Which of the following risk register elements is MOST likely to be updated if the attack surface or exposure of an asset is reduced?
Which of the following would BEST help to address the risk associated with malicious outsiders modifying application data?
A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization ' s data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?
When determining the accuracy of a key risk indicator (KRI), it is MOST important that the indicator:
Which of the following statements describes the relationship between key risk indicators (KRIs) and key control indicators (KCIs)?
Which of the following should be included in a risk scenario to be used for risk analysis?
An organization has implemented immutable backups to prevent successful ransomware attacks. Which of the following is the MOST effective control for the risk practitioner to review?
Which of the following is the BEST approach to mitigate the risk associated with a control deficiency?
Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?
An organization has implemented a system capable of comprehensive employee monitoring. Which of the following should direct how the system is used?
To enable effective integration of IT risk scenarios and enterprise risk management (ERM), it is MOST important to have a consistent approach to reporting:
Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?
Which of the following is the GREATEST concern if user acceptance testing (UAT) is not conducted when implementing a new application?
Which of the following BEST represents a critical threshold value for a key control indicator (KCI)?
Which of the following information is MOST useful to a risk practitioner for developing IT risk scenarios?
Which of the following is a risk practitioner ' s BEST recommendation regarding disaster recovery management (DRM) for Software as a Service (SaaS) providers?
Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?
Which of the following would provide executive management with the BEST information to make risk decisions as a result of a risk assessment?
An organization recently experienced a cyber attack that resulted in the loss of confidential customer data. Which of the following is the risk practitioner ' s BEST recommendation after recovery steps have been completed?
Which of the following BEST reduces the likelihood of employees unintentionally disclosing sensitive information to outside parties?
Which of the following is the BEST method to ensure a terminated employee ' s access to IT systems is revoked upon departure from the organization?
Which of the following provides the BEST evidence that robust risk management practices are in place within an organization?
Which of the following is MOST important to include in a risk assessment of an emerging technology?
To help ensure all applicable risk scenarios are incorporated into the risk register, it is MOST important to review the:
During a risk assessment, a risk practitioner learns that an IT risk factor is adequately mitigated by compensating controls in an associated business process. Which of the following would enable the MOST effective management of the residual risk?
A risk practitioner notices a trend of noncompliance with an IT-related control. Which of the following would BEST assist in making a recommendation to management?
A risk practitioner is advising management on how to update the IT policy framework to account for the organization s cloud usage. Which of the following should be the FIRST step in this process?
Which of the following is the PRIMARY benefit when senior management periodically reviews and updates risk appetite and tolerance levels?
Which of the following is the MOST effective way to identify changes in the performance of the control environment?
Which of the following resources is MOST helpful to a risk practitioner when updating the likelihood rating in the risk register?
During a risk treatment plan review, a risk practitioner finds the approved risk action plan has not been completed However, there were other risk mitigation actions implemented. Which of the fallowing is the BEST course of action?
What would be MOST helpful to ensuring the effective implementation of a new cybersecurity program?
Which of the following would MOST effectively protect financial records from ransomware attacks?
Which of the following BEST measures the impact of business interruptions caused by an IT service outage?
An organization ' s chief information officer (CIO) has proposed investing in a new. untested technology to take advantage of being first to market Senior management has concerns about the success of the project and has set a limit for expenditures before final approval. This conditional approval indicates the organization ' s risk:
An information system for a key business operation is being moved from an in-house application to a Software as a Service (SaaS) vendor. Which of the following will have the GREATEST impact on the ability to monitor risk?
When assigning control ownership, it is MOST important to verify that the owner has accountability for:
Which of the following BEST facilitates the development of relevant risk scenarios?
A risk assessment has identified that departments have installed their own WiFi access points on the enterprise network. Which of the following would be MOST important to include in a report to senior management?
Key performance indicators (KPIs) are BEST utilized to provide a high-level overview of:
A risk practitioners PRIMARY focus when validating a risk response action plan should be that risk response:
An organization is planning to engage a cloud-based service provider for some of its data-intensive business processes. Which of the following is MOST important to help define the IT risk associated with this outsourcing activity?
Which of the following provides the MOST useful information to senior management about risk mitigation status?
Which of the following would MOST likely result in agreement on accountability for risk scenarios?
Which of the following BEST supports the management of identified risk scenarios?
After identifying new risk events during a project, the project manager s NEXT step should be to: