and managed, never eliminated; management aims for informed acceptance. 12/100 Risk Intro & Overview Which statement about risk and reward is accurate? AAll risk-taking is recklessβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Organizations take risk to gain value; risk management makes that pursuit informed. BRisk only applies to ITβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Organizations take risk to gain value; risk management makes that pursuit informed. CValue creation typically requires taking some risk deliberately and managing itβ COURSE CONFIRMEDThat's the answer a seasoned analyst would give.Organizations take risk to gain value; risk management makes that pursuit informed. DReward never involves riskβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Organizations take risk to gain value; risk management makes that pursuit informed. 13/100 Risk Intro & Overview A flood damaging a data center is which category of threat? AAdversarialβ EXPOSURE MISSEDSmall detour β back on course with this:Threat sources include adversarial, accidental, structural, and environmental categories. BRegulatoryβ EXPOSURE MISSEDSmall detour β back on course with this:Threat sources include adversarial, accidental, structural, and environmental categories. CCulturalβ EXPOSURE MISSEDSmall detour β back on course with this:Threat sources include adversarial, accidental, structural, and environmental categories. DEnvironmental/naturalβ APPETITE ALIGNEDYou're building the foundation every risk career stands on.Threat sources include adversarial, accidental, structural, and environmental categories. 14/100 Risk Intro & Overview An employee accidentally emailing a client list to the wrong recipient is which threat type? AHardware failureβ RECALIBRATENo losses in practice. Log the lesson:Unintentional human error is one of the most common threat sources. BAccidental / human errorβ SCENARIO MAPPEDSolid fundamentals β that's a future CRISC talking.Unintentional human error is one of the most common threat sources. CNatural disasterβ RECALIBRATENo losses in practice. Log the lesson:Unintentional human error is one of the most common threat sources. DAdversarial attackβ RECALIBRATENo losses in practice. Log the lesson:Unintentional human error is one of the most common threat sources. 15/100 Risk Intro & Overview The chance a threat successfully exploits a vulnerability and harms an asset describes: AA controlβ REVIEW THE BASICSAdjust your heading with this insight:When threat meets vulnerability and impacts an asset, risk is realized as an incident/loss event. BA risk scenario materializingβ IMPACT MEASUREDExactly right. Risk thinking is becoming instinct.When threat meets vulnerability and impacts an asset, risk is realized as an incident/loss event. CGovernanceβ REVIEW THE BASICSAdjust your heading with this insight:When threat meets vulnerability and impacts an asset, risk is realized as an incident/loss event. DAn auditβ REVIEW THE BASICSAdjust your heading with this insight:When threat meets vulnerability and impacts an asset, risk is realized as an incident/loss event. 16/100 Risk Intro & Overview Why does every organization β not just banks or hospitals β need IT risk management? ARegulations apply identically to allβ OFF COURSEFundamentals take reps. Here's the takeaway:Technology dependence is universal; only the scale and specifics of risk differ. BOnly large firms have riskβ OFF COURSEFundamentals take reps. Here's the takeaway:Technology dependence is universal; only the scale and specifics of risk differ. CNearly every organization depends on technology and data to operate, so all face IT riskβ RESPONSE CHOSENClear-eyed and correct. Oluma loves to see it.Technology dependence is universal; only the scale and specifics of risk differ. DIt's fashionableβ OFF COURSEFundamentals take reps. Here's the takeaway:Technology dependence is universal; only the scale and specifics of risk differ. 17/100 Risk Intro & Overview Which best describes the relationship between information security and IT risk management? ASecurity is a major discipline within managing IT risk, which also covers availability, project, and strategic technology riskβ INDICATOR GREENYou just reasoned like a risk professional.IT risk is broader than security alone β it includes any tech-related threat to objectives. BSecurity replaces risk managementβ RECHECK THE MAPSmall detour β back on course with this:IT risk is broader than security alone β it includes any tech-related threat to objectives. CRisk management is a firewall brandβ RECHECK THE MAPSmall detour β back on course with this:IT risk is broader than security alone β it includes any tech-related threat to objectives. DThey are unrelatedβ RECHECK THE MAPSmall detour β back on course with this:IT risk is broader than security alone β it includes any tech-related threat to objectives. 18/100 Risk Governance & Management Risk governance is primarily concerned with: ADaily firewall rulesβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Governance sets the framework and boundaries; management executes within them. BSetting direction, accountability, and oversight for how risk is managedβ LESSON LOGGEDThat's the answer a seasoned analyst would give.Governance sets the framework and boundaries; management executes within them. CBuying insuranceβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Governance sets the framework and boundaries; management executes within them. DWriting codeβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Governance sets the framework and boundaries; management executes within them. 19/100 Risk Governance & Management Who is ultimately accountable for risk oversight in an organization? AInternsβ RECALIBRATEAdjust your heading with this insight:Boards own oversight; management runs the program day to day. BVendorsβ RECALIBRATEAdjust your heading with this insight:Boards own oversight; management runs the program day to day. CThe board of directors / senior governance bodyβ BEARINGS TRUEYou're building the foundation every risk career stands on.Boards own oversight; management runs the program day to day. DThe service deskβ RECALIBRATEAdjust your heading with this insight:Boards own oversight; management runs the program day to day. 20/100 Risk Governance & Management The amount of risk an organization is willing to take in pursuit of its objectives is its: AResidual riskβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Appetite is the willingness boundary set by leadership. BRisk capacityβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Appetite is the willingness boundary set by leadership. CRisk appetiteβ REGISTER CURRENTSolid fundamentals β that's a future CRISC talking.Appetite is the willingness boundary set by leadership. DRisk registerβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Appetite is the willingness boundary set by leadership. CHECKPOINT β 20 DOWN, KEEP CLIMBING 21/100 Risk Governance & Management Risk tolerance differs from appetite in that tolerance: AIs always zeroβ OFF COURSESmall detour β back on course with this:Tolerance operationalizes appetite at the objective/initiative level. BIs set by vendorsβ OFF COURSESmall detour β back on course with this:Tolerance operationalizes appetite at the objective/initiative level. CDefines acceptable variation around appetite for specific objectives or activitiesβ RISK UNDERSTOODExactly right. Risk thinking is becoming instinct.Tolerance operationalizes appetite at the objective/initiative level. DReplaces governanceβ OFF COURSESmall detour β back on course with this:Tolerance operationalizes appetite at the objective/initiative level. 