Michigan IT Risk Management Specialist
Exam Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
Pdf
1. Which of the following best defines risk appetite in an IT risk
management context?
A. The total number of risks an organization has identified
B. The level of risk an organization is willing to accept
2. C. The amount of financial loss a company has already experienced
due to risk
D. The maximum severity of risk events that have occurred in the last
assessment
Correct answer bolded.
A clear risk appetite helps determine which risks are acceptable and
which require mitigation based on organizational strategy.
3. What is the primary purpose of a risk register?
A. To list all employees responsible for risk management
B. To record identified risks and their attributes C. To document
technology inventory items
D. To track system performance metrics
Correct answer bolded.
A risk register centralizes risk information including likelihood,
impact, owner, and mitigation status.
4. In a qualitative risk assessment, which two factors are most commonly
evaluated?
A. Cost and schedule variance
, B. Availability and confidentiality
C. Likelihood and impact D. Detection and prevention
Correct answer bolded.
Likelihood and impact are the primary dimensions used to prioritize
risks qualitatively.
5. A control that prevents unauthorized access to a network by requiring
credentials is an example of what type of control?
A. Detective
B. Corrective
C. Preventive
D. Compensatory
Correct answer bolded.
Preventive controls act to stop risk events before they occur by
limiting exposures.
6. Which standard framework is widely used for IT risk management
globally?
A. ITIL
B. ISO/IEC 27005
C. COBIT 4.1
D. TOGAF
Correct answer bolded.
ISO/IEC 27005 provides guidance on information security risk
management practices.
7. What does the term residual risk refer to?
A. Risk that will never occur
B. Risk remaining after controls are applied
C. Risk only identified in audits
D. Risk transferred to a third party
Correct answer bolded.
Residual risk exists even after mitigation efforts due to imperfect
controls.
8. Which analysis technique quantifies risk using numerical values for
likelihood and impact?
A. SWOT
B. Quantitative risk assessment
, C. Brainstorming
D. Delphi
Correct answer bolded.
Quantitative approaches assign specific numeric scales for more
precise prioritization and cost-benefit analysis.
9. A Business Impact Analysis (BIA) primarily informs which risk metric?
A. Likelihood
B. Impact
C. Control effectiveness
D. Incident response time
Correct answer bolded.
BIA assesses potential consequences of disruptions to critical
business functions.
10. In risk matrix terminology, a risk rated as “High” likelihood and
“Low” impact would typically be:
A. Critical
B. Moderate
C. Medium priority
D. Low priority
Correct answer bolded.
High likelihood but low impact often results in moderate
management attention.
11. The NIST Risk Management Framework (RMF) includes how
many core steps?
A. Four
B. Five
C. Six
D. Seven
Correct answer bolded.
The NIST RMF consists of six steps: Categorize, Select, Implement,
Assess, Authorize, Monitor.
12. Which control type detects undesirable outcomes after they
occur?
A. Preventive
B. Corrective
Exam Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
1. Which of the following best defines risk appetite in an IT risk
management context?
A. The total number of risks an organization has identified
B. The level of risk an organization is willing to accept
2. C. The amount of financial loss a company has already experienced
due to risk
D. The maximum severity of risk events that have occurred in the last
assessment
Correct answer bolded.
A clear risk appetite helps determine which risks are acceptable and
which require mitigation based on organizational strategy.
3. What is the primary purpose of a risk register?
A. To list all employees responsible for risk management
B. To record identified risks and their attributes C. To document
technology inventory items
D. To track system performance metrics
Correct answer bolded.
A risk register centralizes risk information including likelihood,
impact, owner, and mitigation status.
4. In a qualitative risk assessment, which two factors are most commonly
evaluated?
A. Cost and schedule variance
, B. Availability and confidentiality
C. Likelihood and impact D. Detection and prevention
Correct answer bolded.
Likelihood and impact are the primary dimensions used to prioritize
risks qualitatively.
5. A control that prevents unauthorized access to a network by requiring
credentials is an example of what type of control?
A. Detective
B. Corrective
C. Preventive
D. Compensatory
Correct answer bolded.
Preventive controls act to stop risk events before they occur by
limiting exposures.
6. Which standard framework is widely used for IT risk management
globally?
A. ITIL
B. ISO/IEC 27005
C. COBIT 4.1
D. TOGAF
Correct answer bolded.
ISO/IEC 27005 provides guidance on information security risk
management practices.
7. What does the term residual risk refer to?
A. Risk that will never occur
B. Risk remaining after controls are applied
C. Risk only identified in audits
D. Risk transferred to a third party
Correct answer bolded.
Residual risk exists even after mitigation efforts due to imperfect
controls.
8. Which analysis technique quantifies risk using numerical values for
likelihood and impact?
A. SWOT
B. Quantitative risk assessment
, C. Brainstorming
D. Delphi
Correct answer bolded.
Quantitative approaches assign specific numeric scales for more
precise prioritization and cost-benefit analysis.
9. A Business Impact Analysis (BIA) primarily informs which risk metric?
A. Likelihood
B. Impact
C. Control effectiveness
D. Incident response time
Correct answer bolded.
BIA assesses potential consequences of disruptions to critical
business functions.
10. In risk matrix terminology, a risk rated as “High” likelihood and
“Low” impact would typically be:
A. Critical
B. Moderate
C. Medium priority
D. Low priority
Correct answer bolded.
High likelihood but low impact often results in moderate
management attention.
11. The NIST Risk Management Framework (RMF) includes how
many core steps?
A. Four
B. Five
C. Six
D. Seven
Correct answer bolded.
The NIST RMF consists of six steps: Categorize, Select, Implement,
Assess, Authorize, Monitor.
12. Which control type detects undesirable outcomes after they
occur?
A. Preventive
B. Corrective