Risk 25% Flashcards
Which of the following tables are in the GRC: Risk Scope? (Select all that apply)
a. Issue
b. Risk Framework
c. Risk Statement
d. Citation
b. Risk Framework
c. Risk Statement
A risk statement can be created outside of a Risk Framework
a. Yes
b. No
a. Yes
- Risk Statements can reference more than one Risk Framework
a. Yes
b. No
b. No
- What are the 3 Risk Score Types?
a. Qualitative
b. Residual
c. Quantitative
d. Calculated
e. Inherent
b. Residual
d. Calculated
e. Inherent
Default values for Inherent and Residual risks are entered on the Risk Statement
a. Yes
b. No
a. Yes
Calculated Risk scores appear one the Risk once it is generated
a. Yes
b. No
a. Yes
- Which of the following are Risk Score Methods? Choose 2
a. Calculated
b. Quantitative
c. Single Loss Expectancy
d. Qualitative
e. Likelihood
b. Quantitative
d. Qualitative
- Which of the following are components of a Risk Score? Choose 4
a. Annualized Rate of Occurrence (ARO)
b. Likelihood
c. Annualized Loss Expectancy (SLE)
d. Score
e. Impact
f. Single Loss Expectancy (ALE)
b. Likelihood
d. Score
e. Impact
f. Single Loss Expectancy (ALE)
For Calculated Risk, only the ALE and Risk score exist
a. Yes
b. No
a. Yes
Can you nest or stack Risk Frameworks?
a. Yes
b. No
a. No
Can you nest or stack Risk Statements?
a. Yes
b. No
a. Yes
Only if using the Advanced Risk application.
Can a Risk Manager update Entity Types and Entities?
a. Yes
b. No
a. Yes
Entity Types can be applied at what level to generate Registered Risks?
A. Risk Framework
b. Risk Statement / Risk Template
c. Both
c. Both
A risk response if automatically generated when the type of response is saved.
a. Yes
b. No
a. Yes
Data from the ServiceNow Security Operations applications can impact a Risk.
a. Yes
b. No
a. Yes