Which of the following BEST helps to ensure disaster recovery staff members
are able to complete their assigned tasks effectively during a disaster?
Which of the following should be the PRIMARY focus of an IT risk awareness program?
Which of the following is the GREATEST advantage of implementing a risk management program?
During an IT department reorganization, the manager of a risk mitigation action plan was replaced. The new manager has begun implementing a new control after identifying a more effective option. Which of the following is the risk practitioner ' s BEST course of action?
Which of the following is MOST important for developing effective key risk indicators (KRIs)?
An organization has granted a vendor access to its data in order to analyze customer behavior. Which of the following would be the MOST effective control to mitigate the risk of customer data leakage?
Which of the following would be MOST helpful to a risk practitioner when ensuring that mitigated risk remains within acceptable limits?
A newly enacted information privacy law significantly increases financial penalties for breaches of personally identifiable information (Pll). Which of the following will MOST likely outcome for an organization affected by the new law?
Which of the following should be the FIRST course of action if the risk associated with a new technology is found to be increasing?
The head of a business operations department asks to review the entire IT risk register. Which of the following would be the risk manager s BEST approach to this request before sharing the register?
IT management has asked for a consolidated view into the organization ' s risk profile to enable project prioritization and resource allocation. Which of the following materials would
be MOST helpful?
Which of the following is necessary to enable an IT risk register to be consolidated with the rest of the organization’s risk register?
Which of the following provides the MOST important information to facilitate a risk response decision?
Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of a disaster recovery test of critical business processes?
Which of the following is the PRIMARY reason to perform ongoing risk assessments?
Which of the following provides the MOST useful information when assessing whether an organization has appropriately managed its level of risk compared to its established risk appetite?
After the implementation of internal of Things (IoT) devices, new risk scenarios were identified. What is the PRIMARY reason to report this information to risk owners?
Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?
What are the MOST important criteria to consider when developing a data classification scheme to facilitate risk assessment and the prioritization of risk mitigation activities?
Which of the following management actions will MOST likely change the likelihood rating of a risk scenario related to remote network access?
Which of the following should be the PRIMARY area of focus when reporting changes to an organization ' s risk profile to executive management?
Which of the following is the MOST important reason to revisit a previously accepted risk?
An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?
A control owner identifies that the organization ' s shared drive contains personally identifiable information (Pll) that can be accessed by all personnel. Which of the following is the MOST effective risk response?
The PRIMARY advantage of involving end users in continuity planning is that they:
Which of the following would have the GREATEST impact on reducing the risk associated with the implementation of a big data project?
Which of the following is MOST important for an organization to have in place to identify unauthorized devices on the network?
The risk to an organization ' s reputation due to a recent cybersecurity breach is PRIMARILY considered to be:
Which of the following is the BEST way to ensure ongoing control effectiveness?
Which of the following is the MOST important consideration when developing risk strategies?
Which of the following is the BEST way to determine software license compliance?
Which of the following would provide the MOST useful information for communicating an organization’s risk level to senior management?
What would be the MAIN concern associated with a decentralized IT function maintaining multiple risk registers?
Establishing and organizational code of conduct is an example of which type of control?
An application runs a scheduled job that compiles financial data from multiple business systems and updates the financial reporting system. If this job runs too long, it can delay financial reporting. Which of the following is the risk practitioner ' s BEST recommendation?
Which component of a software inventory BEST enables the identification and mitigation of known vulnerabilities?
Which of the following is a risk practitioner ' s MOST important course of action when the level of risk has exceeded risk tolerance?
An organization has implemented a preventive control to lock user accounts after three unsuccessful login attempts. This practice has been proven to be unproductive, and a change in the control threshold value has been recommended. Who should authorize changing this threshold?
Which of the following is the BEST way to ensure adequate resources will be allocated to manage identified risk?
A risk practitioner has just learned about new malware that has severely impacted industry peers worldwide data loss?
Which of the following is the BEST approach for performing a business impact analysis (BIA) of a supply-chain management application?
An organization is considering outsourcing user administration controls tor a critical system. The potential vendor has offered to perform quarterly sett-audits of its controls instead of having annual independent audits. Which of the following should be of GREATEST concern to me risk practitioner?
Which of the following is the BEST way to determine the value of information assets for risk management purposes?
Which of the following has the GREATEST influence on an organization ' s risk appetite?