When establishing an enterprise IT risk management program, it is MOST important to:
Which of the following should management consider when selecting a risk mitigation option?
Which of the following is the PRIMARY concern for a risk practitioner regarding an organization ' s adoption of innovative big data analytics capabilities?
When developing risk scenario using a list of generic scenarios based on industry best practices, it is MOST imported to:
When evaluating enterprise IT risk management it is MOST important to:
Which of the following is the MOST effective control to ensure user access is maintained on a least-privilege basis?
Which of the following is the MOST important concern when assigning multiple risk owners for an identified risk?
Which of the following BEST facilitates the identification of appropriate key performance indicators (KPIs) for a risk management program?
It is MOST important that entries in an organization’s risk register be updated:
An organization uses a vendor to destroy hard drives. Which of the following would BEST reduce the risk of data leakage?
The MAIN reason a risk practitioner should review control assessment reports is to:
Which of the following controls would BEST reduce the risk of account compromise?
A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?
What would be the MAIN concern associated with a decentralized IT function maintaining multiple risk registers?
In an organization where each division manages risk independently, which of the following would BEST enable management of risk at the enterprise level?
Which of the following has the MOST validity for conducting risk assessments?
Which of the following offers the SIMPLEST overview of changes in an organization ' s risk profile?
Which of the following is MOST likely to introduce risk for financial institutions that use blockchain?
Which of the following is the MOST important consideration when determining the appropriate data retention period throughout the data management life cycle?
Which of the following provides the MOST helpful information in identifying risk in an organization?
A key risk indicator (KRI) indicates a reduction in the percentage of appropriately patched servers. Which of the following is the risk practitioner ' s BEST course of action?
Which of the following would BEST ensure that identified risk scenarios are addressed?
Which of the following is the MAIN purpose of monitoring risk?
The BEST way to mitigate the high cost of retrieving electronic evidence associated with potential litigation is to implement policies and procedures for:
What should be the PRIMARY driver for periodically reviewing and adjusting key risk indicators (KRIs)?
Which of the following BEST indicates the effectiveness of anti-malware software?
An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:
Which risk analysis methodology uses diagrams to analyze causes and consequences of particular risk events?
An organization ' s Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?
Which of the following provides the MOST insight into an organization ' s IT threat exposure?
When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?
Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?
Who should be responsible for strategic decisions on risk management?
Which of the following is the MOST useful information for prioritizing risk mitigation?
An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?
An organization has asked an IT risk practitioner to conduct an operational risk assessment on an initiative to outsource the organization ' s customer service operations overseas. Which of the following would MOST significantly impact management ' s decision?
Which of these documents is MOST important to request from a cloud service
provider during a vendor risk assessment?
During an organization ' s simulated phishing email campaign, which of the following is the BEST indicator of a mature security awareness program?
Which of the following is the FIRST step in risk assessment?
Which of the following would BEST help to determine the inherent risk associated with a cloud service provider?
Which of the following BEST indicates that an organization has implemented IT performance requirements?
Which of the following is a risk practitioner ' s MOST important action to reduce the likelihood of internal fraud?
The BEST metric to demonstrate that servers are configured securely is the total number of servers:
Business management is seeking assurance from the CIO that IT has a plan in place for early identification of potential issues that could impact the delivery of a new application Which of the following is the BEST way to increase the chances of a successful delivery ' ?
Which of the following would be MOST helpful in assessing the risk associated with data loss due to human vulnerabilities?
Which of the following is the BEST way to incorporate continuous monitoring in IT risk policies?
In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities. The risk practitioner ' s BEST recommendation to further reduce the impact of ransomware attacks would be to implement:
Which of the following is the PRIMARY role of the first line of defense with respect to information security policies?
Which of the following is the MOST effective way for a large and diversified organization to minimize risk associated with unauthorized software on company devices?
An organization has implemented a system capable of comprehensive employee monitoring. Which of the following should direct how the system is used?