An organization has outsourced its billing function to an external service provider. Who should own the risk of customer data leakage caused by the service provider?
Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?
Which of the following would be MOST important for a risk practitioner to provide to the internal audit department during the audit planning process?
Who is PRIMARILY accountable for identifying risk on a daily basis and ensuring adherence to the organization ' s policies?
Which of the following should be done FIRST when developing a data protection management plan?
Which of the following is the BEST way to assess the effectiveness of an access management process?
Which of the following would be the BEST way for a risk practitioner to validate the effectiveness of a patching program?
Which of the following would BEST enable a risk practitioner to embed risk management within the organization?
An organization wants to assess the maturity of its internal control environment. The FIRST step should be to:
The following is the snapshot of a recently approved IT risk register maintained by an organization ' s information security department.

After implementing countermeasures listed in ‘’Risk Response Descriptions’’ for each of the Risk IDs, which of the following component of the register MUST change?
Which of the following is MOST helpful when prioritizing action plans for identified risk?
A failure in an organization s IT system build process has resulted in several computers on the network missing the corporate endpoint detection and response (EDR) software. Which of the following should be the risk practitioner’s IMMEDIATE concern?
After the implementation of a remediation plan, an assessment of associated control design and operating effectiveness can determine the level of:
Once a risk owner has decided to implement a control to mitigate risk, it is MOST important to develop:
Which of the following would be MOST helpful when communicating roles associated with the IT risk management process?
An online payment processor would be severely impacted if the fraud detection system has an outage. Which of the following is the BEST way to address this risk?
Within the three lines of defense model, the responsibility for managing risk and controls resides with:
Which of the following BEST enables an organization to increase the likelihood of identifying risk associated with unethical employee behavior?
Which of the following is MOST useful for measuring the existing risk management process against a desired state?
An organization is planning to acquire a new financial system. Which of the following stakeholders would provide the MOST relevant information for analyzing the risk associated with the new IT solution?
When presenting risk, the BEST method to ensure that the risk is measurable against the organization ' s risk appetite is through the use of a:
Which of the following is the PRIMARY reason for a risk practitioner to examine a post-implementation review report for a control automation tool?
A risk practitioner notices that a particular key risk indicator (KRI) has remained below its established trigger point for an extended period of time. Which of the following should be done FIRST?
Which of the following scenarios is MOST important to communicate to senior management?
A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:
Which of the following is the MOST important information to be communicated during security awareness training?
During a risk assessment of a financial institution, a risk practitioner discovers that tellers can initiate and approve transactions of significant value. This team is also responsible for ensuring transactions are recorded and balances are reconciled by the end of the day. Which of the following is the risk practitioner ' s BEST recommendation to mitigate the associated risk?
Which of the following would MOST effectively reduce the potential for inappropriate exposure of vulnerabilities documented in an organization ' s risk register?
Which of the following would be of MOST concern to a risk practitioner reviewing risk action plans for documented IT risk scenarios?
Which of the following BEST enables detection of ethical violations committed by employees?
A PRIMARY function of the risk register is to provide supporting information for the development of an organization ' s risk:
A risk practitioner is summarizing the results of a high-profile risk assessment sponsored by senior management. The BEST way to support risk-based decisions by senior management would be to:
An organization has opened a subsidiary in a foreign country. Which of the following would be the BEST way to measure the effectiveness of the subsidiary ' s IT systems controls?
If concurrent update transactions to an account are not processed properly, which of the following will MOST likely be affected?
Which of the following will BEST help to ensure implementation of corrective action plans?
Which of the following BEST helps to identify significant events that could impact an organization?
Vulnerability analysis
Who should be accountable for monitoring the control environment to ensure controls are effective?
Which of the following should a risk practitioner recommend FIRST when an increasing trend of risk events and subsequent losses has been identified?
Which of the following is the MOST important document regarding the treatment of sensitive data?
Which of the following should be of GREATEST concern to a risk practitioner when determining the effectiveness of IT controls?
An IT license audit has revealed that there are several unlicensed copies of co be to:
A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?
What is the MOST important consideration when aligning IT risk management with the enterprise risk management (ERM) framework?
Which of the following BEST facilities the alignment of IT risk management with enterprise risk management (ERM)?
Which of the following should be the PRIMARY driver for the prioritization of risk responses?
Which of the following is the MOST effective way 10 identify an application backdoor prior to implementation ' ?
Which of the following is the MOST important consideration for prioritizing risk treatment plans when faced with budget limitations?