An IT risk practitioner is evaluating an organization ' s change management controls over the last six months. The GREATEST concern would be an increase in:
An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
A management team is on an aggressive mission to launch a new product to penetrate new markets and overlooks IT risk factors, threats, and vulnerabilities. This scenario BEST demonstrates an organization ' s risk:
A service provider is managing a client’s servers. During an audit of the service, a noncompliant control is discovered that will not be resolved before the next audit because the client cannot afford the downtime required to correct the issue. The service provider’s MOST appropriate action would be to:
Which of the following is the MOST important consideration when establishing a recovery point objective (RPO)?
Which of the following BEST provides an early warning that network access of terminated employees is not being revoked in accordance with the service level agreement (SLA)?
A peer review of a risk assessment finds that a relevant threat community was not included. Mitigation of the risk will require substantial changes to a software application. Which of the following is the BEST course of action?
A bank wants to send a critical payment order via email to one of its offshore branches. Which of the following is the BEST way to ensure the message reaches the intended recipient without alteration?
When developing risk treatment alternatives for a Business case, it is MOST helpful to show risk reduction based on:
Which of the following will BEST help to ensure implementation of corrective action plans?
IT stakeholders have asked a risk practitioner for IT risk profile reports associated with specific departments to allocate resources for risk mitigation. The BEST way to address this request would be to use:
The risk associated with an asset before controls are applied can be expressed as:
Which of the following is MOST important to include in a risk assessment of an emerging technology?
A key risk indicator (KRI) for technology operations has been above risk thresholds for the last three reporting periods. What is the BEST way for a risk practitioner to address this concern?
Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?
An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?
A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:
Which of the following would be MOST helpful when selecting appropriate protection for data?
Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?
Changes in which of the following would MOST likely cause a risk practitioner to adjust the risk impact rating in the risk register?
Which of the following would be the GREATEST challenge when implementing a corporate risk framework for a global organization?
Which of the following would be the GREATEST concern related to data privacy when implementing an Internet of Things (loT) solution that collects personally identifiable information (Pll)?
Which of the following is the MOST important key performance indicator (KPI) for monitoring the user access management process?
Who is the BEST person to the employee personal data?
A risk practitioner is reporting on an increasing trend of ransomware attacks in the industry. Which of the following information is MOST important to include to enable an informed response decision by key stakeholders?
To minimize the risk of a potential acquisition being exposed externally, an organization has selected a few key employees to be engaged in the due diligence process. A member of the due diligence team realizes a close acquaintance is a high-ranking IT professional at a subsidiary of the company about to be acquired. What is the BEST course of action for this team member?
Which of the following is MOST critical when designing controls?
The BEST way to obtain senior management support for investment in a control implementation would be to articulate the reduction in:
Which of the following criteria associated with key risk indicators (KRIs) BEST enables effective risk monitoring?
Which of the following is the PRIMARY purpose of a risk register?
Which of the following is the PRIMARY objective of providing an aggregated view of IT risk to business management?
A risk owner has accepted a high-impact risk because the control was adversely affecting process efficiency. Before updating the risk register, it is MOST important for the risk practitioner to:
Which of the following is the BEST success criterion for control implementation?
Following the implementation of an Internet of Things (loT) solution, a risk practitioner identifies new risk factors with impact to existing controls. Which of the following is MOST important to include in a report to stakeholders?
Which of the following BEST supports ethical IT risk management practices?
Which of the following would be a risk practitioner ' $ BEST recommendation to help ensure cyber risk is assessed and reflected in the enterprise-level risk profile?
Which of the following is a risk practitioner ' s MOST important course of action when the level of risk has exceeded risk tolerance?
Which of the following would BEST provide early warning of a high-risk condition?
A failed IT system upgrade project has resulted in the corruption of an organization ' s asset inventory database. Which of the following controls BEST mitigates the impact of this incident?
Which of the following is the MOST important reason to revisit a previously accepted risk?
The BEST key performance indicator (KPI) for monitoring adherence to an organization ' s user accounts provisioning practices is the percentage of:
Where should a risk practitioner document the current state and desired future state of organizational risk?
Which of the following is the BEST way to reduce the likelihood of an individual performing a potentially harmful action as the result of unnecessary entitlement?
Which of the following is a specific concern related to machine learning algorithms?
Which of the following is the PRIMARY role of the first line within the three lines model?
Which of the following should be accountable for ensuring that media containing financial information are adequately destroyed per an organization ' s data disposal policy?
The cost of maintaining a control has grown to exceed the potential loss. Which of the following BEST describes this situation?
A risk practitioner discovers several key documents detailing the design of a product currently in development have been posted on the Internet. What should be the risk practitioner ' s FIRST course of action?
Which of the following BEST enables an organization to determine whether risk management is aligned with its goals and objectives?
Which of the following is the BEST way to validate whether controls to reduce user device vulnerabilities have been implemented according to management ' s action plan?