A monthly payment report is generated from the enterprise resource planning (ERP) software to validate data against the old and new payroll systems. What is the BEST way to mitigate the risk associated with data integrity loss in the new payroll system after data migration?
A risk practitioner notes control design changes when comparing risk response to a previously approved action plan. Which of the following is MOST important for the practitioner to confirm?
Which of the following is the MOST important document regarding the treatment of sensitive data?
Which of the following is MOST important for an organization to consider when developing its IT strategy?
A risk practitioner is MOST likely to use a SWOT analysis to assist with which risk process?
Which of the following should a risk practitioner review FIRST when evaluating risk events associated with the organization ' s data flow model?
Which of the following would be MOST useful when measuring the progress of a risk response action plan?
A risk practitioner has reviewed new international regulations and realizes the new regulations will affect the organization. Which of the following should be the risk practitioner ' s NEXT course of
action?
Which of the following provides a risk practitioner with the MOST reliable evidence of a third party ' s ability to protect the confidentiality of sensitive corporate information?
Which of the following should be done FIRST when developing an initial set of risk scenarios for an organization?
Which of the following is PRIMARILY a risk management responsibly of the first line of defense?
An organization is implementing encryption for data at rest to reduce the risk associated with unauthorized access. Which of the following MUST be considered to assess the residual risk?
Which of the following should be the MOST important consideration for senior management when developing a risk response strategy?
Which of the following is the MOST useful information for a risk practitioner when planning response activities after risk identification?
Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?
Which of the following would be MOST helpful to a risk practitioner when ensuring that mitigated risk remains within acceptable limits?
Which of the following would provide the MOST comprehensive information for updating an organization ' s risk register?
During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?
Which of the following is the PRIMARY risk management responsibility of the second line in the three lines model?
An organization is considering allowing users to access company data from their personal devices. Which of the following is the MOST important factor when assessing the risk?
Reviewing which of the following BEST helps an organization gam insight into its overall risk profile ' '
Which of the following is the STRONGEST indication an organization has ethics management issues?
Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?
The PRIMARY benefit of selecting an appropriate set of key risk indicators (KRIs) is that they:
Which of the following data would be used when performing a business impact analysis (BIA)?
Which component of a software inventory BEST enables the identification and mitigation of known vulnerabilities?
A PRIMARY objective of disaster recovery is to:
A risk practitioner observes that hardware failure incidents have been increasing over the last few months. However, due to built-in redundancy and fault-tolerant architecture, there have been no interruptions to business operations. The risk practitioner should conclude that:
A new international data privacy regulation requires personal data to be
disposed after the specified retention period, which is different from the local
regulatory requirement. Which of the following is the risk practitioner ' s
BEST course of action?
Which of the following is the BEST time for an enterprise project management team to use risk analysis?
Which of the following controls BEST addresses the risk of unauthorized disclosure of sensitive data as a result of a lost bring your own device (BYOD) tablet?
An organization practices the principle of least privilege. To ensure access remains appropriate, application owners should be required to review user access rights on a regular basis by obtaining:
Which of the following key risk indicators (KRIs) provides the BEST insight into the risk associated with IT systems being unable to meet the required availability service level in the future?
Which of the following is the PRIMARY objective of a risk awareness program?
Which of the following controls would BEST reduce the risk of account compromise?
Which of the following helps ensure compliance with a nonrepudiation policy requirement for electronic transactions?
An organization is concerned that a change in its market situation may impact the current level of acceptable risk for senior management. As a result, which of the following is MOST important to reevaluate?
Which of the following provides the MOST useful information to trace the impact of aggregated risk across an organization ' s technical environment?
What is the PRIMARY reason an organization should include background checks on roles with elevated access to production as part of its hiring process?
Which of the following is a risk practitioner ' s MOST important course of action when the level of risk has exceeded risk tolerance?
Which of the following BEST enables risk-based decision making in support of a business continuity plan (BCP)?
When of the following standard operating procedure (SOP) statements BEST illustrates appropriate risk register maintenance?
Which of the following is the PRIMARY reason for a risk practitioner to report changes and trends in the IT risk profile to senior management?
Which of the following is the BEST source for identifying key control indicators (KCIs)?
The BEST way to mitigate the high cost of retrieving electronic evidence associated with potential litigation is to implement policies and procedures for:
Which of the following should be an element of the risk appetite of an organization?
Which of the following BEST contributes to the implementation of an effective risk response action plan?
Which of the following practices BEST mitigates risk related to enterprise-wide ethical decision making in a multi-national organization?
Which of the following is a PRIMARY benefit of engaging the risk owner during the risk assessment process?
Which of the following is MOST important to communicate to senior management during the initial implementation of a risk management program?