IT-Risk-Fundamentals ISACA IT Risk Fundamentals Certificate Practice Questions
Prepare for IT-Risk-Fundamentals with more than an answer.
- Exam fee
- $275 USD
- Level
- Fundamentals
- Valid for
- No expiration
Domains covered on the exam 6
- Risk Introduction and Overview5%
- Risk Governance and Management15%
- Risk Identification20%
- Risk Assessment and Analysis25%
- Risk Response15%
- Risk Monitoring, Reporting and Communication20%
- 1
A hospital is performing a risk assessment on its new electronic health record (EHR) system. The risk team needs to perform a quantitative analysis of a data breach scenario. Which of the following inputs are required to calculate the Single Loss Expectancy (SLE)? (Select ALL that apply)
Show answer details
Correct answer: A, B
The Asset Value (AV) is a critical component of the SLE calculation. It represents the total value of the asset being assessed (in this case, the EHR data).
The Exposure Factor (EF) is the percentage of the asset's value that is expected to be lost in a single incident. It is the second required component for the SLE calculation.
- 2
Case Study
'HelioEnergy' is a rapidly growing renewable energy provider. The company's board of directors has established a very low risk appetite for any event that could cause a power grid outage or endanger public safety. The company's SCADA (Supervisory Control and Data Acquisition) systems, which control the energy grid, are managed by the Operations Technology (OT) department. The IT department manages the corporate network.
An internal audit finds that the OT and IT departments operate in silos. The OT department, focused on uptime, rarely applies security patches to the SCADA systems, fearing service interruptions. The IT department, focused on security, has a rigorous patching policy for the corporate network. There is no unified risk governance committee to oversee both domains, and each department sets its own risk tolerance levels.
What is the most significant risk governance failure described in this scenario?
Show answer details
Correct answer: C
This is the core governance failure. The scenario describes a classic case of organizational silos where different departments (IT and OT) make independent and conflicting risk decisions. The OT department's high tolerance for security risk directly contradicts the board's low appetite for outage risk. A proper enterprise risk governance structure would unify oversight, establish consistent policies, and ensure that departmental actions align with the strategic objectives and risk appetite set by the board.
- 3
A business unit wants to launch a new product that requires processing sensitive customer data in a way that may violate certain data privacy regulations. The risk committee must decide how to proceed. Which factor is the MOST important for the committee to consider?
Show answer details
Correct answer: B
This is the most critical factor. The organization's risk appetite statement for compliance and legal matters provides the guiding principles for this decision. Most organizations have a very low, or zero, appetite for breaking the law. The decision must be aligned with this strategic directive from the board and senior leadership, which often outweighs the potential financial gains of a non-compliant activity.
- 4
What is the primary difference between a Key Risk Indicator (KRI) and a Key Performance Indicator (KPI)?
Show answer details
Correct answer: B
This is the core difference. KRIs are forward-looking metrics designed to provide early warnings that a risk exposure may be increasing (e.g., 'increase in phishing email clicks'). KPIs are backward-looking, measuring performance against a target and indicating how well a process has performed in the past (e.g., '99.9% system uptime achieved').
- 5
A university's IT department is conducting a risk assessment on its student information system. They identify a vulnerability where former student workers' access credentials are not always revoked in a timely manner. The threat is that a disgruntled former worker could use these credentials to access and alter student grades. This relationship is an example of a:
Show answer details
Correct answer: B
This is the most accurate description. The risk exists because a specific threat (a disgruntled former worker) can exploit a specific vulnerability (unrevoked credentials) to cause an impact. The combination of a threat and a vulnerability that can be exploited by that threat creates the risk.
- 6
A global logistics company is analyzing the financial impact of a potential data breach in its primary shipping database. The asset value (AV) of the database is estimated at $5,000,000. Historical data from similar incidents suggest a 20% loss of asset value if a breach occurs (Exposure Factor). Based on threat intelligence, an attack of this nature is expected to succeed once every four years. What is the Annualized Loss Expectancy (ALE) for this scenario?
Show answer details
Correct answer: B
The calculation is as follows: First, find the Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF), which is $5,000,000 * 0.20 = $1,000,000. Next, determine the Annualized Rate of Occurrence (ARO), which is 1 incident / 4 years = 0.25. Finally, calculate the Annualized Loss Expectancy (ALE) = SLE * ARO, which is $1,000,000 * 0.25 = $250,000.
- 7
A risk analyst at a manufacturing firm is preparing a report for senior management. The analyst has identified that a critical control system for the assembly line has no failover capability, making it a single point of failure. Which of the following is the MOST appropriate way to document this in the risk register?
Show answer details
Correct answer: C
This is the most comprehensive and appropriate risk statement. It clearly links the threat (system failure) and the vulnerability (lack of failover) to the specific business impact (production stoppage, financial loss, delays). This format provides the necessary context for risk assessment and response planning.
- 8
A financial services firm is implementing a continuous monitoring program for its IT risks. The CISO wants to create Key Risk Indicators (KRIs) to provide early warnings of increasing risk levels. Which TWO of the following would be the MOST effective KRIs for monitoring the risk of unauthorized access to sensitive client data? (Select TWO)
Show answer details
Correct answer: B, D
This is an excellent KRI. A rising percentage indicates a breakdown in access control processes, which directly increases the risk of unauthorized access through stale or inappropriate privileged accounts. It is a leading indicator of potential future incidents.
This is a strong KRI because a spike in this metric provides an early warning of a potential brute-force or credential stuffing attack in progress. It allows the security team to react before a successful breach occurs, making it a leading indicator.
- 9
A non-profit organization relies on a third-party cloud provider for all its donor management and financial systems. A risk assessment identifies a significant risk of service unavailability due to a potential provider outage. The organization has a very limited budget and cannot afford to switch providers or implement a multi-cloud strategy. What is the MOST appropriate risk response strategy in this situation?
Show answer details
Correct answer: B
Risk mitigation involves taking action to reduce the likelihood or impact of the risk. Even with a limited budget, the organization can implement mitigating controls such as developing a robust incident response plan, performing regular data backups to a separate, low-cost location, and negotiating stronger Service Level Agreements (SLAs) with the provider. This is the most proactive and appropriate response.
- 10
True or False: In a qualitative risk assessment, a risk with a 'High' impact and a 'Low' probability should always be prioritized for treatment over a risk with a 'Medium' impact and a 'High' probability.
Show answer details
Correct answer: B
This statement is false. Risk prioritization is determined by the overall risk rating, which is a combination of impact and probability. An organization's risk matrix might rate a 'Medium Impact / High Probability' risk as 'High' overall, while rating a 'High Impact / Low Probability' risk as 'Medium' overall. The prioritization depends entirely on the specific risk matrix and risk appetite defined by the organization.
