Optimized risk management is achieved when risk is reduced:
Which of the following is the BEST key control indicator (KCI) for a vulnerability management program?
Which of the following is the MOST important information to cover in a business continuity awareness training program for all employees of the organization?
A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner ' s NEXT step?
Print jobs containing confidential information are sent to a shared network printer located in a secure room. Which of the following is the BEST control to prevent the inappropriate disclosure of confidential information?
A Software as a Service (SaaS) company wants to use aggregated data from its clients to improve its services via a machine learning (ML) model. However, its contracts do not clearly allow this use of aggregated data. What should the organization do NEXT?
Which of the following is the GREATEST risk associated with the use of data analytics?
Which of the following BEST indicates that an organizations risk management program is effective?
Which of the following is the PRIMARY purpose of analyzing control effectiveness during risk analysis?
A risk practitioner implemented a process to notify management of emergency changes that may not be approved. Which of the following is the BEST way to provide this information to management?
Which of the following is MOST helpful when determining whether a system security control is effective?
Which of the following is the GREATEST risk associated with the misclassification of data?
A recent regulatory requirement has the potential to affect an organization ' s use of a third party to supply outsourced business services. Which of the following is the BEST course of action?
Which of the following BEST represents a critical threshold value for a key control indicator (KCI)?
A key performance indicator (KPI) has been established to monitor the number of software changes that fail and must be re-implemented. An increase in the KPI indicates an ineffective:
Which of the following is the PRIMARY role of a data custodian in the risk management process?
Which of the following approaches will BEST help to ensure the effectiveness of risk awareness training?
Which of the following is MOST likely to result in a major change to the overall risk profile of the organization?
Which of the following BEST prevents control gaps in the Zero Trust model when implementing in the environment?
Which of the following will be MOST effective in uniquely identifying the originator of electronic transactions?
A small organization finds it difficult to implement separation of duties necessary to mitigate the likelihood of system misuse. Which of the following would be the BEST compensating control?
An IT department originally planned to outsource the hosting of its data center at an overseas location to reduce operational expenses. After a risk assessment, the department has decided to keep the data center in-house. How should the risk treatment response be reflected in the risk register?
Which of the following should be the PRIMARY consideration for a startup organization that has decided to adopt externally-sourced security policies?
When prioritizing risk response, management should FIRST:
Whether the results of risk analyses should be presented in quantitative or qualitative terms should be based PRIMARILY on the:
Which of the following resources is MOST helpful when creating a manageable set of IT risk scenarios?
Which of the following is MOST commonly compared against the risk appetite?
Which of the following BEST contributes to the implementation of an effective risk response action plan?
Which of the following would BEST facilitate the implementation of data classification requirements?
Which of the following is MOST important to consider when assessing the likelihood that a recently discovered software vulnerability will be exploited?
An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner ' s FIRST course of action?
The BEST indication that risk management is effective is when risk has been reduced to meet:
An organization has engaged a third party to provide an Internet gateway encryption service that protects sensitive data uploaded to a cloud service. This is an example of risk:
A recent vulnerability assessment of a web-facing application revealed several weaknesses. Which of the following should be done NEXT to determine the risk exposure?
Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?
Malware has recently affected an organization. The MOST effective way to resolve this situation and define a comprehensive risk treatment plan would be to perform:
The BEST way to demonstrate alignment of the risk profile with business objectives is through:
A multinational organization is considering implementing standard background checks to ' all new employees A KEY concern regarding this approach
Which of the following controls will BEST detect unauthorized modification of data by a database administrator?
A business is conducting a proof of concept on a vendor ' s Al technology. Which of the following is the MOST important consideration for managing risk?
Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?
Which of the following BEST supports the integration of IT risk management into an organization ' s strategic planning?
An organization is adopting block chain for a new financial system. Which of the following should be the GREATEST concern for a risk practitioner evaluating the system ' s production readiness?
Which organizational role should be accountable for ensuring information assets are appropriately classified?
Which of the following is the MOST important objective of regularly presenting the project risk register to the project steering committee?
When implementing an IT risk management program, which of the following is the BEST time to evaluate current control effectiveness?
During a data loss incident, which role in the RACI chart would be aligned to the risk practitioner?
A risk practitioner is performing a risk assessment of recent external advancements in quantum computing. Which of the following would pose the GREATEST concern for the risk practitioner?
Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of an antivirus program?