ANSWERS, AND DETAILED RATIONALES GRADE A+ ASSURED
SECTION 1: RISK MANAGEMENT & BUSINESS CONTINUITY (Questions 1-25)
Q1. Which process involves assessing and identifying the potential effects of
disruptions to a business operation?
A) Risk Appetite Analysis
B) Business Continuity Planning
C) Business Impact Analysis (BIA)
D) Disaster Recovery Planning
Answer: C
,Rationale: A Business Impact Analysis (BIA) is a process that assesses and
identifies the potential effects of disruptions to a business operation. It helps
organizations understand the consequences of interruptions to critical business
functions and informs recovery strategies .
Q2. What term describes a component or system that, if it fails, will cause the
entire system to fail?
A) Redundant System
B) Critical Path
C) Single Point of Failure (SPOF)
D) Bottleneck
Answer: C
Rationale: A Single Point of Failure (SPOF) is a component or system that, if it fails,
will cause the entire system to fail. Identifying and eliminating SPOFs is a key goal
in designing resilient cloud architectures .
,Q3. Which type of risk assessment uses specific numerical values to evaluate
risks?
A) Qualitative
B) Comparative
C) Subjective
D) Quantitative
Answer: D
Rationale: Quantitative risk assessment uses specific numerical values (e.g.,
monetary amounts, probabilities, percentages) to evaluate risks, allowing for
objective comparisons and cost-benefit analyses .
Q4. A risk assessment method that uses non-numerical categories like high,
medium, and low is known as:
, A) Quantitative
B) Predictive
C) Statistical
D) Qualitative
Answer: D
Rationale: Qualitative risk assessment uses non-numerical categories that are
relative in nature, such as high, medium, and low. This approach is often faster
and easier to implement than quantitative assessments .
Q5. What is the term for the level, amount, or type of risk that an organization
finds acceptable?
A) Risk Tolerance