An organization is implementing internet of Things (loT) technology to control temperature and lighting in its headquarters. Which of the following should be of GREATEST concern?
A root because analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators Who should be accountable for resolving the situation?
Which of the following is MOST important to consider when selecting risk indicators (KRIs)? The ability to:
Which of the following is MOST important when identifying an organization ' s risk exposure associated with Internet of Things (loT) devices?
An organization has outsourced its ERP application to an external SaaS provider. Which of the following provides the MOST useful information to identify risk scenarios involving data loss?
When an organization ' s business continuity plan (BCP) states that it cannot afford to lose more than three hours of a critical application ' s data, the three hours is considered the application’s:
An organization mandates the escalation of a service ticket when a key application is offline for 5 minutes or more due to potential risk exposure. The risk practitioner has been asked by management to prepare a report of application offline times using both 3- and 5-minute thresholds. What does the 3-minute threshold represent?
A business unit is unable to fully implement the security policy on a critical business application. Which type of process should be in place to BEST manage the related risk?
Which of the following is the PRIMARY benefit when senior management periodically reviews and updates risk appetite and tolerance levels?
An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization ' s risk appetite and tolerance, which of the following is the risk practitioner ' s BEST recommendation?
A legacy application used for a critical business function relies on software that has reached the end of extended support Which of the following is the MOST effective control to manage this application?
Which of the following BEST facilitates the process of documenting risk tolerance?
An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?
Which of the following is MOST important for an organization to have in place when developing a risk management framework?
Which of the following BEST helps to mitigate risk associated with users inputting incorrect data into a system?
Which of the following presents the GREATEST challenge for an IT risk practitioner who wants to report on trends in historical IT risk levels?
Which of the following would provide the MOST useful information for communicating an organization’s risk level to senior management?
Which of the following would MOST effectively reduce risk associated with an increase of online transactions on a retailer website?
Which of the following BEST enables the integration of IT risk management across an organization?
Which of the following provides the MOST important information to facilitate a risk response decision?
What would be a risk practitioner ' s BEST recommendation when several key performance indicators (KPIs) for a control process fail to meet service level agreements (SLAs)?
An organization has provided legal text explaining the rights and expected behavior of users accessing a system from geographic locations that have strong privacy regulations. Which of the following control types has been applied?
Which of the following provides the MOST useful information for developing key risk indicators (KRIs)?
Which of the following provides the BEST indication that existing controls are effective?
An organization ' s stakeholders are unable to agree on appropriate risk responses. Which of the following would be the BEST course of action?
An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?
An organization has restructured its business processes, and the business continuity plan (BCP) needs to be revised accordingly. Which of the following should be identified FIRST?
In a public company, which group is PRIMARILY accountable for ensuring sufficient attention and resources are applied to the risk management process?
Which of the following s MOST likely to deter an employee from engaging in inappropriate use of company owned IT systems?
Which of the following is the PRIMARY benefit of using a risk profile?
Which of the following is the GREATEST concern associated with business end users developing their own applications on end user spreadsheets and database programs?
A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner ' s BEST course of action when a compensating control needs to be applied?
Which of the following introduces the GREATEST amount of risk during the software development life cycle (SDLC)?
The percentage of unpatched systems is a:
During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?
Which of the following would be the BEST senior management action to influence a strong risk-aware culture within an organization?
A rule-based data loss prevention {DLP) tool has recently been implemented to reduce the risk of sensitive data leakage. Which of the following is MOST likely to change as a result of this implementation?
Which of the following should be the PRIMARY input when designing IT controls?
The results of a risk assessment reveal risk scenarios with high impact and low likelihood of occurrence. Which of the following would be the BEST action to address these scenarios?
A risk practitioner is evaluating policies defined by an organization as part of its IT security framework. Which of the following would be of GREATEST concern?
During a risk assessment, the risk practitioner finds a new risk scenario without controls has been entered into the risk register. Which of the following is the MOST appropriate action?
An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning of the associated risk entries?
Which of the following is MOST important when developing key performance indicators (KPIs)?
Which of the following is MOST likely to increase the likelihood or impact of an identified risk scenario?
Which of the following should be done FIRST when developing an initial set of risk scenarios for an organization?
It is MOST important that security controls for a new system be documented in:
Which of the following is MOST important to ensure risk management practices are effective at all levels within the organization?
Which of the following statements in an organization ' s current risk profile report is cause for further action by senior management?
Which of the following is the GREATEST concern when using artificial intelligence (AI) language models?
The head of a business operations department asks to review the entire IT risk register. Which of the following would be the risk manager s BEST approach to this request before sharing the register?