High School AdvancedA15 Module Test25 Questions

A15 — Risk Management and Compliance

Module Test

This assessment checks whether you can reason across the entire A15 module: risk context, analysis, ownership, registers, controls, compliance, evidence, exceptions, suppliers, leadership communication, and enterprise risk decisions.

The questions use fictional, defensive scenarios only. Answers stay hidden until you interact with the quiz component.

Readiness Check

A15 Module Test Readiness

0/5 ready

Assessment Coverage

What the 25 Questions Measure

A15.1 — Risk Management in Cybersecurity

Risk vocabulary, business context, inherent vs. residual risk, treatment options, ownership, evidence, uncertainty.

Questions 1–4

A15.2 — Assets, Threats, Impact, and Likelihood

Risk scenario construction, impact, likelihood, uncertainty, business dependencies.

Questions 1–3

A15.3 — Risk Registers and Ownership

Risk register purpose, ownership, status, treatment, milestones, review, closure.

Questions 4–6

A15.4 — Security Controls and Control Testing

Control purpose, design effectiveness, operating effectiveness, compensating controls, evidence.

Questions 7–10

A15.5 — Compliance Framework Concepts

Frameworks, applicability, mappings, compliance vs. security, exceptions.

Questions 11–13

A15.6 — Audit Evidence and Documentation

Relevance, freshness, contradiction, sufficiency, traceability.

Questions 14–16

A15.7 — Risk Acceptance and Exceptions

Acceptance, expiry, compensating controls, bounded governance.

Questions 17–19

A15.8 — Third-Party Risk Concepts

Criticality, concentration, assurance, continuity, business dependency.

Questions 20–22

A15.9 — Communicating Risk to Leaders

Business translation, executive briefs, recommendations, evidence confidence.

Questions 23–24

A15.10 — Risk Decision Lab

Integrated enterprise risk decisions across controls, evidence, governance, suppliers, and ownership.

Questions 25

Module Test

25 Questions — Risk Management and Compliance

Read each scenario carefully. Many questions are designed to test whether you can distinguish technical activity from business risk, control presence from control effectiveness, compliance from security, and historical approval from current governance.

Check Your Understanding

A15 Module Test: Risk Management and Compliance

Choose your answers first. Explanations appear only after submission.

1. Which statement best describes cybersecurity risk?

2. Which combination best forms a useful risk scenario?

3. What is the difference between inherent risk and residual risk?

4. Who should normally own the business decision about residual risk?

5. What is the strongest purpose of a cybersecurity risk register?

6. When should a risk normally be Closed?

7. What is design effectiveness?

8. What is operating effectiveness?

9. A control is well designed, but current evidence is incomplete across the full intended population. What is the strongest conclusion?

10. What is a compensating control?

11. Which statement best describes the relationship between compliance and security?

12. What should a framework or compliance mapping include?

13. What is strongest for an approved exception to a preferred control requirement?

14. What makes audit evidence relevant?

15. What should happen when credible evidence sources contradict each other?

16. Which statement about evidence freshness is strongest?

17. What is risk acceptance?

18. What should happen when an exception reaches its expiry date?

19. Which statement about Accepted Risk is strongest?

20. What makes a supplier critical?

21. What is concentration risk?

22. Which statement about supplier assurance is strongest?

23. What should a leadership risk brief usually lead with?

24. What should a leadership recommendation include besides the preferred action?

25. Which is the strongest basis for an enterprise risk decision?

Performance Guide

How to Interpret Your Result

23–25 correctAdvanced Ready

You can integrate risk, controls, evidence, compliance, ownership, suppliers, exceptions, and leadership decisions with strong consistency.

Next action: Proceed to the next Advanced module after reviewing any missed questions.

20–22 correctStrong

You understand the module well, with a few areas that need targeted review.

Next action: Review the lesson areas connected to missed questions, then retry the test.

