Who should be accountable for ensuring effective cybersecurity controls are established?
Which of the following is MOST important to determine when assessing the potential risk exposure of a loss event involving personal data?
A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner s NEXT step? r
Which of the following is the BEST way to mitigate the risk to IT infrastructure availability?
Which of the following is MOST helpful to ensure effective security controls for a cloud service provider?
Which of the following is performed after a risk assessment is completed?
Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?
Which of the following will be MOST effective to mitigate the risk associated with the loss of company data stored on personal devices?
Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?
Which of the following BEST enables a risk practitioner to understand management ' s approach to organizational risk?
After a risk has been identified, who is in the BEST position to select the appropriate risk treatment option?
Which of the following groups represents the first line of defense?
What is the MOST effective approach to promote ethical decision-making in a global organization?
Which of the following is the BEST time for an enterprise project management team to use risk analysis?
Which of the following BEST helps to ensure disaster recovery staff members
are able to complete their assigned tasks effectively during a disaster?
After identifying new risk events during a project, the project manager s NEXT step should be to:
An organization ' s IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?
A recent regulatory requirement has the potential to affect an organization’s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?
A risk assessment indicates the residual risk associated with a new bring your own device (BYOD) program is within organizational risk tolerance. Which of the following should the risk practitioner
recommend be done NEXT?
Which of the following is the BEST approach when a risk practitioner has been asked by a business unit manager to exclude an in-scope system from a risk assessment?
Which of the following will be MOST effective in helping to ensure control failures are appropriately managed?
Which of the following is the GREATEST benefit of centralizing IT systems?
Which of the following is MOST important to ensure when reviewing an organization ' s risk register?
During a routine check, a system administrator identifies unusual activity indicating an intruder within a firewall. Which of the following controls has MOST likely been compromised?
When of the following is the BEST key control indicator (KCI) to determine the effectiveness of en intrusion prevention system (IPS)?
Which of the following BEST reduces the likelihood of employees unintentionally disclosing sensitive information to outside parties?
An organization has decided to implement a new Internet of Things (loT) solution. Which of the following should be done FIRST when addressing security concerns associated with this new technology?
Which of the following BEST protects organizational data within a production cloud environment?
Which of the following is the BEST indicator of the effectiveness of a control monitoring program?
Which of the following poses the GREATEST risk to an organization ' s operations during a major it transformation?
Which of the following is the MOST important for an organization to have in place to ensure IT asset protection?
A business delegates its application data management to the internal IT team. Which of the following is the role of the internal IT team in this situation?
An organization ' s risk tolerance should be defined and approved by which of the following?
An organization uses one centralized single sign-on (SSO) control to cover many applications. Which of the following is the BEST course of action when a new application is added to the environment after testing of the SSO control has been completed?
The MOST important objective of information security controls is to:
Which of the following should be done FIRST when developing a data protection management plan?
Which type of cloud computing deployment provides the consumer the GREATEST degree of control over the environment?
The software version of an enterprise ' s critical business application has reached end-of-life and is no longer supported by the vendor. IT has decided to develop an in-house replacement application. Which of the following should be the PRIMARY concern?
Which of the following would BEST facilitate the implementation of data classification requirements?
The MOST essential content to include in an IT risk awareness program is how to:
While reviewing the risk register, a risk practitioner notices that different business units have significant variances in inherent risk for the same risk scenario. Which of the following is the BEST course of action?
Which of the following would MOST likely drive the need to review and update key performance indicators (KPIs) for critical IT assets?
The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of:
A global company s business continuity plan (BCP) requires the transfer of its customer information….
event of a disaster. Which of the following should be the MOST important risk consideration?
Which of the following is the BEST key control indicator (KCI) for risk related to IT infrastructure failure?
Which of the following would be a weakness in procedures for controlling the migration of changes to production libraries?
When developing a risk awareness training program, which of the following is the BEST way to promote a risk-aware culture?
Which of the following issues should be of GREATEST concern when evaluating existing controls during a risk assessment?
A robotic process automation (RPA) project has implemented new robots to enhance the efficiency of a sales business process. Which of the following provides the BEST evidence that the new controls have been implemented successfully?