Match the word to the appropriate sentence to complete the risk response definition.
A) An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B) This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C) When an entity responds to risk with ________, the entity takes no action to affect risk
likelihood or risk impact.
D) This risk response involves ________ or exiting the activities that give rise to the risk.
14) Avoiding
Diff: 2
Objective: Q12.3 What do I need to know about COSO’s ERM Cube components?
15) Reduce
Diff: 2
Objective: Q12.3 What do I need to know about COSO’s ERM Cube components?
16) Sharing
Diff: 2
Objective: Q12.3 What do I need to know about COSO’s ERM Cube components?
17) Acceptance
Diff: 2
Objective: Q12.3 What do I need to know about COSO’s ERM Cube components?
Match the IT control activity to the appropriate enterprise level.
A) IT governance
B) Business processes
C) IT processes and services
18) Entity-level IT controls
19) Application controls
20) IT general controls
Diff: 2
Objective: Q12.3 What do I need to know about COSO’s ERM Cube components?
21) Hiring competent employees who are provided ongoing training
A) Can increase risks from accidents and errors
B) Can increase the amount of fraud
C) Can reduce risks from accidents and errors
D) Can reduce an enterprise’s risk tolerance
22) Which of the following is NOT an external factor that might affect an enterprise’s ability to
achieve objectives?
A) Economic events
B) Natural environment
C) Processes
D) Political events
23) Which of the following is both an internal and external factor that might affect an enterprise’s
ability to achieve objectives?
A) Infrastructures
B) Technology events
C) Economic events
D) Social events
24) Operation objectives relate to
A) The reliability of both internal and external reports, including both financial and nonfinancial
information
B) The effective and efficient use of the entity’s resources
C) An entity’s compliance with applicable laws and regulations
D) An entity’s ability to mitigate risk
25) Which of the following is NOT an incident or occurrence that originates outside an
organization?
A) Changes in consumer demographics
B) New legislation
C) Employee competence
D) Liquidity factors
26) Which of the following is an incident or occurrence that originates inside an organization?
A) Changes in regulations
B) Data integrity
C) New technology
D) Product competition
27) Which question pertains to assessing risk likelihood?
A) What is the estimated frequency of the threat occurring?
B) What is the asset’s value?
C) What is the estimated potential loss per threat?
D) How much is the asset worth to the competition?
28) Qualitative measures include
A) Means
B) Regression
C) Percentages
D) Ranking likelihood
29) Which of the following is NOT considered a control activity?
A) Locked door
B) Performance reviews
C) Event identification
D) Segregation of duties
30) What is risk tolerance? Provide an example.
31) What are five external events that may pose a risk to an enterprise‘s ability to achieve
objectives? Provide examples.
32) What are four internal events that may pose a risk to an enterprise’s ability to achieve
objectives? Provide examples.
33) Assessment techniques used to assess risk are grouped into two categories. What are these
categories? Define each.
34) What are the four risk response categories? Include a definition of each.
1) ISO 13000 is not the only internationally accepted enterprise risk management standard.
2) The risk time frame ________ relates to the organization’s strategy, affecting three to five
years or longer.
3) The risk time frame ________ related to tactics, such as new projects that initiate change.
4) The risk time frame ________relates to operations and routine activities.
5) Which risk time frame relates to tactics, such as new projects that initiate change?
A) Short term
B) Medium term
C) Long term
D) Intermediate term
6) Which risk time frame relates to operations and routine activities?
A) Short term
B) Medium term
C) Long term
D) Intermediate term
7) Which of the 7Rs of risk management listed below pertains to risk assessment?
A) Reaction planning
B) Rank
C) Resource controls
D) Report and monitor risk performance
8) Which of the following is NOT one of the 4Ts of risk management?
A) Treat risk
B) Terminate risk
C) Transform risk
D) Transfer risk
9) List the 7Rs and 4Ts of risk management.
1) Focusing on sustainable operations increases the risk of dependence on dwindling natural
resources that may become cost prohibitive in the future.
2) Effective implementation of ERM requires a robust discussion of the potential impact of not
mitigating risks and the likelihood that the risk will impact the organization.
3) ________ practices offer a solution to reduce risk.
4) ________ involves evaluating and determining which IT applications and related systems
should be included in IT compliance review.
5) Focusing on sustainable operations reduces the risk of
A) Dependence on dwindling natural resources
B) Inflation
C) Economic downturns
D) Dependence on vendors
6) Whether enterprise risk management is effective and sustainable depends upon
A) The economy
B) The weakest link in the system
C) Consumer demands
D) How transparent the enterprise is with shareholders
7) In an IT compliance road map, what type of deficiencies may be found and how are they
prioritized?
8) How can IT build sustainability into IT controls?
1) Spreadsheets introduce significant risks into the financial reporting process for organizations.
2) Storing the spreadsheet on the server increases the difficulty to track changes made by
multiple users.
3) The use of access security controls on spreadsheets is not an effective method to improve
spreadsheet risk management.
4) A ________ log tracks who is accessing the specific spreadsheet.
5) The ________ log documents the date of the update, user making the updates, the type of
updates (for example, formulas), update specifications, and what initiated the update.
6) What percentage of CFOs rely heavily on Microsoft Excel spreadsheets for financial tasks?
A) 87%
B) 92%
C) 83%
D) 94%
7) Which of the following is NOT one of the top 10 tips for improving spreadsheet risk
management?
A) Store all spreadsheets on a network server.
B) Implement spreadsheet change logs (user log and change log).
C) Add a contents tab to the spreadsheet to create a spreadsheet table of contents.
D) Create an error log for each spreadsheet.
8) Which of the following information would NOT appear on a documentation tab in a
spreadsheet?
A) Developer notes
B) User instructions
C) List of users that accessed the spreadsheet
D) Authorized uses
9) What is the purpose of requiring a spreadsheet user log and change log?
10) A co-worker complains to you about being required to store all spreadsheets on a network
server. How do you explain the purpose of storing the spreadsheets on the network?
11) The company where you work is implementing risk management for spreadsheets. This
includes adding a user log and change log to each spreadsheet. A co worker complains to you
about having this information attached to spreadsheets. How do you explain the purpose of the
these logs?
12) The company where you work is considering requiring a documentation tab to every
spreadsheet as part of spreadsheet risk management. You are asked to make recommendations
regarding the contents of the documentation tab. What type of information would you
recommend?
13) The company where you work is considering requiring a contents tab to every spreadsheet as
part of spreadsheet risk management. You are asked to make recommendations regarding the
contents of the contents tab. What type of information would you recommend?