Exam Questions Answers Braindumps ISO-31000-CLA Exam Dumps PDF Questions [Q23-Q43]

Share

Exam Questions Answers Braindumps ISO-31000-CLA Exam Dumps PDF Questions

Download Free GAQM ISO-31000-CLA Real Exam Questions

NEW QUESTION # 23
Which risk is sometimes called 'retained risk.'?

  • A. Conceptualize risk
  • B. Procedural risk
  • C. Analytical risk
  • D. Residual risk

Answer: D

Explanation:
Explanation
According to ISO/IEC Guide73 (2009), clause B., residual risk is "the level of remaining after controls have been applied". It is sometimes called 'retained risk' because it represents the amount of risk that an organization decides to accept or retain after implementing its mitigation strategies 3.


NEW QUESTION # 24
Which type of risk framework is expected to improve efficiency by aligning strategy, processes, technology and people?

  • A. Corporate, governance and control.
  • B. Governance, risk and compliance.
  • C. Controls, risk and supervision.
  • D. Supervision, audit and compliance

Answer: B

Explanation:
Explanation
A governance, risk and compliance (GRC) framework is expected to improve efficiency by aligning strategy, processes, technology and people. GRC aims to integrate these elements to achieve organisational objectives while managing risks and complying with regulations.


NEW QUESTION # 25
Which of the following are two ISO 31000:2018 risk management principles? (Choose two)

  • A. Statistical
  • B. Design
  • C. Strategy
  • D. Customized
  • E. Functional
  • F. Integrated

Answer: D,F

Explanation:
Explanation
Integrated and customized are two of the nine risk management principles in ISO 31000:20181. Integrated means that risk management is an integral part of all organizational activities. Customized means that risk management is aligned with the organization's external and internal context and risk profile.


NEW QUESTION # 26
Which of the following ensures that uncertainty is managed so the organization can meet its objectives?

  • A. Avoidance risk management
  • B. Enhanced risk management
  • C. Extended risk management
  • D. Evasive risk management

Answer: B

Explanation:
Explanation
Enhanced risk management ensures that uncertainty is managed so the organization can meet its objectives4.
Enhanced risk management involves applying a systematic and logical process to identify, analyze, evaluate, treat, monitor, review, and communicate risks.


NEW QUESTION # 27
As part of the ISO 31000 risk management process, 'monitoring and review' is best thought of as which of the following?

  • A. Part of risk assessment.
  • B. An extra stage.
  • C. A feedback loop.

Answer: C

Explanation:
Explanation
According to 3, clause 6.5., monitoring and review "is intended as a feedback loop for checking whether any change has occurred either internally or externally that may affect performance against objectives". It helps to ensure that the risk management process remains relevant and effective over time.


NEW QUESTION # 28
Treatment plan becomes a living document of defining the direction of the risk treatment and being able to monitor progress against the plan.

  • A. False
  • B. True

Answer: B

Explanation:
Explanation
Treatment plan becomes a living document of defining the direction of the risk treatment andbeing able to monitor progress against the plan3. Treatment plan helps to ensure that risk treatment actions are aligned with the changing context, objectives, and stakeholder expectations.


NEW QUESTION # 29
Which management is core to governance and compliance?

  • A. Crisis
  • B. Quality
  • C. Risk
  • D. Fillet

Answer: C

Explanation:
Explanation
Risk management is core to governance and compliance . Risk management helps to ensure that organizational objectives are achieved in a lawful, ethical, and transparent manner.


NEW QUESTION # 30
Which of the following consists of risk management principles, framework, and process that have been adopted as a national risk management standard by more than 60 countries?

  • A. ISO 31000:2018
  • B. ISO 27001:2013
  • C. ISO 14001:2018
  • D. ISO 9001:2015

Answer: A

Explanation:
Explanation
ISO 31000:2018 consists of risk management principles, framework, and process that have been adopted as a national risk management standard by more than 60 countries . It provides guidelines on managing any type of risk faced by organizations.


NEW QUESTION # 31
The organization's resources and internal support are ________ the risk management strategy.

  • A. inputs in the development of
  • B. adjustable to match
  • C. metrics used to measure the value of
  • D. outcomes of the development of

Answer: A

Explanation:
Explanation
according to page 15 of source 3, the development of a risk management strategy takes into account the organization's resources and internal support. These resources include factors such as human, capital, and technological resources; organizational structure, culture, and governance; communication and consultation mechanisms; and support from senior management and leadership. These inputs have an impact on the feasibility and effectiveness of the risk management strategy.


NEW QUESTION # 32
Which type of risk management technique does insurance belongs to?

  • A. Retention
  • B. Sharing
  • C. Reduction

Answer: B

Explanation:
Explanation
According to , page 16-17, insurance belongs to sharing technique which is "a way of transferring some or all financial consequences associated with a particular exposure". It involves paying a premium in exchange for compensation in case of loss.


NEW QUESTION # 33
__________ means doing something according to a plan or method.