22/100 Risk Governance & Management The absolute maximum loss an organization could survive is its: ARisk appetiteβ RECHECK THE MAPNo losses in practice. Log the lesson:Capacity is the hard ceiling; appetite should be set safely below it. BRisk capacityβ COURSE CONFIRMEDClear-eyed and correct. Oluma loves to see it.Capacity is the hard ceiling; appetite should be set safely below it. CRisk scoreβ RECHECK THE MAPNo losses in practice. Log the lesson:Capacity is the hard ceiling; appetite should be set safely below it. DRisk toleranceβ RECHECK THE MAPNo losses in practice. Log the lesson:Capacity is the hard ceiling; appetite should be set safely below it. 23/100 Risk Governance & Management In the 'three lines' model, business/operational management is: AOutside the modelβ EXPOSURE MISSEDAdjust your heading with this insight:The first line owns risks; second line oversees; third line (audit) assures independently. BThe third lineβ EXPOSURE MISSEDAdjust your heading with this insight:The first line owns risks; second line oversees; third line (audit) assures independently. CThe first line β owning and managing risk in daily operationsβ APPETITE ALIGNEDYou just reasoned like a risk professional.The first line owns risks; second line oversees; third line (audit) assures independently. DThe second lineβ EXPOSURE MISSEDAdjust your heading with this insight:The first line owns risks; second line oversees; third line (audit) assures independently. 24/100 Risk Governance & Management Internal audit's role in risk management is to: ASet risk appetiteβ RECALIBRATEFundamentals take reps. Here's the takeaway:Audit is the third line: independent evaluation reported to governance. BOperate firewallsβ RECALIBRATEFundamentals take reps. Here's the takeaway:Audit is the third line: independent evaluation reported to governance. CProvide independent assurance that risk management and controls are effectiveβ SCENARIO MAPPEDThat's the answer a seasoned analyst would give.Audit is the third line: independent evaluation reported to governance. DOwn all risksβ RECALIBRATEFundamentals take reps. Here's the takeaway:Audit is the third line: independent evaluation reported to governance. 25/100 Risk Governance & Management A risk policy that no one follows creates: AA false sense of security β documented and actual practice divergeβ IMPACT MEASUREDYou're building the foundation every risk career stands on.Unenforced policy hides real exposure behind paper assurance. BBetter moraleβ REVIEW THE BASICSSmall detour β back on course with this:Unenforced policy hides real exposure behind paper assurance. CStrong protectionβ REVIEW THE BASICSSmall detour β back on course with this:Unenforced policy hides real exposure behind paper assurance. DAutomatic complianceβ REVIEW THE BASICSSmall detour β back on course with this:Unenforced policy hides real exposure behind paper assurance. 26/100 Risk Governance & Management Risk culture refers to: AServer namingβ OFF COURSENo losses in practice. Log the lesson:Culture determines whether risk practices are lived or bypassed. BThe shared attitudes and behaviors that shape real risk decisionsβ RESPONSE CHOSENSolid fundamentals β that's a future CRISC talking.Culture determines whether risk practices are lived or bypassed. COffice dΓ©corβ OFF COURSENo losses in practice. Log the lesson:Culture determines whether risk practices are lived or bypassed. DThe audit calendarβ OFF COURSENo losses in practice. Log the lesson:Culture determines whether risk practices are lived or bypassed. 27/100 Risk Governance & Management Leadership publicly rewards a manager who bypassed controls to hit a deadline. The cultural signal is: ASpeed beats safety β encouraging others to bypass controls tooβ INDICATOR GREENExactly right. Risk thinking is becoming instinct.Tone at the top teaches the organization what really gets rewarded. BNothingβ RECHECK THE MAPAdjust your heading with this insight:Tone at the top teaches the organization what really gets rewarded. CControls matterβ RECHECK THE MAPAdjust your heading with this insight:Tone at the top teaches the organization what really gets rewarded. DAuditors are watchingβ RECHECK THE MAPAdjust your heading with this insight:Tone at the top teaches the organization what really gets rewarded. 28/100 Risk Governance & Management Assigning each significant risk a named owner ensures: AClear accountability for monitoring and treatment decisionsβ LESSON LOGGEDClear-eyed and correct. Oluma loves to see it.Ownership makes someone answerable for the risk's management. BFewer risks existβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Ownership makes someone answerable for the risk's management. CLower salariesβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Ownership makes someone answerable for the risk's management. DMore meetingsβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Ownership makes someone answerable for the risk's management. 29/100 Risk Governance & Management Why should risk management be embedded in decision-making rather than run as a separate annual exercise? ADecisions create or change risk daily β risk input belongs at decision timeβ BEARINGS TRUEYou just reasoned like a risk professional.Risk-aware decisions require risk information when choices are made, not months later. BRegulators forbid annual reviewsβ RECALIBRATESmall detour β back on course with this:Risk-aware decisions require risk information when choices are made, not months later. CIt shouldn't beβ RECALIBRATESmall detour β back on course with this:Risk-aware decisions require risk information when choices are made, not months later. DAnnual is cheaperβ RECALIBRATESmall detour β back on course with this:Risk-aware decisions require risk information when choices are made, not months later. 30/100 Risk Governance & Management A risk management framework (e.g., based on ISO 31000 or COBIT) provides: AFirewall settingsβ REVIEW THE BASICSNo losses in practice. Log the lesson:Frameworks standardize practice so risk is handled systematically, not ad hoc. BFree softwareβ REVIEW THE BASICSNo losses in practice. Log the lesson:Frameworks standardize practice so risk is handled systematically, not ad hoc. CConsistent principles, processes, and vocabulary for managing risk across the organizationβ REGISTER CURRENTThat's the answer a seasoned analyst would give.Frameworks standardize practice so risk is handled systematically, not ad hoc. DLegal immunityβ REVIEW THE BASICSNo losses in practice. Log the lesson:Frameworks standardize practice so risk is handled systematically, not ad hoc. CHECKPOINT β 30 DOWN, KEEP CLIMBING 31/100 Risk Governance & Management Compliance requirements (laws, regulations, contracts) relate to risk appetite how? AThey replace appetiteβ OFF COURSEAdjust your heading with this insight:Legal duties are non-negotiable boundaries on acceptable risk-taking. BThey are optional inputsβ OFF COURSEAdjust your heading with this insight:Legal duties are non-negotiable boundaries on acceptable risk-taking. CThey only apply to banksβ OFF COURSEAdjust your heading with this insight:Legal duties are non-negotiable boundaries on acceptable risk-taking. DThey constrain appetite β obligations must be met regardless of willingness to take riskβ RISK UNDERSTOODYou're building the foundation every risk career stands on.Legal duties are non-negotiable boundaries on acceptable risk-taking. 32/100 Risk Governance & Management Which structure typically reviews enterprise risk regularly and escalates to the board? AA single developerβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Risk committees provide management-level oversight feeding board governance. BA risk committeeβ COURSE CONFIRMEDSolid fundamentals β that's a future CRISC talking.Risk committees provide management-level oversight feeding board governance. CThe mailroomβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Risk committees provide management-level oversight feeding board governance. DThe cafeteria staffβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Risk committees provide management-level oversight feeding board governance. 