Which of the following is the MOST important reason to integrate IT risk management practices into the enterprise-wide operational risk management framework?
Which of the following should a risk practitioner recommend be done prior to disposal of server hardware containing confidential data?
The PRIMARY objective of the board of directors periodically reviewing the risk profile is to help ensure:
A risk practitioner is collaborating with key stakeholders to prioritize a large number of IT risk scenarios. Which scenarios should receive the PRIMARY focus?
Which of the following controls would BEST reduce the likelihood of a successful network attack through social engineering?
Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?
A vendor’s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?
Which of the following is the MOST important enabler of effective risk management?
Which of the following is MOST important for maintaining the effectiveness of an IT risk register?
Which of the following is of GREATEST concern when uncontrolled changes are made to the control environment?
Days before the realization of an acquisition, a data breach is discovered at the company to be acquired. For the accruing organization, this situation represents which of the following?
The analysis of which of the following will BEST help validate whether suspicious network activity is malicious?
Which of the following has the GREATEST impact on ensuring the alignment of the risk profile with business objectives?
From a risk management perspective, which of the following is the PRIMARY benefit of using automated system configuration validation tools?
Which of the following is a risk practitioner ' s BEST course of action when a control is not meeting agreed-upon performance criteria?
From a data protection and regulatory compliance perspective, which of the following is the MOST important reason for a global organization to use immutable backups?
Risk mitigation procedures should include:
Which of the following techniques is MOST helpful when quantifying the potential loss impact of cyber risk?
Which element of an organization ' s risk register is MOST important to update following the commissioning of a new financial reporting system?
Which of the following should be management ' s PRIMARY focus when key risk indicators (KRIs) begin to rapidly approach defined thresholds?
Which of the following is the MOST critical consideration when awarding a project to a third-party service provider whose servers are located offshore?
Which of the following activities BEST facilitates effective risk management throughout the organization?
When evaluating a number of potential controls for treating risk, it is MOST important to consider:
Which of the following is the BEST key control indicator (KCI) for measuring the security of a blockchain network?
When a high number of approved exceptions are observed during a review of a control procedure, an organization should FIRST initiate a review of the:
Which of the following is the MOST important reason for a risk practitioner to identify stakeholders for each IT risk scenario?
Which of the following stakeholders define risk tolerance for an enterprise?
Which of the following provides the BEST assurance of…..
The BEST way to improve a risk register is to ensure the register:
If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7
The MOST important characteristic of an organization s policies is to reflect the organization ' s:
The PRIMARY objective of collecting information and reviewing documentation when performing periodic risk analysis should be to:
The MAIN purpose of a risk register is to:
A newly enacted information privacy law significantly increases financial penalties for breaches of personally identifiable information (Pll). Which of the following will MOST likely outcome for an organization affected by the new law?
Which of the following is the MOST important course of action to foster an ethical, risk-aware culture?
A risk practitioner has been asked to assess the risk associated with a new critical application used by a financial process team that the risk practitioner was a member of two years ago. Which of the following is the GREATEST concern with this request?
A bank has outsourced its statement printing function to an external service provider. Which of the following is the MOST critical requirement to include in the contract?
Which of the following practices MOST effectively safeguards the processing of personal data?
An organization automatically approves exceptions to security policies on a recurring basis. This practice is MOST likely the result of:
Which of the following is MOST essential for an effective change control environment?
From a governance perspective, which of the following is MOST important to ensure when risk management policies are being updated to facilitate the pursuit of new opportunities?
An organization requires data owners to perform a quarterly review of all privileged users on key financial systems. What type of control does this represent?
What should a risk practitioner do FIRST when an assessment reveals a control is not operating as intended?
Which of the following is MOST important requirement to include in a Software as a Service (SaaS) vendor contract to ensure data is protected?
Which of the following BEST measures the efficiency of an incident response process?
Which of the following would BEST help minimize the risk associated with social engineering threats?
The acceptance of control costs that exceed risk exposure is MOST likely an example of:
Reviewing which of the following provides the BEST indication of an organizations risk tolerance?
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:
Which of the following is MOST important to consider when selecting and designing key control indicators (KCIs)?