Which of the following would MOST likely lead to misaligned outcomes from enterprise architecture (EA)?
Which of the following is the MOST important consideration when sharing risk management updates with executive management?
Which of the following should be the risk practitioner s FIRST course of action when an organization has decided to expand into new product areas?
Which of the following data would be used when performing a business impact analysis (BIA)?
Automated code reviews to reduce the risk associated with web applications are MOST effective when performed:
Which of the following is the MOST important key performance indicator (KPI) for monitoring the user access management process?
Which of the following is the MOST important input when developing risk scenarios?
When of the following is the MOST significant exposure when an application uses individual user accounts to access the underlying database?
Which of the following should be of GREATEST concern to a risk practitioner reviewing an organization ' s disaster recovery plan (DRP)?
Which of the following has the MOST validity for conducting risk assessments?
What is senior management ' s role in the RACI model when tasked with reviewing monthly status reports provided by risk owners?
Which of the following management actions will MOST likely change the likelihood rating of a risk scenario related to remote network access?
Which of the following is a drawback in the use of quantitative risk analysis?
Which of the following is the GREATEST concern related to the monitoring of key risk indicators (KRIs)?
Which of the following is the MOST important element of a successful risk awareness training program?
Which of the following is the MOST important consideration when multiple risk practitioners capture risk scenarios in a single risk register?
Which of the following situations would BEST justify escalation to senior management?
It is MOST important to the effectiveness of an IT risk management function that the associated processes are:
Which of the following process controls BEST mitigates the risk of an employee issuing fraudulent payments to a vendor?
Which of the following is the MOST important reason for a risk practitioner to identify stakeholders for each IT risk scenario?
An organization ' s risk management team wants to develop IT risk scenarios to show the impact of collecting and storing credit card information. Which of the following is the MOST comprehensive approach to capture this scenario?
Which of the following provides the MOST helpful reference point when communicating the results of a risk assessment to stakeholders?
Which of the following issues found during the review of a newly created disaster recovery plan (DRP) should be of MOST concern?
An organization has detected unauthorized logins to its client database servers. Which of the following should be of GREATEST concern?
Before selecting a final risk response option for a given risk scenario, management should FIRST:
Which of the following is the MOST important objective of regularly presenting the project risk register to the project steering committee?
Which of the following is MOST important when considering risk in an enterprise risk management (ERM) process?
Which of the following is a benefit of implementing user and entity behavior analytics to help mitigate information security threats?
An automobile manufacturer is considering implementing an Internet of Things (IoT) network to improve customer service by collecting customer and vehicle data. Which of the following would be the risk practitioner’s BEST recommendation?
A new regulator/ requirement imposes severe fines for data leakage involving customers ' personally identifiable information (Pll). The risk practitioner has recommended avoiding the risk. Which of the following actions would BEST align with this recommendation?
Participants in a risk workshop have become focused on the financial cost to mitigate risk rather than choosing the most appropriate response. Which of the following is the BEST way to address this type of issue in the long term?
Which of the following is MOST important for an organization to have in place when developing a risk management framework?
Which of the following is the MOST important reason to integrate IT risk management practices into the enterprise-wide operational risk management framework?
Which of the following has the GREATEST positive impact on ethical compliance within the risk management process?
Which of the following changes would be reflected in an organization ' s risk profile after the failure of a critical patch implementation?