Risk Identification
Risk Assessment & Analysis
Risk Management Tools & Strategies
Business Impact & Organizational Risk Posture
100

What risk identification method gathers stakeholders together to list potential risks?

What is brainstorming?

100

What type of risk assessment is conducted only when needed, usually due to major changes or events?


What is an ad hoc risk assessment?

100

What document stores all identified risks, their characteristics, owners, and mitigation plans?


What is a risk register?

100

What metric represents the maximum acceptable downtime for restoring a system or process?


What is the Recovery Time Objective (RTO)?

200

What type of analysis examines Strengths, Weaknesses, Opportunities, and Threats to identify risks?


What is a SWOT analysis?

200

What type of risk analysis uses descriptive terms like “low,” “medium,” and “high” instead of numbers?


What is qualitative risk analysis?

200

What risk management strategy shifts the risk to a third party, such as through insurance or contracts?


What is risk transfer?

200

What metric defines the maximum allowable amount of data loss measured in time?


What is the Recovery Point Objective (RPO)?

300

What method identifies risks by examining project plans, reports, and historical information?


What is a documentation review?

300

What does SLE stand for in quantitative risk analysis?


What is Single Loss Expectancy?

300

Who is assigned responsibility for managing, monitoring, and mitigating each risk in the risk register?


Who are the risk owners?

300

What metric represents the average time needed to repair a system after a failure?


What is Mean Time to Repair (MTTR)?

400

What technique creates “what-if” scenarios to identify possible risks and outcomes?


What is scenario analysis?

400

To calculate ALE, you multiply SLE by this value.


What is the Annualized Rate of Occurrence (ARO)?

400

What strategy eliminates the risk entirely by choosing not to engage in a certain activity?


What is risk avoidance?

400

What term describes the amount and type of risk an organization is willing to pursue or accept?


What is risk appetite?

500

What method investigates past incidents to find underlying causes that may reveal future risks?

What is root cause analysis?

500

This percentage represents the portion of asset loss in a risk event and is needed to calculate SLE.


What is the Exposure Factor?

500

What are measurable signals used to detect early warning signs of worsening risk conditions?


What are Key Risk Indicators (KRIs)?

500

What metric refers to the average time between system or component failures?


What is Mean Time Between Failures (MTBF)?

M
e
n
u