  • A. Systematic
  • B. Comprehensive
  • C. Informal
  • D. Formal

Answer: A

Explanation:
Explanation
Systematic means doing something according to a plan or method. Systematic implies orderliness, consistency, and rigor in applying risk management.


NEW QUESTION # 34
Using the FIRM scorecard which of the following risks could a risk manager quantify?
1. Loss of income.
2. Financial gain.
3. Reputational damage.

  • A. 2 and 3.
  • B. 1 and 2.
  • C. 1 and 3.

Answer: B

Explanation:
Explanation
According to 2, FIRM scorecard is "a tool for measuring risk performance". It uses four dimensions: financial impact, internal processes, reputation and market position (FIRM). Loss of income and financial gain are examples of financial impact risks that can be quantified using monetary values or ratios. Reputational damage is an example of reputation risk that is more difficult to quantify using objective measures.


NEW QUESTION # 35
What is typically the day-to-day responsibility of a Chief Risk Officer within a large organisation?

  • A. Producing policies on compliance matters
  • B. Providing assurance that individual risk management processes are effective.
  • C. Preparing and maintaining individual insurance arrangements
  • D. Ensuring that all key risks are adequately managed and reported.

Answer: D

Explanation:
Explanation
The day-to-day responsibility of a Chief Risk Officer within a large organisation is to ensure that all key risks are adequately managed and reported4. This involves overseeing the implementation of risk management policies, processes and systems across the organisation.


NEW QUESTION # 36
Risk management as defined by OCEG GRC model is:

  • A. Capability to set and evaluate performance against objectives
  • B. Capability to proactively encourage and ensure compliance with established policies and boundaries
  • C. Capability to proactively identify, assess and address uncertainty and potential obstacles to achieving objectives

Answer: C

Explanation:
Explanation
According to 1, OCEG GRC model is "a framework for integrating governance, risk management, compliance and ethics/culture into a single capability". It defines risk management as "the capability that enables an organization to understand how uncertainty affects its ability to achieve objectives" 2.


NEW QUESTION # 37
Risk management is a strategic management process.

  • A. False
  • B. True

Answer: B

Explanation:
Explanation
Risk management is a strategic management process . Risk management helps organizations to align their objectives, strategies, and actions with their external and internal environment.


NEW QUESTION # 38
Which type of risk presents only the chance of loss or no loss?

  • A. Financial risk
  • B. Operational risk
  • C. Hazard risk
  • D. Strategic risk

Answer: C

Explanation:
Explanation
According to , page 8, hazard risk is "the traditional pure risk that only has a downside". It is usually associated with natural disasters, accidents, lawsuits or other events that cause harm or damage.


NEW QUESTION # 39
Which activity does the risk management professional perform immediately after obtaining internal and external information about the organization?

  • A. Organize the information
  • B. Report the information.
  • C. Prioritize the information
  • D. Analyze the information.

Answer: A

Explanation:
Explanation
According to page 9-10 of source 2, risk management professionals organize internal and external information about the organization into categories such as stakeholders, strategic objectives, policies and procedures, risk appetite and tolerance, and risk culture. This categorization process facilitates the analysis and reporting of the risk information at a later stage, making it easier to understand and use.


NEW QUESTION # 40
Relying on historic analysis when assessing potential risks and possible impacts implies that

  • A. should adverse events occur, the impact can be accurately modelled.
  • B. all significant risks can be confidently analysed.
  • C. management believe that the future will behave much like the past.

Answer: C

Explanation:
Explanation
According to 1, page 19, historic analysis is "a method of risk identification based on past data". It assumes that past patterns and trends will continue in the future, which may not always be true.


NEW QUESTION # 41
New definition of risk under ISO 31000 and 31010 is:

  • A. Danger that injury, damage, or loss will occur
  • B. Possibility of investment loss
  • C. Probability of loss to an insurer
  • D. Probability of an event that will have an impact on objectives

Answer: D

Explanation:
Explanation
According to ISO/IEC Guide73 (2009), clause 1., risk is defined as "the effect of uncertainty on objectives".
This definition applies to both ISO/IEC Guide73 (2009) and ISO31000 (2018), which are standards for risk management terminology and principles respectively.


NEW QUESTION # 42
Organizational information systems, information flows, and formal and informal decision-making processes are all a part of establishing which type of context in regard to the organization?

  • A. Technological
  • B. External
  • C. Local
  • D. Internal

Answer: D

Explanation:
Explanation
According to ISO31000 (2018), clause 5., establishing the context involves defining "the external and internal parameters to be taken into account when managing risk". The internal context includes "information systems, information flows and decision-making processes" among other factors.


NEW QUESTION # 43
......

Latest GAQM ISO-31000-CLA Real Exam Dumps PDF: https://www.vceengine.com/ISO-31000-CLA-vce-test-engine.html

ISO-31000-CLA Exam Dumps, ISO-31000-CLA Practice Test Questions: https://drive.google.com/open?id=1KRXv78_WhUdx5jC9YA1i9qblzboTgutc