33/100 Risk Governance & Management Risk management responsibilities in job descriptions and objectives serve to: APad documentsβ EXPOSURE MISSEDSmall detour β back on course with this:Embedding responsibility into roles operationalizes the governance model. BReduce clarityβ EXPOSURE MISSEDSmall detour β back on course with this:Embedding responsibility into roles operationalizes the governance model. CSlow hiringβ EXPOSURE MISSEDSmall detour β back on course with this:Embedding responsibility into roles operationalizes the governance model. DMake accountability real by tying it to performance expectationsβ APPETITE ALIGNEDExactly right. Risk thinking is becoming instinct.Embedding responsibility into roles operationalizes the governance model. 34/100 Risk Governance & Management The main output difference between governance and management of risk is: AManagement sets appetite aloneβ RECALIBRATENo losses in practice. Log the lesson:Direct-and-oversee versus plan-and-execute is the core split. BGovernance writes codeβ RECALIBRATENo losses in practice. Log the lesson:Direct-and-oversee versus plan-and-execute is the core split. CNone β same thingβ RECALIBRATENo losses in practice. Log the lesson:Direct-and-oversee versus plan-and-execute is the core split. DGovernance produces direction and boundaries; management produces execution: assessments, treatments, and monitoringβ SCENARIO MAPPEDClear-eyed and correct. Oluma loves to see it.Direct-and-oversee versus plan-and-execute is the core split. 35/100 Risk Identification The goal of risk identification is to: AFix all problems immediatelyβ REVIEW THE BASICSAdjust your heading with this insight:You can only manage risks you have found and articulated. BAssign blameβ REVIEW THE BASICSAdjust your heading with this insight:You can only manage risks you have found and articulated. CDiscover and describe risks before they materialize so they can be assessed and treatedβ IMPACT MEASUREDYou just reasoned like a risk professional.You can only manage risks you have found and articulated. DBuy toolsβ REVIEW THE BASICSAdjust your heading with this insight:You can only manage risks you have found and articulated. 36/100 Risk Identification Which is a common risk identification technique? AWaiting for incidentsβ OFF COURSEFundamentals take reps. Here's the takeaway:Structured workshops surface risks from the people who know the processes. BGuessing annuallyβ OFF COURSEFundamentals take reps. Here's the takeaway:Structured workshops surface risks from the people who know the processes. CBrainstorming workshops with business and IT stakeholdersβ RESPONSE CHOSENThat's the answer a seasoned analyst would give.Structured workshops surface risks from the people who know the processes. DIgnoring near-missesβ OFF COURSEFundamentals take reps. Here's the takeaway:Structured workshops surface risks from the people who know the processes. 37/100 Risk Identification Reviewing past incidents and near-misses supports identification by: AReplacing all other methodsβ RECHECK THE MAPSmall detour β back on course with this:History is evidence: past events highlight real, demonstrated exposure. BRevealing recurring weaknesses and scenarios that have already proven possibleβ INDICATOR GREENYou're building the foundation every risk career stands on.History is evidence: past events highlight real, demonstrated exposure. CReliving failures for funβ RECHECK THE MAPSmall detour β back on course with this:History is evidence: past events highlight real, demonstrated exposure. DAssigning blameβ RECHECK THE MAPSmall detour β back on course with this:History is evidence: past events highlight real, demonstrated exposure. 38/100 Risk Identification An up-to-date asset inventory matters for identification because: AIt sets pricesβ EXPOSURE MISSEDNo losses in practice. Log the lesson:You cannot identify risks to assets you don't know exist. BIt prevents phishing directlyβ EXPOSURE MISSEDNo losses in practice. Log the lesson:You cannot identify risks to assets you don't know exist. CRisks attach to assets β unknown systems and data mean unidentified riskβ LESSON LOGGEDSolid fundamentals β that's a future CRISC talking.You cannot identify risks to assets you don't know exist. DAuditors love spreadsheetsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:You cannot identify risks to assets you don't know exist. 39/100 Risk Identification A well-written risk scenario connects: ATwo acronymsβ RECALIBRATEAdjust your heading with this insight:Complete scenarios link cause to consequence, making risks assessable. BA password and a usernameβ RECALIBRATEAdjust your heading with this insight:Complete scenarios link cause to consequence, making risks assessable. CA vendor and a discountβ RECALIBRATEAdjust your heading with this insight:Complete scenarios link cause to consequence, making risks assessable. DA threat, a vulnerability, an asset, and the business impactβ BEARINGS TRUEExactly right. Risk thinking is becoming instinct.Complete scenarios link cause to consequence, making risks assessable. 40/100 Risk Identification 'Cyber risk' as a single register entry is problematic because: ARegisters only hold five entriesβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Actionable identification requires specific, bounded scenarios. BCyber isn't a riskβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Actionable identification requires specific, bounded scenarios. CIt is too broad to assess, own, or treat β it must be decomposed into specific scenariosβ REGISTER CURRENTClear-eyed and correct. Oluma loves to see it.Actionable identification requires specific, bounded scenarios. DIt is too detailedβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Actionable identification requires specific, bounded scenarios. CHECKPOINT β 40 DOWN, KEEP CLIMBING 41/100 Risk Identification Threat intelligence feeds identification by: AEncrypting dataβ OFF COURSESmall detour β back on course with this:Knowing current adversary behavior helps identify realistic scenarios. BAdvertising productsβ OFF COURSESmall detour β back on course with this:Knowing current adversary behavior helps identify realistic scenarios. CRevealing attacker techniques and campaigns relevant to your industry and technologyβ RISK UNDERSTOODYou just reasoned like a risk professional.Knowing current adversary behavior helps identify realistic scenarios. DReplacing controlsβ OFF COURSESmall detour β back on course with this:Knowing current adversary behavior helps identify realistic scenarios. 42/100 Risk Identification Interviewing business process owners during identification helps because: AThey approve budgetsβ RECHECK THE MAPNo losses in practice. Log the lesson:Process owners see impact pathways that IT staff alone may miss. BThey know process dependencies and what failures would actually disruptβ COURSE CONFIRMEDThat's the answer a seasoned analyst would give.Process owners see impact pathways that IT staff alone may miss. CThey write firewall rulesβ RECHECK THE MAPNo losses in practice. Log the lesson:Process owners see impact pathways that IT staff alone may miss. DIt fills calendarsβ RECHECK THE MAPNo losses in practice. Log the lesson:Process owners see impact pathways that IT staff alone may miss. 43/100 Risk Identification Which change should trigger fresh risk identification? AFixing a typoβ EXPOSURE MISSEDAdjust your heading with this insight:Material change introduces new assets, dependencies, and exposure. BA staff birthdayβ EXPOSURE MISSEDAdjust your heading with this insight:Material change introduces new assets, dependencies, and exposure. CA new office plantβ EXPOSURE MISSEDAdjust your heading with this insight:Material change introduces new assets, dependencies, and exposure. DAdopting a new cloud service, major system, or business processβ APPETITE ALIGNEDYou're building the foundation every risk career stands on.Material change introduces new assets, dependencies, and exposure. 