Which of the following presents the GREATEST challenge to managing an organization ' s end-user devices?
Which of the following is the BEST metric to measure the effectiveness of an organization ' s disaster recovery program?
Which of the following would be MOST helpful in assessing the risk associated with data loss due to human vulnerabilities?
Which of the following is the PRIMARY concern related to using pseudonymization for the protection of an organization’s processed privacy data?
Which of the following is the PRIMARY reason for a risk practitioner to review an organization ' s IT asset inventory?
A risk register BEST facilitates which of the following risk management functions?
Which of the following is MOST important for a risk practitioner to verify when periodically reviewing risk response action plans?
Which of the following is the MOST important objective from a cost perspective for considering aggregated risk responses in an organization?
Which of the following provides the MOST comprehensive information when developing a risk profile for a system?
An organization has decided to outsource a web application, and customer data will be stored in the vendor ' s public cloud. To protect customer data, it is MOST important to ensure which of the following?
A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:
Which of the following is a PRIMARY benefit to an organization that is using threat intelligence?
An organization has received notification that it is a potential victim of a cybercrime that may have compromised sensitive customer data. What should be The FIRST course of action?
Which of the following is the BEST key performance indicator (KPI) to measure the ability to deliver uninterrupted IT services?
Which of the following is MOST critical to the design of relevant risk scenarios?
Which of the following is a responsibility of the second line in the three lines model?
Which of the following emerging technologies is frequently used for botnet distributed denial of service (DDoS) attacks?
Which of the following provides the BEST protection for Internet of Things (loT) devices that are accessed within an organization?
Upon learning that the number of failed back-up attempts continually exceeds the current risk threshold, the risk practitioner should:
An organization is planning to move its application infrastructure from on-premises to the cloud. Which of the following is the BEST course of the actin to address the risk associated with data transfer if the relationship is terminated with the vendor?
Of the following, who should be responsible for determining the inherent risk rating of an application?
Which of the following is MOST important to consider when determining a recovery time objective (RTO)?
Which of the following has the GREATEST impact on backup policies for a system supporting a critical process?
From a risk management perspective, which of the following is the PRIMARY benefit of using automated system configuration validation tools?
A risk practitioner has learned that the number of emergency change management tickets without subsequent approval has doubled from the same period of the previous year. Which of the following is the MOST important action for the risk practitioner to take?
When implementing an IT risk management program, which of the following is the BEST time to evaluate current control effectiveness?
When determining which control deficiencies are most significant, which of the following would provide the MOST useful information?
An organization has outsourced a critical process involving highly regulated data to a third party with servers located in a foreign country. Who is accountable for the confidentiality of this data?
Which of the following is MOST important to communicate to senior management during the initial implementation of a risk management program?
A recent regulatory requirement has the potential to affect an organization ' s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?
A risk practitioner has discovered a deficiency in a critical system that cannot be patched. Which of the following should be the risk practitioner ' s FIRST course of action?
Which of the following is MOST likely to increase the likelihood or impact of an identified risk scenario?
Which of the following is the MOST important success factor when introducing risk management in an organization?
Which of the following risk impacts should be the PRIMARY consideration for determining recovery priorities in a disaster recovery situation?
Which of the following would be the GREATEST risk associated with a new implementation of single sign-on?
A key performance indicator (KPI) shows that a process is operating inefficiently, even though no control issues were noted during the most recent risk assessment. Which of the following should be done FIRST?
The MOST important reason for implementing change control procedures is to ensure:
During testing, a risk practitioner finds the IT department ' s recovery time objective (RTO) for a key system does not align with the enterprise ' s business continuity plan (BCP). Which of the following should be done NEXT?
An organization recently configured a new business division Which of the following is MOST likely to be affected?
Which of the following is the BEST criterion to determine whether higher residual risk ratings in the risk register should be accepted?
What is the MAIN benefit of using a top-down approach to develop risk scenarios?
Which of the following can be affected by the cost of risk mitigation alternatives?
In the context of the three lines model, which of the following is responsible for providing assurance to senior management and the governing body through independent and objective reviews?
The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:
Which of the following is MOST important to the successful development of IT risk scenarios?
Which of the following is the MOST important responsibility of a business process owner to enable effective IT risk management?
In addition to the risk register, what should a risk practitioner review to develop an understanding of the organization ' s risk profile?
Which of the following is the BEST source for identifying key control indicators (KCIs)?