Free Certified in Risk and Information Systems Control practice — 6 questions on IT Risk Assessment, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 2: IT Risk Assessment
A risk practitioner is calculating the annualized loss expectancy (ALE) for a data center outage. The asset value is $2,000,000, the exposure factor (EF) is 30%, and the annualized rate of occurrence (ARO) is 0.5. What is the ALE?
Single loss expectancy (SLE) = Asset Value × EF = $2,000,000 × 0.30 = $600,000. ALE = SLE × ARO = $600,000 × 0.5 = $300,000.
Question 2 of 6 · Domain 2: IT Risk Assessment
A risk practitioner identifies a risk of unauthorized access to customer financial data. The IT security team subsequently configures and manages the access control lists that mitigate this risk. Who should be assigned as the risk owner in the risk register?
The risk owner is the individual accountable for ensuring the risk is managed to an acceptable level — typically the business process or asset owner, since they bear the consequences of the risk materializing, not the party who merely implements technical controls.
Question 3 of 6 · Domain 2: IT Risk Assessment
An organization is evaluating risk associated with adopting an emerging AI technology for which no historical loss data or industry loss benchmarks exist. Management needs a risk rating communicated to the board within one week. Which risk analysis approach is MOST appropriate?
Qualitative analysis using a likelihood/impact matrix does not require reliable historical or statistical data and can be performed quickly using expert judgment, making it the most appropriate approach when data is unavailable and time is constrained.
Question 4 of 6 · Domain 2: IT Risk Assessment
A risk register currently records the risk statement, risk owner, and inherent risk rating for each entry. Which additional attribute is MOST essential to correctly derive the residual risk rating from the inherent risk rating?
Residual risk is derived by adjusting the inherent risk rating based on the effectiveness of existing controls; without a documented control effectiveness assessment, the register cannot demonstrate how residual risk was calculated from inherent risk.
Question 5 of 6 · Domain 2: IT Risk Assessment
An organization's inherent risk rating for a payment-processing process has remained unchanged for two consecutive years. However, recent internal audit reports show a growing number of control testing failures for the key controls associated with this process. What is the MOST likely conclusion regarding residual risk?
Residual risk is a function of both inherent risk and control effectiveness; a decline in control effectiveness — evidenced by increasing testing failures — increases residual risk even when the underlying inherent risk rating stays constant.
Question 6 of 6 · Domain 2: IT Risk Assessment
A business impact analysis determines that the maximum tolerable downtime (MTD) for an order-processing system is 24 hours. The recovery time objective (RTO) for restoring system functionality is set at 18 hours, and the estimated work recovery time (WRT) needed to fully resume normal business operations after systems are technically restored is 8 hours. What should the risk practitioner conclude?
Total recovery time must include both the RTO and the WRT; here 18 + 8 = 26 hours, which exceeds the 24-hour MTD, meaning the organization would exceed the point of unacceptable business impact even though the system itself is technically recovered within the RTO.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.