Which of the following BEST represents a critical threshold value for a key control indicator (KCI)?
Which of the following should be a risk practitioner’s MOST important consideration when developing IT risk scenarios?
An organization is considering outsourcing user administration controls tor a critical system. The potential vendor has offered to perform quarterly sett-audits of its controls instead of having annual independent audits. Which of the following should be of GREATEST concern to me risk practitioner?
Which of the following BEST enables the risk profile to serve as an effective resource to support business objectives?
Which of me following is MOST helpful to mitigate the risk associated with an application under development not meeting business objectives?
An organization allows programmers to change production systems in emergency situations. Which of the following is the BEST control?
Which of the following is the MOST significant risk related to an organization's use of AI technology?
A risk register BEST facilitates which of the following risk management functions?
Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?
A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
After mapping generic risk scenarios to organizational security policies, the NEXT course of action should be to:
Management has determined that it will take significant time to remediate exposures in the current IT control environment. Which of the following is the BEST course of action?
A penetration test reveals several vulnerabilities in a web-facing application. Which of the following should be the FIRST step in selecting a risk response?
Which of the following would provide the MOST useful information to a risk owner when reviewing the progress of risk mitigation?
Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?
Which of the following is MOST important for a multinational organization to consider when developing its security policies and standards?
Which of the following is MOST important when developing key performance indicators (KPIs)?
A risk practitioner has reviewed new international regulations and realizes the new regulations will affect the organization. Which of the following should be the risk practitioner's NEXT course of
action?
A risk practitioner is assisting with the preparation of a report on the organization s disaster recovery (DR) capabilities. Which information would have the MOST impact on the overall recovery profile?
Which of the following is the PRIMARY reason to use administrative controls in conjunction with technical controls?
Which of the following is the MOST important course of action for a risk practitioner when reviewing the results of control performance monitoring?
Which of the following helps ensure compliance with a nonrepudiation policy requirement for electronic transactions?
An automobile manufacturer is considering implementing an Internet of Things (IoT) network to improve customer service by collecting customer and vehicle data. Which of the following would be the risk practitioner’s BEST recommendation?
Which of the following is the MOST important driver of an effective enterprise risk management (ERM) program?
Which of the following risk register updates is MOST important for senior management to review?
After a business unit implemented an Internet of Things (IoT) solution, the organization became aware of an emerging risk from the interoperability of IoT devices. Which of the following should be done FIRST in response to this situation?
Which of the following would be MOST relevant to stakeholders regarding ineffective control implementation?
While evaluating control costs, management discovers that the annual cost exceeds the annual loss expectancy (ALE) of the risk. This indicates the:
Which of the following will BEST help ensure that risk factors identified during an information systems review are addressed?
During the initial risk identification process for a business application, it is MOST important to include which of the following stakeholders?
Which of the following is the BEST way to identify changes to the risk landscape?
Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability management process?
Which of the following is MOST critical to the design of relevant risk scenarios?
An organization recently implemented an extensive risk awareness program after a cybersecurity incident. Which of the following is MOST likely to be affected by the implementation of the program?
A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner’s BEST course of action?
Which of the following is the GREATEST concern when establishing key risk indicators (KRIs)?
Which of the following MUST be assessed before considering risk treatment options for a scenario with significant impact?
The MOST appropriate key performance indicator (KPI) to communicate the effectiveness of an enterprise IT risk management program is:
To implement the MOST effective monitoring of key risk indicators (KRIs), which of the following needs to be in place?
Which of the following is the MOST important consideration when establishing a recovery point objective (RPO)?
Which of the following will MOST likely change as a result of the decrease in risk appetite due to a new privacy regulation?
After several security incidents resulting in significant financial losses, IT management has decided to outsource the security function to a third party that provides 24/7 security operation services. Which risk response option has management implemented?
Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?