44/100 Risk Identification A near-miss (incident with no loss) should be: ACelebrated onlyβ RECALIBRATEFundamentals take reps. Here's the takeaway:Near-misses are free lessons about real weaknesses. BDeleted from recordsβ RECALIBRATEFundamentals take reps. Here's the takeaway:Near-misses are free lessons about real weaknesses. CCaptured and analyzed as evidence of a risk that nearly materializedβ SCENARIO MAPPEDSolid fundamentals β that's a future CRISC talking.Near-misses are free lessons about real weaknesses. DIgnored β no harm doneβ RECALIBRATEFundamentals take reps. Here's the takeaway:Near-misses are free lessons about real weaknesses. 45/100 Risk Identification Emerging risk identification looks at: AOnly current problemsβ REVIEW THE BASICSSmall detour β back on course with this:Scanning the horizon lets the organization prepare before risk fully forms. BLast centuryβ REVIEW THE BASICSSmall detour β back on course with this:Scanning the horizon lets the organization prepare before risk fully forms. CSolved issuesβ REVIEW THE BASICSSmall detour β back on course with this:Scanning the horizon lets the organization prepare before risk fully forms. DDeveloping trends β new technologies, threats, and regulations that may create future exposureβ IMPACT MEASUREDExactly right. Risk thinking is becoming instinct.Scanning the horizon lets the organization prepare before risk fully forms. 46/100 Risk Identification Shadow IT complicates identification because: AIt is always compliantβ OFF COURSENo losses in practice. Log the lesson:Unknown services are unidentified risk carriers. BUnsanctioned tools hold data and access outside the inventory and assessment processβ RESPONSE CHOSENClear-eyed and correct. Oluma loves to see it.Unknown services are unidentified risk carriers. CIt reduces spendingβ OFF COURSENo losses in practice. Log the lesson:Unknown services are unidentified risk carriers. DIt improves visibilityβ OFF COURSENo losses in practice. Log the lesson:Unknown services are unidentified risk carriers. 47/100 Risk Identification Vulnerability scanning contributes to identification by: ABlocking attackersβ RECHECK THE MAPAdjust your heading with this insight:Scans surface exploitable conditions β raw material for risk scenarios. BFixing weaknesses automaticallyβ RECHECK THE MAPAdjust your heading with this insight:Scans surface exploitable conditions β raw material for risk scenarios. CReplacing risk registersβ RECHECK THE MAPAdjust your heading with this insight:Scans surface exploitable conditions β raw material for risk scenarios. DDiscovering technical weaknesses that could become risk scenarios when paired with threatsβ INDICATOR GREENYou just reasoned like a risk professional.Scans surface exploitable conditions β raw material for risk scenarios. 48/100 Risk Identification Dependency mapping (systems, vendors, data flows) helps identify: AEmail signaturesβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Understanding dependencies reveals where one failure cascades. BParking issuesβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Understanding dependencies reveals where one failure cascades. CSingle points of failure and third-party exposure that could disrupt business processesβ LESSON LOGGEDThat's the answer a seasoned analyst would give.Understanding dependencies reveals where one failure cascades. DFont conflictsβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Understanding dependencies reveals where one failure cascades. 49/100 Risk Identification Who should participate in risk identification? AOnly executivesβ RECALIBRATESmall detour β back on course with this:Diverse perspectives catch risks any single group would miss. BOnly auditorsβ RECALIBRATESmall detour β back on course with this:Diverse perspectives catch risks any single group would miss. COnly the risk teamβ RECALIBRATESmall detour β back on course with this:Diverse perspectives catch risks any single group would miss. DA cross-section: business owners, IT, security, legal, and others with relevant knowledgeβ BEARINGS TRUEYou're building the foundation every risk career stands on.Diverse perspectives catch risks any single group would miss. 50/100 Risk Identification The output of identification is typically recorded in: AA chat messageβ REVIEW THE BASICSNo losses in practice. Log the lesson:The register is the system of record feeding assessment and treatment. BThe risk register with scenario descriptions and provisional ownersβ REGISTER CURRENTSolid fundamentals β that's a future CRISC talking.The register is the system of record feeding assessment and treatment. CA private notebookβ REVIEW THE BASICSNo losses in practice. Log the lesson:The register is the system of record feeding assessment and treatment. DNowhereβ REVIEW THE BASICSNo losses in practice. Log the lesson:The register is the system of record feeding assessment and treatment. CHECKPOINT β 50 DOWN, KEEP CLIMBING 51/100 Risk Identification Which is an example of a project-related IT risk to identify? AA completed milestoneβ OFF COURSEAdjust your heading with this insight:Change initiatives carry delivery and disruption risk worth identifying early. BA team lunchβ OFF COURSEAdjust your heading with this insight:Change initiatives carry delivery and disruption risk worth identifying early. CA signed contractβ OFF COURSEAdjust your heading with this insight:Change initiatives carry delivery and disruption risk worth identifying early. DA critical system migration that could fail, overrun, or disrupt operations at cutoverβ RISK UNDERSTOODExactly right. Risk thinking is becoming instinct.Change initiatives carry delivery and disruption risk worth identifying early. 52/100 Risk Assessment & Analysis Risk assessment determines: AMarketing budgetsβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Assessment turns a list of risks into a prioritized, decision-ready picture. BWho is firedβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Assessment turns a list of risks into a prioritized, decision-ready picture. CThe significance of identified risks β usually via likelihood and impact β to support prioritizationβ COURSE CONFIRMEDClear-eyed and correct. Oluma loves to see it.Assessment turns a list of risks into a prioritized, decision-ready picture. DSalariesβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Assessment turns a list of risks into a prioritized, decision-ready picture. 53/100 Risk Assessment & Analysis Qualitative assessment uses: ADescriptive scales (e.g., High/Medium/Low) and expert judgmentβ APPETITE ALIGNEDYou just reasoned like a risk professional.Qualitative methods rate risks with scales rather than calculated currency values. BMonte Carlo onlyβ EXPOSURE MISSEDSmall detour β back on course with this:Qualitative methods rate risks with scales rather than calculated currency values. CStock pricesβ EXPOSURE MISSEDSmall detour β back on course with this:Qualitative methods rate risks with scales rather than calculated currency values. DMonetary formulas onlyβ EXPOSURE MISSEDSmall detour β back on course with this:Qualitative methods rate risks with scales rather than calculated currency values. 54/100 Risk Assessment & Analysis Quantitative assessment expresses risk in: AAdjectivesβ RECALIBRATENo losses in practice. Log the lesson:Quantitative analysis calculates values like SLE, ARO, and ALE. BColorsβ RECALIBRATENo losses in practice. Log the lesson:Quantitative analysis calculates values like SLE, ARO, and ALE. CEmojisβ RECALIBRATENo losses in practice. Log the lesson:Quantitative analysis calculates values like SLE, ARO, and ALE. DNumeric terms β typically expected monetary lossβ SCENARIO MAPPEDThat's the answer a seasoned analyst would give.Quantitative analysis calculates values like SLE, ARO, and ALE. 55/100 Risk Assessment & Analysis An asset worth $500,000 would lose 40% of its value in a specific incident. The SLE is: A$500,000β REVIEW THE BASICSAdjust your heading with this insight:SLE = asset value Γ exposure factor = $500,000 Γ 0.40 = $200,000. B$200,000β IMPACT MEASUREDYou're building the foundation every risk career stands on.SLE = asset value Γ exposure factor = $500,000 Γ 0.40 = $200,000. C$125,000β REVIEW THE BASICSAdjust your heading with this insight:SLE = asset value Γ exposure factor = $500,000 Γ 0.40 = $200,000. D$40,000β REVIEW THE BASICSAdjust your heading with this insight:SLE = asset value Γ exposure factor = $500,000 Γ 0.40 = $200,000. 56/100 Risk Assessment & Analysis If SLE is $200,000 and the event is expected once every 5 years (ARO 0.2), the ALE is: A$4,000β OFF COURSEFundamentals take reps. Here's the takeaway:ALE = SLE Γ ARO = $200,000 Γ 0.2 = $40,000 per year. B$40,000β RESPONSE CHOSENSolid fundamentals β that's a future CRISC talking.ALE = SLE Γ ARO = $200,000 Γ 0.2 = $40,000 per year. C$1,000,000β OFF COURSEFundamentals take reps. Here's the takeaway:ALE = SLE Γ ARO = $200,000 Γ 0.2 = $40,000 per year. D$200,000β OFF COURSEFundamentals take reps. Here's the takeaway:ALE = SLE Γ ARO = $200,000 Γ 0.2 = $40,000 per year. 57/100 Risk Assessment & Analysis ALE is most useful for: AComparing annualized risk cost against the cost of controlsβ INDICATOR GREENExactly right. Risk thinking is becoming instinct.Annualized figures support cost-benefit decisions about treatment. BSetting passwordsβ RECHECK THE MAPSmall detour β back on course with this:Annualized figures support cost-benefit decisions about treatment. CNaming serversβ RECHECK THE MAPSmall detour β back on course with this:Annualized figures support cost-benefit decisions about treatment. DScheduling meetingsβ RECHECK THE MAPSmall detour β back on course with this:Annualized figures support cost-benefit decisions about treatment. 58/100 Risk Assessment & Analysis Inherent risk is assessed: ANeverβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Inherent risk sets the baseline; controls reduce it to residual. BAfter all controlsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Inherent risk sets the baseline; controls reduce it to residual. COnly by vendorsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Inherent risk sets the baseline; controls reduce it to residual. DBefore considering controls β the raw exposureβ LESSON LOGGEDClear-eyed and correct. Oluma loves to see it.Inherent risk sets the baseline; controls reduce it to residual. 59/100 Risk Assessment & Analysis Residual risk is: ARisk before controlsβ RECALIBRATEAdjust your heading with this insight:Residual risk is what the organization actually lives with β compared against appetite. BA type of auditβ RECALIBRATEAdjust your heading with this insight:Residual risk is what the organization actually lives with β compared against appetite. CThe risk remaining after controls are appliedβ BEARINGS TRUEYou just reasoned like a risk professional.Residual risk is what the organization actually lives with β compared against appetite. DAlways zeroβ RECALIBRATEAdjust your heading with this insight:Residual risk is what the organization actually lives with β compared against appetite. 60/100 Risk Assessment & Analysis A heat map plots risks by: ALikelihood and impactβ REGISTER CURRENTThat's the answer a seasoned analyst would give.The two classic assessment dimensions form the map's axes. BTeam and officeβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:The two classic assessment dimensions form the map's axes. CAge and ownerβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:The two classic assessment dimensions form the map's axes. DCost and vendorβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:The two classic assessment dimensions form the map's axes. CHECKPOINT β 60 DOWN, KEEP CLIMBING 61/100 Risk Assessment & Analysis A risk rated low-likelihood but catastrophic-impact should be: AEvaluated against appetite β severe tail risks may still demand treatmentβ RISK UNDERSTOODYou're building the foundation every risk career stands on.Impact-heavy risks can be unacceptable even when unlikely. BAveraged awayβ OFF COURSESmall detour β back on course with this:Impact-heavy risks can be unacceptable even when unlikely. CDeletedβ OFF COURSESmall detour β back on course with this:Impact-heavy risks can be unacceptable even when unlikely. DAutomatically ignoredβ OFF COURSESmall detour β back on course with this:Impact-heavy risks can be unacceptable even when unlikely. 62/100 Risk Assessment & Analysis Why do qualitative ratings need defined criteria (what 'High' means)? AFonts varyβ RECHECK THE MAPNo losses in practice. Log the lesson:Shared definitions make judgment repeatable instead of arbitrary. BSo ratings are consistent and comparable across assessors and timeβ COURSE CONFIRMEDSolid fundamentals β that's a future CRISC talking.Shared definitions make judgment repeatable instead of arbitrary. CTo lengthen documentsβ RECHECK THE MAPNo losses in practice. Log the lesson:Shared definitions make judgment repeatable instead of arbitrary. DCriteria are decorativeβ RECHECK THE MAPNo losses in practice. Log the lesson:Shared definitions make judgment repeatable instead of arbitrary. 63/100 Risk Assessment & Analysis Control effectiveness influences assessment because: AControls are irrelevantβ EXPOSURE MISSEDAdjust your heading with this insight:Real mitigation depends on controls actually operating as intended. BEffectiveness is unmeasurableβ EXPOSURE MISSEDAdjust your heading with this insight:Real mitigation depends on controls actually operating as intended. CWeak or failing controls mean residual risk is higher than the paper design suggestsβ APPETITE ALIGNEDExactly right. Risk thinking is becoming instinct.Real mitigation depends on controls actually operating as intended. DControls only affect budgetsβ EXPOSURE MISSEDAdjust your heading with this insight:Real mitigation depends on controls actually operating as intended. 64/100 Risk Assessment & Analysis A business impact analysis (BIA) primarily identifies: AServer brandsβ RECALIBRATEFundamentals take reps. Here's the takeaway:BIA grounds availability-related assessment and recovery objectives (RTO/RPO). BSalary bandsβ RECALIBRATEFundamentals take reps. Here's the takeaway:BIA grounds availability-related assessment and recovery objectives (RTO/RPO). CCritical processes and the consequences of their disruption over timeβ SCENARIO MAPPEDClear-eyed and correct. Oluma loves to see it.BIA grounds availability-related assessment and recovery objectives (RTO/RPO). DMarketing slogansβ RECALIBRATEFundamentals take reps. Here's the takeaway:BIA grounds availability-related assessment and recovery objectives (RTO/RPO). 65/100 Risk Assessment & Analysis Which factor increases the likelihood of a risk scenario? AStrong compensating controlsβ REVIEW THE BASICSSmall detour β back on course with this:Likelihood grows when capable threats meet accessible weaknesses. BEffective patchingβ REVIEW THE BASICSSmall detour β back on course with this:Likelihood grows when capable threats meet accessible weaknesses. CNetwork segmentationβ REVIEW THE BASICSSmall detour β back on course with this:Likelihood grows when capable threats meet accessible weaknesses. DAn active threat, high exposure, and an exploitable vulnerabilityβ IMPACT MEASUREDYou just reasoned like a risk professional.Likelihood grows when capable threats meet accessible weaknesses. 66/100 Risk Assessment & Analysis Assessments should be repeated when: AOnly after a breachβ OFF COURSENo losses in practice. Log the lesson:Risk moves; stale assessments misinform decisions. BThe register is fullβ OFF COURSENo losses in practice. Log the lesson:Risk moves; stale assessments misinform decisions. CSignificant change occurs or periodically as threats and business conditions evolveβ RESPONSE CHOSENThat's the answer a seasoned analyst would give.Risk moves; stale assessments misinform decisions. DNeverβ OFF COURSENo losses in practice. Log the lesson:Risk moves; stale assessments misinform decisions. 67/100 Risk Assessment & Analysis Single-point estimates ('this will cost exactly $1M') can mislead because: AEstimates are always rightβ RECHECK THE MAPAdjust your heading with this insight:Expressing uncertainty prevents false precision from driving bad decisions. BNumbers are evilβ RECHECK THE MAPAdjust your heading with this insight:Expressing uncertainty prevents false precision from driving bad decisions. CExecutives prefer decimalsβ RECHECK THE MAPAdjust your heading with this insight:Expressing uncertainty prevents false precision from driving bad decisions. DThey hide uncertainty β ranges or scenarios represent possible outcomes more honestlyβ INDICATOR GREENYou're building the foundation every risk career stands on.Expressing uncertainty prevents false precision from driving bad decisions. 68/100 Risk Assessment & Analysis The primary output of assessment is: AA new logoβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Assessment ends with prioritization that response planning consumes. BA firewall ruleβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Assessment ends with prioritization that response planning consumes. CA prioritized view of risks with ratings that inform response decisionsβ LESSON LOGGEDSolid fundamentals β that's a future CRISC talking.Assessment ends with prioritization that response planning consumes. DA press releaseβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:Assessment ends with prioritization that response planning consumes. 69/100 Risk Response The four classic risk response options are: AAccept, avoid, mitigate, transferβ BEARINGS TRUEExactly right. Risk thinking is becoming instinct.Treatment choices: accept, avoid, mitigate (reduce), transfer (share). BLog, alert, block, reportβ RECALIBRATESmall detour β back on course with this:Treatment choices: accept, avoid, mitigate (reduce), transfer (share). CDeny, delay, defer, deleteβ RECALIBRATESmall detour β back on course with this:Treatment choices: accept, avoid, mitigate (reduce), transfer (share). DPlan, do, check, actβ RECALIBRATESmall detour β back on course with this:Treatment choices: accept, avoid, mitigate (reduce), transfer (share). 70/100 Risk Response Implementing MFA to reduce account compromise likelihood is: AMitigationβ REGISTER CURRENTClear-eyed and correct. Oluma loves to see it.Controls that reduce likelihood or impact are mitigation. BAcceptanceβ REVIEW THE BASICSNo losses in practice. Log the lesson:Controls that reduce likelihood or impact are mitigation. CTransferβ REVIEW THE BASICSNo losses in practice. Log the lesson:Controls that reduce likelihood or impact are mitigation. DAvoidanceβ REVIEW THE BASICSNo losses in practice. Log the lesson:Controls that reduce likelihood or impact are mitigation. CHECKPOINT β 70 DOWN, KEEP CLIMBING 71/100 Risk Response Cancelling a project because its risk exceeds its value is: AAvoidanceβ RISK UNDERSTOODYou just reasoned like a risk professional.Avoidance eliminates exposure by not doing the risky thing. BMitigationβ OFF COURSEAdjust your heading with this insight:Avoidance eliminates exposure by not doing the risky thing. CTransferβ OFF COURSEAdjust your heading with this insight:Avoidance eliminates exposure by not doing the risky thing. DAcceptanceβ OFF COURSEAdjust your heading with this insight:Avoidance eliminates exposure by not doing the risky thing. 72/100 Risk Response Purchasing cyber insurance is: ATransfer / sharingβ COURSE CONFIRMEDThat's the answer a seasoned analyst would give.Insurance shifts part of the financial consequence to another party. BAcceptanceβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Insurance shifts part of the financial consequence to another party. CMitigationβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Insurance shifts part of the financial consequence to another party. DAvoidanceβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Insurance shifts part of the financial consequence to another party. 73/100 Risk Response Documenting a decision to live with a minor risk is: AAcceptanceβ APPETITE ALIGNEDYou're building the foundation every risk career stands on.Acceptance is a conscious, recorded decision to retain risk within appetite. BTransferβ EXPOSURE MISSEDSmall detour β back on course with this:Acceptance is a conscious, recorded decision to retain risk within appetite. CAvoidanceβ EXPOSURE MISSEDSmall detour β back on course with this:Acceptance is a conscious, recorded decision to retain risk within appetite. DMitigationβ EXPOSURE MISSEDSmall detour β back on course with this:Acceptance is a conscious, recorded decision to retain risk within appetite. 74/100 Risk Response Risk acceptance should be made by: AAn outside vendorβ RECALIBRATENo losses in practice. Log the lesson:Acceptance authority must match the potential impact being retained. BThe newest hireβ RECALIBRATENo losses in practice. Log the lesson:Acceptance authority must match the potential impact being retained. CAn owner with authority appropriate to the risk's sizeβ SCENARIO MAPPEDSolid fundamentals β that's a future CRISC talking.Acceptance authority must match the potential impact being retained. DAnyone availableβ RECALIBRATENo losses in practice. Log the lesson:Acceptance authority must match the potential impact being retained. 75/100 Risk Response After outsourcing a process, accountability for its risks: ARemains with the organization even though activities transferredβ IMPACT MEASUREDExactly right. Risk thinking is becoming instinct.You can delegate work, not accountability to customers and regulators. BDisappearsβ REVIEW THE BASICSAdjust your heading with this insight:You can delegate work, not accountability to customers and regulators. CBelongs to the regulatorβ REVIEW THE BASICSAdjust your heading with this insight:You can delegate work, not accountability to customers and regulators. DMoves entirely to the vendorβ REVIEW THE BASICSAdjust your heading with this insight:You can delegate work, not accountability to customers and regulators. 76/100 Risk Response A control costing $300k/year that prevents $50k/year of expected loss is: AA bargainβ OFF COURSEFundamentals take reps. Here's the takeaway:Cost-benefit analysis keeps treatment proportionate to exposure. BMandatoryβ OFF COURSEFundamentals take reps. Here's the takeaway:Cost-benefit analysis keeps treatment proportionate to exposure. CDisproportionate β response cost should be weighed against risk reductionβ RESPONSE CHOSENClear-eyed and correct. Oluma loves to see it.Cost-benefit analysis keeps treatment proportionate to exposure. DFreeβ OFF COURSEFundamentals take reps. Here's the takeaway:Cost-benefit analysis keeps treatment proportionate to exposure. 77/100 Risk Response When residual risk still exceeds appetite after treatment, the organization should: ADeclare successβ RECHECK THE MAPSmall detour β back on course with this:Above-appetite residual risk demands more action or a deliberate, authorized acceptance. BRedefine mathβ RECHECK THE MAPSmall detour β back on course with this:Above-appetite residual risk demands more action or a deliberate, authorized acceptance. CApply further treatment or escalate for explicit senior acceptanceβ INDICATOR GREENYou just reasoned like a risk professional.Above-appetite residual risk demands more action or a deliberate, authorized acceptance. DHide the resultβ RECHECK THE MAPSmall detour β back on course with this:Above-appetite residual risk demands more action or a deliberate, authorized acceptance. 78/100 Risk Response Combining responses (mitigate + transfer + accept the remainder) is: ACommon and sensible for significant risksβ LESSON LOGGEDThat's the answer a seasoned analyst would give.Layered treatment tailors each portion of the risk to the best-fit response. BForbiddenβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Layered treatment tailors each portion of the risk to the best-fit response. COnly for small firmsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Layered treatment tailors each portion of the risk to the best-fit response. DRandomβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Layered treatment tailors each portion of the risk to the best-fit response. 79/100 Risk Response An action plan for mitigation should include: AA named owner, actions, resources, and target datesβ BEARINGS TRUEYou're building the foundation every risk career stands on.Executable plans have accountability, steps, means, and deadlines. BOnly a budget codeβ RECALIBRATEAdjust your heading with this insight:Executable plans have accountability, steps, means, and deadlines. CNothing writtenβ RECALIBRATEAdjust your heading with this insight:Executable plans have accountability, steps, means, and deadlines. DVague hopesβ RECALIBRATEAdjust your heading with this insight:Executable plans have accountability, steps, means, and deadlines. 80/100 Risk Response A compensating control is used when: ARisk is zeroβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Compensating controls deliver comparable risk reduction by another route. BAuditors are absentβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Compensating controls deliver comparable risk reduction by another route. CNothing else exists to doβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Compensating controls deliver comparable risk reduction by another route. DThe preferred control is infeasible, so an alternative achieving similar protection is appliedβ REGISTER CURRENTSolid fundamentals β that's a future CRISC talking.Compensating controls deliver comparable risk reduction by another route. CHECKPOINT β 80 DOWN, KEEP CLIMBING 81/100 Risk Response Ignoring a known risk without a decision differs from acceptance because: AIgnoring is cheaper and fineβ OFF COURSESmall detour β back on course with this:Unconscious risk retention bypasses governance β the opposite of managed acceptance. BThey are identicalβ OFF COURSESmall detour β back on course with this:Unconscious risk retention bypasses governance β the opposite of managed acceptance. CAcceptance is illegalβ OFF COURSESmall detour β back on course with this:Unconscious risk retention bypasses governance β the opposite of managed acceptance. DAcceptance is informed, authorized, and documented; ignoring is unmanaged exposureβ RISK UNDERSTOODExactly right. Risk thinking is becoming instinct.Unconscious risk retention bypasses governance β the opposite of managed acceptance. 82/100 Risk Response Accepting a risk that violates a legal requirement is: AStandard practiceβ RECHECK THE MAPNo losses in practice. Log the lesson:Legal duties constrain response choices; noncompliance can't be 'accepted.' BThe regulator's problemβ RECHECK THE MAPNo losses in practice. Log the lesson:Legal duties constrain response choices; noncompliance can't be 'accepted.' CA valid business choiceβ RECHECK THE MAPNo losses in practice. Log the lesson:Legal duties constrain response choices; noncompliance can't be 'accepted.' DNot a legitimate option β compliance obligations must be metβ COURSE CONFIRMEDClear-eyed and correct. Oluma loves to see it.Legal duties constrain response choices; noncompliance can't be 'accepted.' 83/100 Risk Response After implementing a response, the organization should: ADelete the register entryβ EXPOSURE MISSEDAdjust your heading with this insight:Validation confirms the treatment achieved the intended reduction. BVerify the control operates effectively and reassess residual riskβ APPETITE ALIGNEDYou just reasoned like a risk professional.Validation confirms the treatment achieved the intended reduction. CStop monitoringβ EXPOSURE MISSEDAdjust your heading with this insight:Validation confirms the treatment achieved the intended reduction. DAssume it works foreverβ EXPOSURE MISSEDAdjust your heading with this insight:Validation confirms the treatment achieved the intended reduction. 84/100 Risk Response Risk avoidance has a hidden cost when: AIt never doesβ RECALIBRATEFundamentals take reps. Here's the takeaway:Over-avoidance trades away benefit; response choice should weigh opportunity, not just danger. BValue is irrelevantβ RECALIBRATEFundamentals take reps. Here's the takeaway:Over-avoidance trades away benefit; response choice should weigh opportunity, not just danger. CThe avoided activity would have created significant value β excessive avoidance sacrifices opportunityβ SCENARIO MAPPEDThat's the answer a seasoned analyst would give.Over-avoidance trades away benefit; response choice should weigh opportunity, not just danger. DAvoidance is freeβ RECALIBRATEFundamentals take reps. Here's the takeaway:Over-avoidance trades away benefit; response choice should weigh opportunity, not just danger. 85/100 Risk Monitoring & Reporting The purpose of risk monitoring is to: AClose the risk programβ REVIEW THE BASICSSmall detour β back on course with this:Monitoring keeps the risk picture current between formal assessments. BCreate paperworkβ REVIEW THE BASICSSmall detour β back on course with this:Monitoring keeps the risk picture current between formal assessments. CTrack whether risk levels, controls, and treatments remain effective as conditions changeβ IMPACT MEASUREDYou're building the foundation every risk career stands on.Monitoring keeps the risk picture current between formal assessments. DReplace assessmentsβ REVIEW THE BASICSSmall detour β back on course with this:Monitoring keeps the risk picture current between formal assessments. 86/100 Risk Monitoring & Reporting A Key Risk Indicator (KRI) provides: AA firewall ruleβ OFF COURSENo losses in practice. Log the lesson:KRIs are forward-looking metrics tied to risk drivers. BAn org chartβ OFF COURSENo losses in practice. Log the lesson:KRIs are forward-looking metrics tied to risk drivers. CEarly warning that exposure to a specific risk is changingβ RESPONSE CHOSENSolid fundamentals β that's a future CRISC talking.KRIs are forward-looking metrics tied to risk drivers. DA passwordβ OFF COURSENo losses in practice. Log the lesson:KRIs are forward-looking metrics tied to risk drivers. 87/100 Risk Monitoring & Reporting Which is a reasonable KRI for phishing risk? ATrend in employees clicking simulated phishing linksβ INDICATOR GREENExactly right. Risk thinking is becoming instinct.Click-rate trends signal changing human-layer exposure. BPrinter ink levelsβ RECHECK THE MAPAdjust your heading with this insight:Click-rate trends signal changing human-layer exposure. CHoliday countβ RECHECK THE MAPAdjust your heading with this insight:Click-rate trends signal changing human-layer exposure. DNumber of desksβ RECHECK THE MAPAdjust your heading with this insight:Click-rate trends signal changing human-layer exposure. 88/100 Risk Monitoring & Reporting A KRI differs from a KPI in that a KRI measures: AEmployee satisfaction onlyβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:KPIs track performance; KRIs track risk signals. BRevenue onlyβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:KPIs track performance; KRIs track risk signals. CChanging risk exposure / early warning of potential problemsβ LESSON LOGGEDClear-eyed and correct. Oluma loves to see it.KPIs track performance; KRIs track risk signals. DAchievement of performance goalsβ EXPOSURE MISSEDFundamentals take reps. Here's the takeaway:KPIs track performance; KRIs track risk signals. 89/100 Risk Monitoring & Reporting KRIs need thresholds because: AColors look niceβ RECALIBRATESmall detour β back on course with this:An indicator without an action trigger is just a chart. BAuditors count themβ RECALIBRATESmall detour β back on course with this:An indicator without an action trigger is just a chart. CMetrics expireβ RECALIBRATESmall detour β back on course with this:An indicator without an action trigger is just a chart. DThresholds define when escalation and action are triggeredβ BEARINGS TRUEYou just reasoned like a risk professional.An indicator without an action trigger is just a chart. 