Vulnerabilities have been detected on an organization ' s systems. Applications installed on these systems will not operate if the underlying servers are updated. Which of the following is the risk practitioner ' s BEST course of action?
Who is BEST suited to provide objective input when updating residual risk to reflect the results of control effectiveness?
Which of the following MOST effectively limits the impact of a ransomware attack?
Which of the following is the BEST way to determine whether system settings are in alignment with control baselines?
A global organization is planning to collect customer behavior data through social media advertising. Which of the following is the MOST important business risk to be considered?
Which of the following is the PRIMARY responsibility of a control owner?
After a business unit implemented an Internet of Things (IoT) solution, the organization became aware of an emerging risk from the interoperability of IoT devices. Which of the following should be done FIRST in response to this situation?
In which of the following system development life cycle (SDLC) phases should controls be incorporated into system specifications?
Which of the following is the MOST important metric to monitor the performance of the change management process?
For a large software development project, risk assessments are MOST effective when performed:
Which of the following is MOST important for a risk practitioner to verify when evaluating the effectiveness of an organization ' s existing controls?
The PRIMARY objective for requiring an independent review of an organization ' s IT risk management process should be to:
The cost of maintaining a control has grown to exceed the potential loss. Which of the following BEST describes this situation?
When determining risk ownership, the MAIN consideration should be:
Which of the following is the MOST important consideration when identifying stakeholders to review risk scenarios developed by a risk analyst? The reviewers are:
A risk practitioner is performing a risk assessment of recent external advancements in quantum computing. Which of the following would pose the GREATEST concern for the risk practitioner?
A risk practitioner has been asked to assess the risk associated with a new critical application used by a financial process team that the risk practitioner was a member of two years ago. Which of the following is the GREATEST concern with this request?
Prior to selecting key performance indicators (KPIs), itis MOST important to ensure:
A risk practitioner observed Vial a high number of pokey exceptions were approved by senior management. Which of the following is the risk practitioner’s BEST course of action to determine root cause?
As part of its risk strategy, an organization decided to transition its financial system from a cloud-based provider to an internally managed system. Which of the following should the risk practitioner do FIRST?
Which of the following BEST ensures that the data feeds used by an organization are complete and accurate?
Which of the following is the MOST important consideration when selecting digital signature software?
A risk practitioner has identified that the agreed recovery time objective (RTO) with a Software as a Service (SaaS) provider is longer than the business expectation. Which of the following is the risk practitioner ' s BEST course of action?
Which of the following is the BEST way to mitigate the risk associated with fraudulent use of an enterprise ' s brand on Internet sites?
Which of the following is the MOST important reason for integrating IT risk management practices into enterprise risk management (ERM)?
Which of the following should be the FIRST course of action if the risk associated with a new technology is found to be increasing?
Which of the following is the PRIMARY purpose of a risk register?
Which of the following BEST informs decision-makers about the value of a notice and consent control for the collection of personal information?
A risk practitioner has learned that an effort to implement a risk mitigation action plan has stalled due to lack of funding. The risk practitioner should report that the associated risk has been:
Where should a risk practitioner document the current state and desired future state of organizational risk?
To mitigate the risk of using a spreadsheet to analyze financial data, IT has engaged a third-party vendor to deploy a standard application to automate the process. Which of the following parties should own the risk associated with calculation errors?
Which of the following introduces the GREATEST amount of risk during the software development life cycle (SDLC)?
An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
Which of the following is the PRIMARY purpose of analyzing control effectiveness during risk analysis?
A key risk indicator (KRI) for technology operations has been above risk thresholds for the last three reporting periods. What is the BEST way for a risk practitioner to address this concern?
Which of the following situations would BEST justify escalation to senior management?
Which of the following is MOST important to review when an organization needs to transition the majority of its employees to remote work during a crisis?
An organization has recently updated its disaster recovery plan (DRP). Which of the following would be the GREATEST risk if the new plan is not tested?
An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:
Which of the following BEST enables the selection of appropriate risk treatment in the event of a disaster?
A control owner responsible for the access management process has developed a machine learning model to automatically identify excessive access privileges. What is the risk practitioner ' s BEST course of action?
Who should be responsible for determining which stakeholders need to be involved in the development of a risk scenario?
The implementation of a risk treatment plan will exceed the resources originally allocated for the risk response. Which of the following should be the risk owner ' s NEXT action?
An organization ' s risk practitioner learns a new third-party system on the corporate network has introduced vulnerabilities that could compromise corporate IT systems. What should the risk practitioner do FIRST?
An organization requires a third party for processing customer personal data. Which of the following is the BEST approach when sharing data over a public network?
An organization is planning to engage a cloud-based service provider for some of its data-intensive business processes. Which of the following is MOST important to help define the IT risk associated with this outsourcing activity?
Which of the following provides the MOST useful input to the development of realistic risk scenarios?
Which of the following is the GREATEST risk associated with inappropriate classification of data?
Which of the following BEST mitigates the risk of sensitive personal data leakage from a software development environment?
Which of the following is the MOST important foundational element of an effective three lines of defense model for an organization?