An organization practices the principle of least privilege. To ensure access remains appropriate, application owners should be required to review user access rights on a regular basis by obtaining:
A business unit has implemented robotic process automation (RPA) for its
repetitive back-office tasks. Which of the following should be the risk
practitioner ' s GREATEST concern?
Which of the following BEST enables an organization to address risk associated with technical complexity?
Which of the following is the BEST indicator of executive management ' s support for IT risk mitigation efforts?
The PRIMARY reason for a risk practitioner to review business processes is to:
Which of the following is the MOST important information to cover in a business continuity awareness training program for all employees of the organization?
Which of the following is the ULTIMATE objective of utilizing key control indicators (KCIs) in the risk management process?
Which of the following will BEST help mitigate the risk associated with malicious functionality in outsourced application development?
During a control review, the control owner states that an existing control has deteriorated over time. What is the BEST recommendation to the control owner?
Reviewing historical risk events is MOST useful for which of the following processes within the risk management life cycle?
Which of the following is the PRIMARY advantage of aligning generic risk scenarios with business objectives?
Which of the following is MOST important to understand when determining an appropriate risk assessment approach?
Which of the following is the MOST important consideration when implementing ethical remote work monitoring?
Which of the following provides the BEST evidence that a selected risk treatment plan is effective?
Which of the following is the MOST useful information for a risk practitioner when planning response activities after risk identification?
Which of the following is a KEY consideration for a risk practitioner to communicate to senior management evaluating the introduction of artificial intelligence (Al) solutions into the organization?
Which of the following would BEST indicate to senior management that IT processes are improving?
Which of the following is the GREATEST concern when using a generic set of IT risk scenarios for risk analysis?
An organization outsources the processing of us payroll data A risk practitioner identifies a control weakness at the third party trial exposes the payroll data. Who should own this risk?
An organization is considering allowing users to access company data from their personal devices. Which of the following is the MOST important factor when assessing the risk?
Which of the following BEST helps to identify significant events that could impact an organization?
Which of the following would be MOST important for a risk practitioner to provide to the internal audit department during the audit planning process?
Which of the following is the PRIMARY purpose for ensuring senior management understands the organization’s risk universe in relation to the IT risk management program?
In order to efficiently execute a risk response action plan, it is MOST important for the emergency response team members to understand:
A bank recently incorporated Blockchain technology with the potential to impact known risk within the organization. Which of the following is the risk practitioner’s BEST course of action?
An organization has been notified that a disgruntled, terminated IT administrator has tried to break into the corporate network. Which of the following discoveries should be of GREATEST concern to the organization?
Which of the following is the BEST approach when a risk treatment plan cannot be completed on time?
Which of the following is the PRIMARY reason to establish the root cause of an IT security incident?
The MOST important reason for implementing change control procedures is to ensure: