Which of the following provides the BEST evidence that risk responses are effective?
Which of the following factors will have the GREATEST impact on the implementation of a risk mitigation strategy for an organization?
The PRIMARY focus of an ongoing risk awareness program should be to:
The BEST way for management to validate whether risk response activities have been completed is to review:
It is MOST important that entries in an organization’s risk register be updated:
Senior management has asked the risk practitioner for the overall residual risk level for a process that contains numerous risk scenarios. Which of the following should be provided?
Which of the following is MOST helpful in identifying gaps between the current and desired state of the IT risk environment?
Which of the following should be determined FIRST when a new security vulnerability is made public?
Which of the following presents the GREATEST challenge to managing an organization ' s end-user devices?
A risk practitioner has been asked to mark an identified control deficiency as remediated, despite concerns that the risk level is still too high. Which of the following is the BEST way to address this concern?
A peer review of a risk assessment finds that a relevant threat community was not included. Mitigation of the risk will require substantial changes to a software application. Which of the following is the BEST course of action?
A risk practitioner is involved in a comprehensive overhaul of the organizational risk management program. Which of the following should be reviewed FIRST to help identify relevant IT risk scenarios?
Which of the following BEST facilitates the identification of emerging risk?
A risk practitioner has been notified of a social engineering attack using artificial intelligence (AI) technology to impersonate senior management personnel. Which of the following would BEST mitigate the impact of such attacks?
Which of the following sources is MOST relevant to reference when updating security awareness training materials?
Which of the following is MOST effective in continuous risk management process improvement?
Which of the following is the MOST effective way to help ensure future risk levels do not exceed the organization ' s risk appetite?
An organization is subject to a new regulation that requires nearly real-time recovery of its services following a disruption. Which of the following is the BEST way to manage the risk in this situation?
An organization moved its payroll system to a Software as a Service (SaaS) application. A new data privacy regulation stipulates that data can only be processed within the countrywhere it is collected. Which of the following should be done FIRST when addressing this situation?
In an organization with a mature risk management program, which of the following would provide the BEST evidence that the IT risk profile is up to date?
Which of the following would be MOST useful to senior management when determining an appropriate risk response?
Which of the following is the BEST indicator of the effectiveness of a control?
Which of the following would BEST enable mitigation of newly identified risk factors related to internet of Things (loT)?
Which of the following is MOST helpful to management when determining the resources needed to mitigate a risk?
Which of the following is the MOST effective way to determine if a risk factor exceeds risk tolerance?
Which of the following is the GREATEST concern when establishing key risk indicators (KRIs)?
Which of the following is the PRIMARY objective of risk management?
Which of the following should be done FIRST when information is no longer required to support business objectives?
Which of the following is MOST important to the integrity of a security log?
As part of an aggressive new marketing strategy, an organization has decided to implement an emerging technology in a critical business system. Which of the following is the BEST course of action to address the risk associated with this new technology?
An effective control environment is BEST indicated by controls that:
Which of the following is the MOST appropriate key control indicator (KCI) to help an organization prevent successful cyber risk events on the external-facing infrastructure?
Which of the following would MOST effectively enable a business operations manager to identify events exceeding risk thresholds?
When reporting on risk for the purpose of initiating required corrective actions, the results should be submitted to the:
A vendor ' s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?
The PRIMARY goal of a risk management program is to:
A risk practitioner notices a risk scenario associated with data loss at the organization ' s cloud provider is assigned to the provider who should the risk scenario be reassigned to.
When determining the accuracy of a key risk indicator (KRI), it is MOST important that the indicator:
An organization is increasingly concerned about loss of sensitive data and asks the risk practitioner to assess the current risk level. Which of the following should the risk practitioner do FIRST?
Which of the following should be the PRIMARY consideration for a startup organization that has decided to adopt externally-sourced security policies?
A recent regulatory requirement has the potential to affect an organization ' s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?
An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner ' s FIRST course of action?
When performing a risk assessment of a new service to support a core business process, which of the following should be done FIRST to ensure continuity of operations?
An employee lost a personal mobile device that may contain sensitive corporate information. What should be the risk practitioner ' s recommendation?
Which of the following BEST indicates that an organization ' s disaster recovery plan (DRP) will mitigate the risk of the organization failing to recover from a major service disruption?
Which of the following is a risk practitioner ' s MOST important responsibility in managing risk acceptance that exceeds risk tolerance?
Which of the following is the GREATEST benefit of identifying appropriate risk owners?
Which of the following is MOST important to consider when determining a recovery time objective (RTO)?
Within the three lines of defense model, the responsibility for managing risk and controls resides with: