Which of the following BEST enables senior management to make risk treatment decisions in line with the organization ' s risk appetite?
Optimized risk management is achieved when risk is reduced:
Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?
A risk practitioner has been asked to mark an identified control deficiency as remediated, despite concerns that the risk level is still too high. Which of the following is the BEST way to address this concern?
Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?
Which of the following is the BEST key performance indicator (KPI) for determining how well an IT policy is aligned to business requirements?
When developing a new risk register, a risk practitioner should focus on which of the following risk management activities?
Which of the following should be the FIRST step when a company is made aware of new regulatory requirements impacting IT?
An organization ' s stakeholders are unable to agree on appropriate risk responses. Which of the following would be the BEST course of action?
Which of the following would prompt changes in key risk indicator {KRI) thresholds?
Which of the following should be the PRIMARY driver for an organization on a multi-year cloud implementation to publish a cloud security policy?
When developing risk treatment alternatives for a Business case, it is MOST helpful to show risk reduction based on:
Which of the following is the MOST useful information for prioritizing risk mitigation?
Which of the following is BEST measured by key control indicators (KCIs)?
Which of the following is the PRIMARY factor in determining a recovery time objective (RTO)?
What is the BEST approach for determining the inherent risk of a scenario when the actual likelihood of the risk is unknown?
Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?
Which of the following has the GREATEST positive impact on ethical compliance within the risk management process?
A risk practitioner learns that a risk owner has been accepting gifts from a supplier of IT products. Some of these IT products are used to implement controls and to mitigate risk to acceptable levels. Which of the following should the risk practitioner do FIRST?
Which of the following is MOST important for an organization to consider when developing its IT strategy?
The MOST effective approach to prioritize risk scenarios is by:
Which of the following IT controls is MOST useful in mitigating the risk associated with inaccurate data?
Risk management strategies are PRIMARILY adopted to:
Which of the following BEST assists in justifying an investment in automated controls?
Which of the following is the BEST way to determine the ongoing efficiency of control processes?
Which of the following approaches would BEST help to identify relevant risk scenarios?
Which of the following BEST enforces access control for an organization that uses multiple cloud technologies?
Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?
Which of the following is the MOST relevant information to include in a risk management strategy?
Which of the following criteria associated with key risk indicators (KRIs) BEST enables effective risk monitoring?
An organization has just implemented changes to close an identified vulnerability that impacted a critical business process. What should be the NEXT course of action?
Which of the following is the MOST appropriate action when a tolerance threshold is exceeded?
Which of the following would be MOST helpful to a risk practitioner when ensuring that mitigated risk remains within acceptable limits?
Following the identification of a risk associated with a major organizational change, which of the following is MOST important to update in the IT risk register?
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:
Which of the following would BEST mitigate the ongoing risk associated with operating system (OS) vulnerabilities?
Which of the following is MOST important to include when reporting the effectiveness of risk management to senior management?
Which of the following is MOST important to determine when assessing the potential risk exposure of a loss event involving personal data?
An internally developed payroll application leverages Platform as a Service (PaaS) infrastructure from the cloud. Who owns the related data confidentiality risk?
Which of the following is of GREATEST concern when uncontrolled changes are made to the control environment?
Which of the following would be MOST beneficial as a key risk indicator (KRI)?
Which of the following is the MOST effective way to evaluate control implementation processes?
What would be a risk practitioner ' s BEST recommendation when several key performance indicators (KPIs) for a control process fail to meet service level agreements (SLAs)?
Which of the following BEST indicates how well a web infrastructure protects critical information from an attacker?
Which of the following is the BEST indication of an effective risk management program?
An organization ' s financial analysis department uses an in-house forecasting application for business projections. Who is responsible for defining access roles to protect the sensitive data within this application?
Which of the following roles is BEST suited to help a risk practitioner understand the impact of IT-related events on business objectives?
A risk assessment has identified that departments have installed their own WiFi access points on the enterprise network. Which of the following would be MOST important to include in a report to senior management?
An external security audit has reported multiple findings related to control noncompliance. Which of the following would be MOST important for the risk practitioner to communicate to senior management?