The BEST metric to demonstrate that servers are configured securely is the total number of servers:
Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?
The PRIMARY benefit of maintaining an up-to-date risk register is that it helps to:
An organization ' s risk management team wants to develop IT risk scenarios to show the impact of collecting and storing credit card information. Which of the following is the MOST comprehensive approach to capture this scenario?
Which of the following is the MOST important key performance indicator (KPI) for monitoring the user access management process?
A new software package that could help mitigate risk in an organization has become available. Which of the following is the risk practitioner ' s BEST course of action?
A risk practitioner has established that a particular control is working as desired, but the annual cost of maintenance has increased and now exceeds the expected annual loss exposure. The result is that the control is:
A key risk indicator (KRI) is reported to senior management on a periodic basis as exceeding thresholds, but each time senior management has decided to take no action to reduce the risk. Which of the following is the MOST likely reason for senior management ' s response?
Management has required information security awareness training to reduce the risk associated with credential compromise. What is the BEST way to assess the effectiveness of the training?
Which of the following BEST facilitates the mitigation of identified gaps between current and desired risk environment states?
Which of the following is the MOST important course of action to foster an ethical, risk-aware culture?
Which of the following will BEST help to ensure the continued effectiveness of the IT risk management function within an organization experiencing high employee turnover?
Which of the following is the BEST way to help ensure risk will be managed properly after a business process has been re-engineered?
A cote data center went offline abruptly for several hours affecting many transactions across multiple locations. Which of the to " owing would provide the MOST useful information to determine mitigating controls?
Which of the following should be the GREATEST concern for an organization that uses open source software applications?
Which of the following is MOST important information to review when developing plans for using emerging technologies?
Which of the following BEST indicates the efficiency of a process for granting access privileges?
An organization ' s capability to implement a risk management framework is PRIMARILY influenced by the:
A control owner has completed a year-long project To strengthen existing controls. It is MOST important for the risk practitioner to:
To enable effective integration of IT risk scenarios and enterprise risk management (ERM), it is MOST important to have a consistent approach to reporting:
An IT risk practitioner ' s report includes a treatment plan and projected risk ratings if recommendations are implemented. Once corrective actions are taken by the system owner, which of the following types of risk will the projected risk become?
Which of the following key risk indicators (KRIs) is MOST effective for monitoring risk related to a bring your own device (BYOD) program?
The acceptance of control costs that exceed risk exposure is MOST likely an example of:
Which of the following is the MOST important benefit of implementing a data classification program?
Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
An organization is considering the adoption of an aggressive business strategy to achieve desired growth From a risk management perspective what should the risk practitioner do NEXT?
A control for mitigating risk in a key business area cannot be implemented immediately. Which of the following is the risk practitioner ' s BEST course of action when a compensating control needs to be applied?
Which of the following provides the MOST useful information when determining if a specific control should be implemented?
Continuous monitoring of key risk indicators (KRIs) will:
Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?
A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?
A company has located its computer center on a moderate earthquake fault. Which of the following is the MOST important consideration when establishing a contingency plan and an alternate processing site?
Which of the following would offer the MOST insight with regard to an organization ' s risk culture?
Which of the following is the MOST important consideration for prioritizing risk treatment plans when faced with budget limitations?
Which of the following is the GREATEST risk associated with the use of data analytics?
A risk practitioner is preparing a report to communicate changes in the risk and control environment. The BEST way to engage stakeholder attention is to:
A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner ' s FIRST course of action?
Which of the following is the BEST metric to measure the effectiveness of an organization ' s disaster recovery program?
Which of the following is MOST useful when communicating risk to management?
Which of the following is the MOST important consideration when selecting either a qualitative or quantitative risk analysis?
The BEST reason to classify IT assets during a risk assessment is to determine the:
A risk practitioner recently discovered that sensitive data from the production environment is required for testing purposes in non-production environments. Which of the following i the BEST recommendation to address this situation?
It is MOST important for a risk practitioner to have an awareness of an organization s processes in order to:
Which of the following is the MOST important driver of an effective enterprise risk management (ERM) program?
A global company s business continuity plan (BCP) requires the transfer of its customer information….
event of a disaster. Which of the following should be the MOST important risk consideration?
Which of the following is MOST helpful to review when assessing the risk exposure associated with ransomware?
An organization is concerned that its employees may be unintentionally disclosing data through the use of social media sites. Which of the following will MOST effectively mitigate tins risk?
Which of the following will BEST ensure that information security risk factors are mitigated when developing in-house applications?
Which of the following, who should be PRIMARILY responsible for performing user entitlement reviews?
In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities. The risk practitioner ' s BEST recommendation to further reduce the impact of ransomware attacks would be to implement: