Which of the following is the MOST important input when developing risk scenarios?
The PRIMARY objective of the board of directors periodically reviewing the risk profile is to help ensure:
An organization is planning to implement a Zero Trust model. From a cybersecunty perspective, which of the following is MOST important to ensure successful alignment with the overall inten Zero Trust?
Which of the following is the BEST method for determining an enterprise ' s current appetite for risk?
Which of the following is a responsibility of the second line in the three lines model?
A business unit has implemented robotic process automation (RPA) for its
repetitive back-office tasks. Which of the following should be the risk
practitioner ' s GREATEST concern?
When updating a risk register with the results of an IT risk assessment, the risk practitioner should log:
An organization has adopted an emerging technology without following proper processes. Which of the following is the risk practitioner ' s BEST course of action to address this risk?
An organization is considering modifying its system to enable acceptance of credit card payments. To reduce the risk of data exposure, which of the following should the organization do FIRST?
A compensating control is MOST appropriate when:
A recently purchased IT application does not meet project requirements. Of the following, who is accountable for the potential impact?
Which of the following is MOST important for a risk practitioner to confirm once a risk action plan has been completed?
A root because analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators Who should be accountable for resolving the situation?
Which of the following is MOST important to determine when assessing the potential risk exposure of a loss event involving personal data?
Which of the following is a PRIMARY reason for considering existing controls during initial risk assessment?
Which of the following activities is PRIMARILY the responsibility of senior management?
Which of the following is MOST helpful in developing key risk indicator (KRl) thresholds?
Which of the following is MOST important to consider when determining the risk associated with re-identification of obfuscated personal data?
Which of the following is MOST important for effective communication of a risk profile to relevant stakeholders?
Which of the following events is MOST likely to trigger the need to conduct a risk assessment?
The PRIMARY reason to implement a formalized risk taxonomy is to:
Which of the following should be the PRIMARY driver for an organization on a multi-year cloud implementation to publish a cloud security policy?
Well-developed, data-driven risk measurements should be:
A risk assessment has revealed that the probability of a successful cybersecurity attack is increasing. The potential loss could exceed the organization ' s risk appetite. Which of the following ould be the MOST effective course of action?
Which of the following is the GREATEST advantage of implementing a risk management program?
The MAIN purpose of selecting a risk response is to.
Which of the following is the MOST important risk management activity during project initiation?
Which of the following is the MOST appropriate role to determine risk appetite and tolerance?
Which of the following is the PRIMARY reason to conduct risk assessments at periodic intervals?
Which of the following is the BEST way for a risk practitioner to present an annual risk management update to the board ' '
Which of the following is MOST important for managing ethical risk?
Which of the following is the MOST effective way to help ensure future risk levels do not exceed the organization ' s risk appetite?
Which of the following is MOST important to include in a Software as a Service (SaaS) vendor agreement?
Which of the following provides the BEST protection for Internet of Things (loT) devices that are accessed within an organization?
The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:
The BEST key performance indicator (KPI) for monitoring adherence to an organization ' s user accounts provisioning practices is the percentage of:
Which of the following would MOST likely lead to misaligned outcomes from enterprise architecture (EA)?
Which of the following is the PRIMARY purpose of a risk register?
Which of the following is the PRIMARY benefit of implementing key control indicators (KCIs)?
Senior leadership has set guidelines for the integration of a new acquisition. The guidelines allow for a variation in the level of risk-taking. The variation indicates which of the following risk management concepts?
Which of the following is the PRIMARY accountability for a control owner?
Following a business continuity planning exercise, an organization decides to accept an identified risk associated with a critical business system. Which of the following should be done next?
The BEST indicator of the risk appetite of an organization is the
Which risk analysis methodology uses diagrams to analyze causes and consequences of particular risk events?
Which of the following is MOST helpful in determining the effectiveness of an organization ' s IT risk mitigation efforts?
Which of the following presents the GREATEST privacy risk related to personal data processing for a global organization?
Which of the following should be of GREATEST concern when reviewing the results of an independent control assessment to determine the effectiveness of a vendor ' s control environment?
Which of the following is the BEST way to promote adherence to the risk tolerance level set by management?