Which of the following is the BEST key control indicator (KCI) for risk related to IT infrastructure failure?
Which of the following should be of MOST concern to a risk practitioner reviewing an organization risk register after the completion of a series of risk assessments?
Which of the following is a risk practitioner ' s MOST important course of action after learning that an organization ' s industry peers have experienced an increase in ransomware attacks?
An organization requires a third party for processing customer personal data. Which of the following is the BEST approach when sharing data over a public network?
Which of the following will BEST help ensure that risk factors identified during an information systems review are addressed?
An organization ' s financial analysis department uses an in-house forecasting application for business projections. Who is responsible for defining access roles to protect the sensitive data within this application?
Which of the following provides the BEST level of assurance to an organization that its vendors ' controls are effective?
The BEST way to validate that a risk treatment plan has been implemented effectively is by reviewing:
Which of the following is the BEST measure of the effectiveness of an employee deprovisioning process?
Which of the following presents the GREATEST security risk associated with Internet of Things (IoT) technology?
Which of the following is the MOST useful information for prioritizing risk mitigation?
A cloud service provider has completed upgrades to its cloud infrastructure to enhance service availability. Which of the following is the MOST important key risk indicator (KRI) for management to monitor?
Which of the following is the BEST method for determining an enterprise ' s current appetite for risk?
Which of the following should be a risk practitioner ' s NEXT step after learning of an incident that has affected a competitor?
Senior management has requested more information regarding the risk associated with introducing a new application into the environment. Which of the following should be done FIRST?
Which of the following is the BEST indicator of the effectiveness of a control?
Which of the following is the BEST way to determine the value of information assets for risk management purposes?
During the control evaluation phase of a risk assessment, it is noted that multiple controls are ineffective. Which of the following should be the risk practitioner ' s FIRST course of action?
Which of the following is MOST important for a project steering committee to consider when deciding to release a new system into production?
Several newly identified risk scenarios are being integrated into an organization ' s risk register. The MOST appropriate risk owner would be the individual who:
Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?
Which of the following will BEST help to ensure key risk indicators (KRIs) provide value to risk owners?
A risk practitioner is performing a risk assessment of recent external advancements in quantum computing. Which of the following would pose the GREATEST concern for the risk practitioner?
Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?
An organization recently implemented an extensive risk awareness program after a cybersecurity incident. Which of the following is MOST likely to be affected by the implementation of the program?
An organization wants to grant remote access to a system containing sensitive data to an overseas third party. Which of the following should be of GREATEST concern to management?
A new international data privacy regulation requires personal data to be
disposed after the specified retention period, which is different from the local
regulatory requirement. Which of the following is the risk practitioner ' s
BEST course of action?
An IT project risk was identified during a monthly steering committee meeting. Which of the following roles is BEST positioned to approve the risk mitigation response?
Which of the following has the GREATEST impact on ensuring the alignment of the risk profile with business objectives?
The BEST way for management to validate whether risk response activities have been completed is to review:
A zero-day vulnerability has been discovered in a globally used brand of hardware server that allows hackers to gain
access to affected IT systems. Which of the following is MOST likely to change as a result of this situation?
Which of the following would be MOST helpful to a risk owner when making risk-aware decisions?
Which of the following BEST indicates that an organizations risk management program is effective?
Which of the following is of GREATEST concern when uncontrolled changes are made to the control environment?
Which of the following would BEST mitigate the ongoing risk associated with operating system (OS) vulnerabilities?
Prior to selecting key performance indicators (KPIs), itis MOST important to ensure:
Which of the following approaches MOST effectively enables accountability for data protection?
A hospital recently implemented a new technology to allow virtual patient appointments. Which of the following should be the risk practitioner ' s FIRST course of action?
Which of the following attributes of a key risk indicator (KRI) is MOST important?
A service provider is managing a client’s servers. During an audit of the service, a noncompliant control is discovered that will not be resolved before the next audit because the client cannot afford the downtime required to correct the issue. The service provider’s MOST appropriate action would be to:
A risk practitioner is organizing risk awareness training for senior management. Which of the following is the MOST important topic to cover in the training session?
An organization mandates the escalation of a service ticket when a key application is offline for 5 minutes or more due to potential risk exposure. The risk practitioner has been asked by management to prepare a report of application offline times using both 3- and 5-minute thresholds. What does the 3-minute threshold represent?
A third-party vendor has offered to perform user access provisioning and termination. Which of the following control accountabilities is BEST retained within the organization?
Which of the following will BEST help to improve an organization ' s risk culture?
An organization has recently hired a large number of part-time employees. During the annual audit, it was discovered that many user IDs and passwords were documented in procedure manuals for use by the part-time employees. Which of the following BEST describes this situation?
it was determined that replication of a critical database used by two business units failed. Which of the following should be of GREATEST concern1?