Which of the following BEST facilitates the process of documenting risk tolerance?
A new software package that could help mitigate risk in an organization has become available. Which of the following is the risk practitioner’s BEST course of action?
An organization is concerned that a change in its market situation may impact the current level of acceptable risk for senior management. As a result, which of the following is MOST important to reevaluate?
Which of the following is the PRIMARY reason to conduct risk assessments at periodic intervals?
Which of the following risk activities is BEST facilitated by enterprise architecture (EA)?
Which of the following is a risk practitioner ' s BEST recommendation upon learning that an employee inadvertently disclosed sensitive data to a vendor?
Which of the following observations from a third-party service provider review would be of GREATEST concern to a risk practitioner?
Which of the following is the BEST approach when a risk practitioner has been asked by a business unit manager for special consideration during a risk assessment of a system?
Which of the following would be MOST effective in monitoring changes in an organization ' s IT risk environment?
Which of the following is the FIRST step when conducting a business impact analysis (BIA)?
Which of the following situations presents the GREATEST challenge to creating a comprehensive IT risk profile of an organization?
The BEST key performance indicator (KPI) to measure the effectiveness of a vendor risk management program is the percentage of:
Which of the following should be the PRIMARY input when designing IT controls?
Winch of the following can be concluded by analyzing the latest vulnerability report for the it infrastructure?
Which of the following would BEST help to ensure that suspicious network activity is identified?
A risk practitioner is reviewing the status of an action plan to mitigate an emerging IT risk and finds the risk level has increased. The BEST course of action would be to:
Which of the following risk scenarios would be the GREATEST concern as a result of a single sign-on implementation?
Which of the following is the MOST important requirement for monitoring key risk indicators (KRls) using log analysis?
Which of the following is the MOST effective way lo ensure professional ethics are maintained as a core organizational value and adhered to by employees?
Which of the following is the BEST metric to demonstrate the effectiveness of an organization ' s patch management process?
The MOST important measure of the effectiveness of risk management in project implementation is the percentage of projects:
Which of the following is the PRIMARY role of a data custodian in the risk management process?
A risk practitioner has been asked by executives to explain how existing risk treatment plans would affect risk posture at the end of the year. Which of the following is MOST helpful in responding to this request?
Which of the following is the BEST way to determine the potential organizational impact of emerging privacy regulations?
Which of the following is the BEST risk management approach for the strategic IT planning process?
Which of the following would be MOST helpful when selecting appropriate protection for data?
Which of the following would be the BEST justification to invest in the development of a governance, risk, and compliance (GRC) solution?
An organization has provided legal text explaining the rights and expected behavior of users accessing a system from geographic locations that have strong privacy regulations. Which of the following control types has been applied?
When is the BEST to identify risk associated with major project to determine a mitigation plan?
An organization has just implemented changes to close an identified vulnerability that impacted a critical business process. What should be the NEXT course of action?
Which of the following is the BEST time for an enterprise project management team to use risk analysis?
An IT department has organized training sessions to improve user awareness of organizational information security policies. Which of the following is the BEST key performance indicator (KPI) to reflect effectiveness of the training?
While reviewing the risk register, a risk practitioner notices that different business units have significant variances in inherent risk for the same risk scenario. Which of the following is the BEST course of action?
A migration from an in-house developed system to an external cloud-based solution is affecting a previously rated key risk scenario related to payroll processing. Which part of the risk register should be updated FIRST?
When assessing the maturity level of an organization ' s risk management framework, which of the following should be of GREATEST concern to a risk practitioner?
A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner ' s BEST course of action when a compensating control needs to be applied?
Which of the following should be the PRIMARY consideration when implementing controls for monitoring user activity logs?
When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?
What are the MOST essential attributes of an effective Key control indicator (KCI)?
When processing personal information which of the following BEST helps to mitigate privacy risk while still enabling testing?
Which of the following is the BEST indication of a mature organizational risk culture?
An organization ' s IT department wants to complete a proof of concept (POC) for a security tool. The project lead has asked for approval to use the production data for testing purposes as it will yield the best results. Which of the following is the risk practitioner ' s BEST recommendation?
A business unit has decided to accept the risk of implementing an off-the-shelf, commercial software package that uses weak password controls. The BEST course of action would be to:
In which of the following system development life cycle (SDLC) phases should controls be incorporated into system specifications?
Which of the following is the MOST effective way to assess the risk associated with outsourcing IT processes?
Which of the following should be management ' s PRIMARY focus when key risk indicators (KRIs) begin to rapidly approach defined thresholds?
A software developer has administrative access to a production application. Which of the following should be of GREATEST concern to a risk practitioner?