Application Risk Assessment Questions

Answer Correct answer: A — These questions are part of a Risk Control Self-Assessment (RCSA) process to identify and evaluate internal controls.

The application development teams have been asked to answer the following questions: • Does this application receive patches from an external source? • Does this application contain open-source code? • Is this application accessible by external users? • Does this application meet the corporate password standard? Which of the following are these questions part of?

  1. Risk control self-assessment Correct Answer
  2. Risk management strategy
  3. Risk acceptance
  4. Risk matrix

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between proactive self-assessment questionnaires and static risk documentation tools like matrices.

Identifies the specific risk management process used to evaluate application security and compliance through targeted internal questions.

Confusing the assessment activity with a risk matrix, which is a tool for scoring rather than a process for gathering data.

Community Discussion (4 comments)

7308365 👍 1
A. Risk control self-assessment A risk and control self-assessment (RCSA) is an internal process undertaken by stakeholders to identify risks and the effectiveness with which controls mitigate those risks. RCSAs are often performed through questionnaires and workshops with department managers.
Jay987654 👍 2 Selected: A
These questions are part of an A. Risk Control Self-Assessment. A Risk Control Self-Assessment (RCSA) is a process through which internal control gaps are identified and assessed for their risk. The questions asked are aimed at understanding the potential risks associated with the application, such as the risk of using open-source code, the risk associated with external patches, the risk of external user access, and the risk of non-compliance with corporate password standards. The answers to these questions will help in assessing the overall risk profile of the application and determining the necessary controls to mitigate these risks.
johnabayot 👍 1 Selected: A
Risk control self-assessment involves identifying, assessing, mitigating, and monitoring risks across all levels of an organization. The questions are examples of how to assess the risks and control related to an application's security, reliability, and compliance.
Hs1208 👍 1 Selected: A
A. Risk control self-assessment These questions are designed to assess and gather information about specific risks associated with an application.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is A. These questions are part of a Risk Control Self-Assessment (RCSA). An RCSA is an internal process where stakeholders identify risks and assess the effectiveness of controls in place. The questions listed—regarding external patches, open-source code, external accessibility, and password standards—are typical control checks performed during such an assessment to determine if the application meets organizational risk appetite and compliance requirements.

Why the Other Options Are Wrong

B is incorrect because a Risk Management Strategy is a high-level framework or plan, not a set of operational questions. C is incorrect because Risk Acceptance is the final decision to tolerate a risk after it has been assessed, not the assessment process itself. D is incorrect because a Risk Matrix is a visual tool used to plot the probability and impact of risks; it does not generate the questions used to gather the underlying data.

Community Comment Notes

Community consensus strongly supports option A. As user Jay987654 noted, "These questions are part of an A. Risk Control Self-Assessment... aimed at understanding the potential risks associated with the application." Another commenter emphasized that RCSAs are "often performed through questionnaires," which aligns perfectly with the format of the questions provided in the scenario.

Exam Strategy

When you see a list of specific questions asked to business units or development teams about their controls, think 'Self-Assessment' or 'Questionnaire'. If the question asks about plotting likelihood vs impact, think 'Matrix'. If it asks about the overall approach, think 'Strategy'.

Frequently Asked Questions

How does RCSA differ from a Risk Matrix?

RCSA is the process of gathering data via questionnaires to identify risks. A Risk Matrix is a tool used later to visualize and score those risks based on probability and impact.

Are these questions part of a security audit?

While similar, RCSA is typically self-initiated by the team or department for internal governance, whereas an audit is often independent and retrospective.

Related Analysis

← Back to SY0-601 Study Guide