90/100 Risk Monitoring & Reporting A KRI breaches its threshold and nothing happens for months. The failure is in: AThe response process β monitoring must connect to accountable actionβ REGISTER CURRENTThat's the answer a seasoned analyst would give.Monitoring without response is theater; escalation paths must work. BThe threshold being too visibleβ REVIEW THE BASICSNo losses in practice. Log the lesson:Monitoring without response is theater; escalation paths must work. CNothingβ REVIEW THE BASICSNo losses in practice. Log the lesson:Monitoring without response is theater; escalation paths must work. DThe metric's fontβ REVIEW THE BASICSNo losses in practice. Log the lesson:Monitoring without response is theater; escalation paths must work. CHECKPOINT β 90 DOWN, KEEP CLIMBING 91/100 Risk Monitoring & Reporting The risk register during the monitoring phase should be: AFrozen after creationβ OFF COURSEAdjust your heading with this insight:A current register is the backbone of meaningful reporting. BPrivate to one personβ OFF COURSEAdjust your heading with this insight:A current register is the backbone of meaningful reporting. CDeleted annuallyβ OFF COURSEAdjust your heading with this insight:A current register is the backbone of meaningful reporting. DA living record β updated as treatments progress, risks change, and new risks appearβ RISK UNDERSTOODYou're building the foundation every risk career stands on.A current register is the backbone of meaningful reporting. 92/100 Risk Monitoring & Reporting Risk reporting to senior leadership should be framed in: ARiddlesβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Executives act on business meaning, not packet captures. BDeep technical jargonβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Executives act on business meaning, not packet captures. CRaw log filesβ RECHECK THE MAPFundamentals take reps. Here's the takeaway:Executives act on business meaning, not packet captures. DBusiness terms β impact on objectives, trends, and decisions neededβ COURSE CONFIRMEDSolid fundamentals β that's a future CRISC talking.Executives act on business meaning, not packet captures. 93/100 Risk Monitoring & Reporting Trend information in risk reports matters because: ADirection shows whether exposure is improving or worsening and whether treatments workβ APPETITE ALIGNEDExactly right. Risk thinking is becoming instinct.A snapshot without trajectory hides whether things are getting better or worse. BIt fills slidesβ EXPOSURE MISSEDSmall detour β back on course with this:A snapshot without trajectory hides whether things are getting better or worse. CTrends are decorativeβ EXPOSURE MISSEDSmall detour β back on course with this:A snapshot without trajectory hides whether things are getting better or worse. DStatus is always sufficientβ EXPOSURE MISSEDSmall detour β back on course with this:A snapshot without trajectory hides whether things are getting better or worse. 94/100 Risk Monitoring & Reporting An out-of-cycle (immediate) risk report is warranted when: ANothing changesβ RECALIBRATENo losses in practice. Log the lesson:Material changes can't wait for the scheduled deck. BThe quarter endsβ RECALIBRATENo losses in practice. Log the lesson:Material changes can't wait for the scheduled deck. CA printer jamsβ RECALIBRATENo losses in practice. Log the lesson:Material changes can't wait for the scheduled deck. DA material event occurs β major incident, KRI breach, or significant new threatβ SCENARIO MAPPEDClear-eyed and correct. Oluma loves to see it.Material changes can't wait for the scheduled deck. 95/100 Risk Monitoring & Reporting Monitoring control effectiveness means: AReading vendor brochuresβ REVIEW THE BASICSAdjust your heading with this insight:Controls decay; periodic verification keeps residual-risk estimates honest. BCounting controlsβ REVIEW THE BASICSAdjust your heading with this insight:Controls decay; periodic verification keeps residual-risk estimates honest. CAssuming controls workβ REVIEW THE BASICSAdjust your heading with this insight:Controls decay; periodic verification keeps residual-risk estimates honest. DTesting and observing whether controls operate as designed over timeβ IMPACT MEASUREDYou just reasoned like a risk professional.Controls decay; periodic verification keeps residual-risk estimates honest. 96/100 Risk Monitoring & Reporting Lessons from incidents should feed monitoring and reporting by: AUpdating risk ratings, revealing control gaps, and improving KRIsβ RESPONSE CHOSENThat's the answer a seasoned analyst would give.Incidents are ground truth that recalibrates the risk picture. BAssigning blame onlyβ OFF COURSEFundamentals take reps. Here's the takeaway:Incidents are ground truth that recalibrates the risk picture. CClosing the registerβ OFF COURSEFundamentals take reps. Here's the takeaway:Incidents are ground truth that recalibrates the risk picture. DBeing forgottenβ OFF COURSEFundamentals take reps. Here's the takeaway:Incidents are ground truth that recalibrates the risk picture. 97/100 Risk Monitoring & Reporting Reporting that shows only successes and hides worsening risks causes: ABetter morale foreverβ RECHECK THE MAPSmall detour β back on course with this:Honest reporting is the whole point; filtered good news breaks governance. BLeadership decisions based on a false picture β the core failure of risk reportingβ INDICATOR GREENYou're building the foundation every risk career stands on.Honest reporting is the whole point; filtered good news breaks governance. CFaster auditsβ RECHECK THE MAPSmall detour β back on course with this:Honest reporting is the whole point; filtered good news breaks governance. DNothingβ RECHECK THE MAPSmall detour β back on course with this:Honest reporting is the whole point; filtered good news breaks governance. 98/100 Risk Monitoring & Reporting Who consumes risk reports? ANobodyβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Reporting is tiered: detail for operators, aggregated insight for governance. BOnly regulatorsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Reporting is tiered: detail for operators, aggregated insight for governance. CMultiple audiences β operational owners, management, committees, and the board β each needing appropriate detailβ LESSON LOGGEDSolid fundamentals β that's a future CRISC talking.Reporting is tiered: detail for operators, aggregated insight for governance. DOnly auditorsβ EXPOSURE MISSEDNo losses in practice. Log the lesson:Reporting is tiered: detail for operators, aggregated insight for governance. 99/100 Risk Monitoring & Reporting Continuous monitoring tools (dashboards fed by scans, logs, and configs) add value by: AProviding timely, consistent risk-state data at a scale manual checks cannot matchβ BEARINGS TRUEExactly right. Risk thinking is becoming instinct.Automation enables the currency and coverage that periodic manual checks lack. BEliminating human judgmentβ RECALIBRATEAdjust your heading with this insight:Automation enables the currency and coverage that periodic manual checks lack. CReplacing governanceβ RECALIBRATEAdjust your heading with this insight:Automation enables the currency and coverage that periodic manual checks lack. DLooking modernβ RECALIBRATEAdjust your heading with this insight:Automation enables the currency and coverage that periodic manual checks lack. 100/100 Risk Monitoring & Reporting The risk management lifecycle is circular because: ACircles are elegantβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Risk management is continuous: monitor, learn, reassess, re-treat. BIt ends after responseβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Risk management is continuous: monitor, learn, reassess, re-treat. CRegulators require circlesβ REVIEW THE BASICSFundamentals take reps. Here's the takeaway:Risk management is continuous: monitor, learn, reassess, re-treat. DMonitoring findings feed back into identification and assessment as conditions changeβ REGISTER CURRENTClear-eyed and correct. Oluma loves to see it.Risk management is continuous: monitor, learn, reassess, re-treat. JOURNEY COMPLETE β FUNDAMENTALS LOCKED INEvery expert was once a beginner who kept practicing. Oluma is proud to walk this road with you. RISKS MANAGED REVIEWED These are original practice questions written for the Oluma community. IT Risk Fundamentalsβ’ is a certificate program of ISACA. Oluma is not affiliated with or endorsed by ISACA. No official exam content is reproduced here.