Multiple Choice Questions:
1. Program alteration is an example of which of the following?
a. An active vulnerability.
b. A passive vulnerability.
c. An active threat.
d. A passive threat.

2. Which of the following does gap analysis primarily identify?
a. Controls that are in place but not working.
b. Controls that are not already in place.
c. Controls that may already be in place.
d. Controls that are not working.

3. Which approach to identifying loss exposures is superior?
a. Qualitative.
b. Quantitative.
c. Neither, both the quantitative and qualitative are equally good.
d. There is not enough information to support any answer.

4. Which of the following is not a risk treatment?
a. Minimize the risk.
b. Accept the risk.
c. Insure against the risk.
d. Implement controls.

5. The end product of the risk assessment process is which of these?
a. The statement of authority.
b. The statement of action.
c. The statement of applicability.
d. None of the above.