16–19 correctDeveloping

You understand the main concepts but are not yet applying them consistently across enterprise scenarios.

Next action: Use the targeted review map below and revisit the related portfolio artifacts.

0–15 correctRebuild the Foundations

Several A15 concepts need stronger understanding before moving forward.

Next action: Revisit A15.1–A15.10 in order, especially risk ownership, control effectiveness, evidence, exceptions, and decision states.

Targeted Review Map

Use Missed Questions to Find the Right Lesson

Missed

Questions 1–3

Revisit

A15.1 and A15.2

Focus

Risk scenarios, business context, inherent/residual risk, impact, likelihood, uncertainty.

Missed

Questions 4–6

Revisit

A15.3

Focus

Risk register purpose, owner roles, decision states, review triggers, closure evidence.

Missed

Questions 7–10

Revisit

A15.4

Focus

Design effectiveness, operating effectiveness, control coverage, compensating controls, evidence.

Missed

Questions 11–13

Revisit

A15.5

Focus

Compliance vs. security, applicability, mapping, exceptions, Partially Met/Compensating states.

Missed

Questions 14–16

Revisit

A15.6

Focus

Evidence relevance, sufficiency, freshness, contradiction, traceability, workpapers.

Missed

Questions 17–19

Revisit

A15.7

Focus

Risk acceptance, expiry, approval authority, bounded exceptions, residual risk.

Missed

Questions 20–22

Revisit

A15.8

Focus

Supplier criticality, concentration risk, assurance, continuity, exit planning.

Missed

Questions 23–24

Revisit

A15.9

Focus

Leadership risk briefs, business-language translation, recommendations, evidence confidence.

Missed

Question 25

Revisit

A15.10

Focus

Integrated enterprise risk decisions and how all A15 artifacts connect.

Portfolio Connection

What A15 Should Leave in Your Portfolio

Your final A15 portfolio outcome is the Risk Register and Leadership Recommendation, assembled through the Enterprise Risk Decision Package in A15.10. It should connect business context, risk records, controls, compliance mappings, evidence, exceptions, third-party risk, leadership briefs, and final decision records.

1

Cyber Risk Context Map

2

Risk Analysis Worksheet

3

Cybersecurity Risk Register

4

Control Effectiveness Review

5

Framework and Control Mapping Register

6

Audit Evidence Register

7

Risk Acceptance and Exception Register

8

Third-Party Risk Review

9

Leadership Risk Brief

10

Enterprise Risk Decision Package

Defender Habits

A15 Final Readiness Checklist

Key Takeaways

What You Should Remember

1.Cybersecurity risk is about uncertainty around business objectives, not technical severity alone.
2.Risk ownership, control ownership, remediation ownership, and evidence ownership are different responsibilities.
3.Risk registers should support decisions, treatment, review, escalation, and closure.
4.Control design and control operation must be evaluated separately.
5.Compliance status does not automatically determine residual business risk.
6.Evidence should be relevant, sufficient, current, attributable, traceable, and honest about limitations.
7.Risk acceptance and exceptions require authority, scope, evidence, review, and expiry or triggers.
8.Supplier assurance and supplier concentration are different risk dimensions.
9.Leadership communication should explain business consequence, confidence, options, recommendation, ownership, and residual risk.
10.Enterprise risk decisions are strongest when business, technical, governance, supplier, evidence, and ownership context are integrated.

Assessment Safety Boundary

A15 remains defensive, fictional, and governance-focused

This test does not require scanning, probing, exploitation, credential access, bypassing controls, investigating real vendors, or collecting confidential organizational evidence. All scenarios, systems, suppliers, controls, risks, and decisions are fictional.

Module Complete

A15 — Risk Management and Compliance

After completing the test and reviewing any missed concepts, you will have finished the A15 learning sequence: ten lessons, ten portfolio artifacts, one integrated Enterprise Risk Decision Package, and the 25-question module assessment.