Which of the following BEST facilitates the development of relevant risk scenarios?
An internal audit report reveals that not all IT application databases have encryption in place. Which of the following information would be MOST important for assessing the risk impact?
Which of the following is the PRIMARY reason to perform ongoing risk assessments?
Which of the following IT key risk indicators (KRIs) provides management with the BEST feedback on IT capacity?
What is senior management's role in the RACI model when tasked with reviewing monthly status reports provided by risk owners?
Which key performance indicator (KPI) BEST measures the effectiveness of an organization's disaster recovery program?
Which of the following is MOST important to add to the risk register for a remediated risk scenario?
Which of the following is the MOST essential factor for managing risk in a highly dynamic environment?
Which of the following is the BEST key performance indicator (KPI) to measure the ability to deliver uninterrupted IT services?
Which of The following BEST represents the desired risk posture for an organization?
The MOST essential content to include in an IT risk awareness program is how to:
Which of the following should be initiated when a high number of noncompliant conditions are observed during review of a control procedure?
Which of the following BEST facilitates the identification of appropriate key performance indicators (KPIs) for a risk management program?
Which of the following is the PRIMARY purpose of periodically reviewing an organization's risk profile?
During a risk assessment, what should an assessor do after identifying threats to organizational assets?
The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:
Which of the following is the PRIMARY purpose of conducting risk and control self-assessments?
Which of the following is the PRIMARY risk management responsibility of the second line of defense?
Which of the following is MOST important to review when evaluating the ongoing effectiveness of the IT risk register?
Which of the following is the PRIMARY role of the board of directors in corporate risk governance?
An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:
The BEST metric to demonstrate that servers are configured securely is the total number of servers:
Which of the following is the GREATEST risk of relying on artificial intelligence (Al) within heuristic security systems?
Which of the following will BEST ensure that controls adequately support business goals and objectives?
Which of the following BEST enables effective risk reporting to the board of directors?
Which of the following findings of a security awareness program assessment would cause the GREATEST concern to a risk practitioner?
An IT license audit has revealed that there are several unlicensed copies of co be to:
Which of the following BEST helps to balance the costs and benefits of managing IT risk?
Which of the following is the BEST way to reduce the likelihood of an individual performing a potentially harmful action as the result of unnecessary entitlement?
Which of the following roles is BEST suited to help a risk practitioner understand the impact of IT-related events on business objectives?
Which of the following is the FIRST step when conducting a business impact analysis (BIA)?
An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner's FIRST course of action?
It is MOST important that security controls for a new system be documented in:
Which of the following describes the relationship between Key risk indicators (KRIs) and key control indicators (KCIS)?
During testing, a risk practitioner finds the IT department's recovery time objective (RTO) for a key system does not align with the enterprise's business continuity plan (BCP). Which of the following should be done NEXT?
Which of the following is the BEST way to assess the effectiveness of an access management process?
A risk practitioner has identified that the agreed recovery time objective (RTO) with a Software as a Service (SaaS) provider is longer than the business expectation. Which of the following is the risk practitioner's BEST course of action?
During an IT department reorganization, the manager of a risk mitigation action plan was replaced. The new manager has begun implementing a new control after identifying a more effective option. Which of the following is the risk practitioner's BEST course of action?
Which of the following is the FIRST consideration to reduce risk associated with the storage of personal data?
Which of the following should be the HIGHEST priority when developing a risk response?
Which of the following is the BEST way to support communication of emerging risk?
The PRIMARY reason for periodically monitoring key risk indicators (KRIs) is to:
An organization has decided to implement an emerging technology and incorporate the new capabilities into its strategic business plan. Business operations for the technology will be outsourced. What will be the risk practitioner's PRIMARY role during the change?
Which of the following is the BEST way to address a board's concern about the organization's current cybersecurity posture?
To enable effective integration of IT risk scenarios and ERM, it is MOST important to have a consistent approach to reporting: