A15.1 — Risk Management in Cybersecurity
Risk vocabulary, business context, inherent vs. residual risk, treatment options, ownership, evidence, uncertainty.
A15 — Risk Management and Compliance
This assessment checks whether you can reason across the entire A15 module: risk context, analysis, ownership, registers, controls, compliance, evidence, exceptions, suppliers, leadership communication, and enterprise risk decisions.
The questions use fictional, defensive scenarios only. Answers stay hidden until you interact with the quiz component.
Readiness Check
0/5 ready
Assessment Coverage
Risk vocabulary, business context, inherent vs. residual risk, treatment options, ownership, evidence, uncertainty.
Risk scenario construction, impact, likelihood, uncertainty, business dependencies.
Risk register purpose, ownership, status, treatment, milestones, review, closure.
Control purpose, design effectiveness, operating effectiveness, compensating controls, evidence.
Frameworks, applicability, mappings, compliance vs. security, exceptions.
Relevance, freshness, contradiction, sufficiency, traceability.
Acceptance, expiry, compensating controls, bounded governance.
Criticality, concentration, assurance, continuity, business dependency.
Business translation, executive briefs, recommendations, evidence confidence.
Integrated enterprise risk decisions across controls, evidence, governance, suppliers, and ownership.
Module Test
Read each scenario carefully. Many questions are designed to test whether you can distinguish technical activity from business risk, control presence from control effectiveness, compliance from security, and historical approval from current governance.
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Performance Guide
You can integrate risk, controls, evidence, compliance, ownership, suppliers, exceptions, and leadership decisions with strong consistency.
Next action: Proceed to the next Advanced module after reviewing any missed questions.
You understand the module well, with a few areas that need targeted review.
Next action: Review the lesson areas connected to missed questions, then retry the test.
You understand the main concepts but are not yet applying them consistently across enterprise scenarios.
Next action: Use the targeted review map below and revisit the related portfolio artifacts.
Several A15 concepts need stronger understanding before moving forward.
Next action: Revisit A15.1–A15.10 in order, especially risk ownership, control effectiveness, evidence, exceptions, and decision states.
Targeted Review Map
Missed
Questions 1–3
Revisit
A15.1 and A15.2
Focus
Risk scenarios, business context, inherent/residual risk, impact, likelihood, uncertainty.
Missed
Questions 4–6
Revisit
A15.3
Focus
Risk register purpose, owner roles, decision states, review triggers, closure evidence.
Missed
Questions 7–10
Revisit
A15.4
Focus
Design effectiveness, operating effectiveness, control coverage, compensating controls, evidence.
Missed
Questions 11–13
Revisit
A15.5
Focus
Compliance vs. security, applicability, mapping, exceptions, Partially Met/Compensating states.
Missed
Questions 14–16
Revisit
A15.6
Focus
Evidence relevance, sufficiency, freshness, contradiction, traceability, workpapers.
Missed
Questions 17–19
Revisit
A15.7
Focus
Risk acceptance, expiry, approval authority, bounded exceptions, residual risk.
Missed
Questions 20–22
Revisit
A15.8
Focus
Supplier criticality, concentration risk, assurance, continuity, exit planning.
Missed
Questions 23–24
Revisit
A15.9
Focus
Leadership risk briefs, business-language translation, recommendations, evidence confidence.
Missed
Question 25
Revisit
A15.10
Focus
Integrated enterprise risk decisions and how all A15 artifacts connect.
Portfolio Connection
Your final A15 portfolio outcome is the Risk Register and Leadership Recommendation, assembled through the Enterprise Risk Decision Package in A15.10. It should connect business context, risk records, controls, compliance mappings, evidence, exceptions, third-party risk, leadership briefs, and final decision records.
Cyber Risk Context Map
Risk Analysis Worksheet
Cybersecurity Risk Register
Control Effectiveness Review
Framework and Control Mapping Register
Audit Evidence Register
Risk Acceptance and Exception Register
Third-Party Risk Review
Leadership Risk Brief
Enterprise Risk Decision Package
Defender Habits
Key Takeaways
Assessment Safety Boundary
This test does not require scanning, probing, exploitation, credential access, bypassing controls, investigating real vendors, or collecting confidential organizational evidence. All scenarios, systems, suppliers, controls, risks, and decisions are fictional.
Module Complete
After completing the test and reviewing any missed concepts, you will have finished the A15 learning sequence: ten lessons, ten portfolio artifacts, one integrated Enterprise Risk Decision Package, and the 25-question module assessment.