A root because analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators Who should be accountable for resolving the situation?
An organization is planning to move its application infrastructure from on-premises to the cloud. Which of the following is the BEST course of the actin to address the risk associated with data transfer if the relationship is terminated with the vendor?
The following is the snapshot of a recently approved IT risk register maintained by an organization's information security department.
After implementing countermeasures listed in ‘’Risk Response Descriptions’’ for each of the Risk IDs, which of the following component of the register MUST change?
An organization has recently hired a large number of part-time employees. During the annual audit, it was discovered that many user IDs and passwords were documented in procedure manuals for use by the part-time employees. Which of the following BEST describes this situation?
Which of the following is the BEST way to ensure data is properly sanitized while in cloud storage?
The BEST way to mitigate the high cost of retrieving electronic evidence associated with potential litigation is to implement policies and procedures for.
Which of the following is the MOST important consideration when developing risk strategies?
Which of the following is MOST helpful in defining an early-warning threshold associated with insufficient network bandwidth’’?
Which of the following should be the PRIMARY basis for prioritizing risk responses?
An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
An organization is implementing robotic process automation (RPA) to streamline business processes. Given that implementation of this technology is expected to impact existing controls, which of the following is the risk practitioner's BEST course of action?
Which of the following would be a risk practitioner’s BEST recommendation upon learning of an updated cybersecurity regulation that could impact the organization?
Which of the following issues found during the review of a newly created disaster recovery plan (DRP) should be of MOST concern?
An organization wants to launch a campaign to advertise a new product Using data analytics, the campaign can be targeted to reach potential customers. Which of the following should be of GREATEST concern to the risk practitioner?
Which of the following is MOST important to the effectiveness of key performance indicators (KPIs)?
A newly incorporated enterprise needs to secure its information assets From a governance perspective which of the following should be done FIRST?
Which of the following is a risk practitioner's MOST important responsibility in managing risk acceptance that exceeds risk tolerance?
Which of the following is the MOST effective way to reduce potential losses due to ongoing expense fraud?
An organization recently configured a new business division Which of the following is MOST likely to be affected?
Which of the following would provide the MOST helpful input to develop risk scenarios associated with hosting an organization's key IT applications in a cloud environment?
Which of the following would be a risk practitioner's GREATEST concern with the use of a vulnerability scanning tool?
If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7
A bank recently incorporated Blockchain technology with the potential to impact known risk within the organization. Which of the following is the risk practitioner’s BEST course of action?
Reviewing which of the following BEST helps an organization gam insight into its overall risk profile''
When is the BEST to identify risk associated with major project to determine a mitigation plan?
Which of the following stakeholders are typically included as part of a line of defense within the three lines of defense model?
Which of the following would BEST facilitate the implementation of data classification requirements?
Which of the following would provide the MOST reliable evidence of the effectiveness of security controls implemented for a web application?
Which of The following BEST represents the desired risk posture for an organization?
An organization automatically approves exceptions to security policies on a recurring basis. This practice is MOST likely the result of:
Which of the following poses the GREATEST risk to an organization's operations during a major it transformation?
Which of the following BEST indicates the condition of a risk management program?
Which of the following is necessary to enable an IT risk register to be consolidated with the rest of the organization’s risk register?
Which type of indicators should be developed to measure the effectiveness of an organization's firewall rule set?
Which of the following should be the PRIMARY focus of an IT risk awareness program?
The PRIMARY advantage of involving end users in continuity planning is that they:
An organization recently received an independent security audit report of its cloud service provider that indicates significant control weaknesses. What should be done NEXT in response to this report?
The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:
Which of the following is a drawback in the use of quantitative risk analysis?
An organization has been notified that a disgruntled, terminated IT administrator has tried to break into the corporate network. Which of the following discoveries should be of GREATEST concern to the organization?
Winch of the following key control indicators (KCIs) BEST indicates whether security requirements are identified and managed throughout a project He cycle?
Winch of the following can be concluded by analyzing the latest vulnerability report for the it infrastructure?
Which of the following statements BEST illustrates the relationship between key performance indicators (KPIs) and key control indicators (KCIs)?
The BEST metric to monitor the risk associated with changes deployed to production is the percentage of:
When performing a risk assessment of a new service to support a ewe Business process. which of the following should be done FRST10 ensure continuity of operations?
Which of the following is the BEST way to determine whether new controls mitigate security gaps in a business system?