Which of the following would BEST ensure that identified risk scenarios are addressed?
Which of the following is the BEST success criterion for control implementation?
Which of the following would be MOST useful to management when allocating resources to mitigate risk to the organization?
The risk associated with inadvertent disclosure of database records from a public cloud service provider (CSP) would MOST effectively be reduced by:
A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?
An organization has introduced risk ownership to establish clear accountability for each process. To ensure effective risk ownership, it is MOST important that:
An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?
A penetration testing team discovered an ineffectively designed access control. Who is responsible for ensuring the control design gap is remediated?
A vendor ' s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?
Which organizational role should be accountable for ensuring information assets are appropriately classified?
In an organization dependent on data analytics to drive decision-making, which of the following would BEST help to minimize the risk associated with inaccurate data?
It is MOST important for a risk practitioner to have an awareness of an organization s processes in order to:
Which of the following BEST prevents control gaps in the Zero Trust model when implementing in the environment?
Which of the following is the MOST important enabler of effective risk management?
Which of the following is the MOST important criteria for selecting key risk indicators (KRIs)?
Which of the following is MOST important for an organization that wants to reduce IT operational risk?
Which of these documents is MOST important to request from a cloud service
provider during a vendor risk assessment?
From a data protection and regulatory compliance perspective, which of the following is the MOST important reason for a global organization to use immutable backups?
Which of the following is the MOST important benefit of reporting risk assessment results to senior management?
An organization has decided to implement a new Internet of Things (loT) solution. Which of the following should be done FIRST when addressing security concerns associated with this new technology?
Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?
Which of the following is the GREATEST benefit for an organization with a strong risk awareness culture?
An organization is developing a risk awareness program for contractors and consultants. Which of the following is MOST important for the organization to keep confidential?
Which of the following provides a risk practitioner with the MOST reliable evidence of a third party ' s ability to protect the confidentiality of sensitive corporate information?
A bank has outsourced its statement printing function to an external service provider. Which of the following is the MOST critical requirement to include in the contract?
The BEST reason to classify IT assets during a risk assessment is to determine the:
Which of the following would provide the MOST comprehensive information for communicating current levels of IT-related risk to executive management?
Which of the following BEST enables an organization to determine whether risk management is aligned with its goals and objectives?
A control owner responsible for the access management process has developed a machine learning model to automatically identify excessive access privileges. What is the risk practitioner ' s BEST course of action?
Which of the following is MOST important for an organization to continuously manage after implementing a Zero Trust security model?
An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios applicable to IT. Which of the following is the BEST way to ensure alignment between these two registers?
Which of the following is the BEST course of action for a system administrator who suspects a colleague may be intentionally weakening a system ' s validation controls in order to pass through fraudulent transactions?
Which of the following is the GREATEST concern when establishing key risk indicators (KRIs)?
Which of the following issues should be of GREATEST concern when evaluating existing controls during a risk assessment?
Which of the following is the MOST important consideration when implementing ethical remote work monitoring?
A risk practitioner can use an organization ' s problem management process to anticipate potential risk within IT systems by:
An organization has engaged a third party to provide an Internet gateway encryption service that protects sensitive data uploaded to a cloud service. This is an example of risk:
The MOST appropriate key performance indicator (KPI) to communicate the effectiveness of an enterprise IT risk management program is:
Which of the following is the MOST important consideration when prioritizing risk response?
Which of the following is MOST important to include in a Software as a Service (SaaS) vendor agreement?
Which of the following findings of a security awareness program assessment would cause the GREATEST concern to a risk practitioner?
A risk owner has identified a risk with high impact and very low likelihood. The potential loss is covered by insurance. Which of the following should the risk practitioner do NEXT?
Which of the following is the GREATEST concern associated with the transmission of healthcare data across the internet?
Which of the following is the MOST effective way to integrate business risk management with IT operations?
Which of the following is the PRIMARY reason for monitoring activities performed in a production database environment?
Which of the following is the FIRST consideration to reduce risk associated with the storage of personal data?
While evaluating control costs, management discovers that the annual cost exceeds the annual loss expectancy (ALE) of the risk. This indicates the:
Winch of the following is the BEST evidence of an effective risk treatment plan?