Which of the following risk impacts should be the PRIMARY consideration for determining recovery priorities in a disaster recovery situation?
Which of the following is MOST likely to be impacted as a result of a new policy which allows staff members to remotely connect to the organization ' s IT systems via personal or public computers?
The PRIMARY benefit of classifying information assets is that it helps to:
Which of the following is the MOST important outcome of a business impact analysis (BIA)?
Which of the following is MOST important for a multinational organization to consider when developing its security policies and standards?
During a risk assessment, the risk practitioner finds a new risk scenario without controls has been entered into the risk register. Which of the following is the MOST appropriate action?
An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?
Which of the following is MOST important for a risk practitioner to update when a software upgrade renders an existing key control ineffective?
Which of the following tools is MOST effective in identifying trends in the IT risk profile?
Which of the following is the BEST way to estimate the impact of an inherent risk over the next year?
Which of the following is MOST helpful in reducing the likelihood of inaccurate risk assessment results?
Which of the following is the MAIN benefit to an organization using key risk indicators (KRIs)?
Which of the following controls are BEST strengthened by a clear organizational code of ethics?
A financial institution has identified high risk of fraud in several business applications. Which of the following controls will BEST help reduce the risk of fraudulent internal transactions?
Which of the following is the MOST important topic to cover in a risk awareness training program for all staff?
Which of the following facilitates a completely independent review of test results for evaluating control effectiveness?
After mapping generic risk scenarios to organizational security policies, the NEXT course of action should be to:
What can be determined from the risk scenario chart?

The BEST key performance indicator (KPI) to measure the effectiveness of a vendor risk management program is the percentage of:
Which of the following occurs during the implementation phase of the system development life cycle (SDLC)?
Winch of the following can be concluded by analyzing the latest vulnerability report for the it infrastructure?
When developing a business continuity plan (BCP), it is MOST important to:
An organization has introduced risk ownership to establish clear accountability for each process. To ensure effective risk ownership, it is MOST important that:
Which of the following is the BEST indication of an enhanced risk-aware culture?
During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?
For no apparent reason, the time required to complete daily processing for a legacy application is approaching a risk threshold. Which of the following activities should be performed FIRST?
Which of the following is the GREATEST concern related to the monitoring of key risk indicators (KRIs)?
Which of the following groups represents the first line of defense?
Which of the following would BEST support the integrity of online financial transactions?
Which of the following presents the GREATEST risk to change control in business application development over the complete life cycle?
Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?
A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?
When assessing the maturity level of an organization ' s risk management framework, which of the following deficiencies should be of GREATEST concern to a risk practitioner?
A company has located its computer center on a moderate earthquake fault. Which of the following is the MOST important consideration when establishing a contingency plan and an alternate processing site?
Which of the following is the MOST important consideration when determining the appropriate data retention period throughout the data management life cycle?
Which of the following represents a vulnerability?
Which of the following is the PRIMARY responsibility of the first line of defense related to computer-enabled fraud?
Winch of the following key control indicators (KCIs) BEST indicates whether security requirements are identified and managed throughout a project He cycle?
A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner ' s NEXT step?
To reduce costs, an organization is combining the second and third tines of defense in a new department that reports to a recently appointed C-level executive. Which of the following is the GREATEST concern with this situation?
Which of the following BEST balances the costs and benefits of managing IT risk*?
Which of the following is the MOST reliable validation of a new control?
Which of the following is MOST important for maintaining the effectiveness of an IT risk register?
Which of the following practices MOST effectively safeguards the processing of personal data?
Which of the following BEST mitigates reputational risk associated with disinformation campaigns against an organization?
Which of the following BEST indicates that additional or improved controls ate needed m the environment?
Which of the following provides the BEST evidence of the effectiveness of an organization ' s account provisioning process?
Which key performance indicator (KPI) BEST measures the effectiveness of an organization ' s disaster recovery program?
Which of the following is the MOST effective way to incorporate stakeholder concerns when developing risk scenarios?