You are the project manager for TTP project. You are in the Identify Risks process. You have to create the risk register. Which of the following are included in the risk register? Each correct answer represents a complete solution. Choose two.
Correct Answer: A,D,E
is incorrect. Risk register do contain the summary of mitigation, but only after the applying risk response. Here in this scenario you are in risk identification phase, hence mitigation techniques cannot be documented at this situation. Answer:B is incorrect. This is not valid content of risk register. A risk register is an inventory of risks and exposure associated with those risks. Risks are commonly found in project management practices, and provide information to identify, analyze, and manage risks. Typically a risk register contains: A description of the risk The impact should this event actually occur The probability of its occurrence Risk Score (the multiplication of Probability and Impact) A summary of the planned response should the event occur A summary of the mitigation (the actions taken in advance to reduce the probability and/or impact of the event) Ranking of risks by Risk Score so as to highlight the highest priority risks to all involved.
Question 237
Which of the following is the MOST important aspect to ensure that an accurate risk register is maintained?
Correct Answer: A
is incorrect. Business process owners typically cannot effectively identify risk to their business processes. They may not have the ability to be unbiased and may not have the appropriate skills or tools for evaluating risks. Answer:B is incorrect. Audit personnel may not have the appropriate business knowledge in risk assessment, hence cannot properly identify risk. Regular audits may also cause hindrance to the business activities. Answer:D is incorrect. Monitoring key risk indicators, and record the findings in the risk register will only provide insights to known and identified risk and will not account for obscure risk, i.e. , risk that has not been identified yet.
Question 238
Which of the following are risk components of the COSO ERM framework? Each correct answer represents a complete solution. Choose three.
Correct Answer: A,B,D,E
is incorrect. Business continuity is not considered as risk component within the ERM framework.
Question 239
What is the process for selecting and implementing measures to impact risk called?
Correct Answer: A
is incorrect. The process of analyzing and evaluating risk is called risk assessment.
Question 240
Which of the following is the GREATEST risk associated with the misclassification of data?