Upon learning that the number of failed back-up attempts continually exceeds the current risk threshold, the risk practitioner should:
How does an organization benefit by purchasing cyber theft insurance?
Which of the following is the MOST important topic to cover in a risk awareness training program for all staff?
Which of the following risk management practices BEST facilitates the incorporation of IT risk scenarios into the enterprise-wide risk register?
Which of the following is the GREATEST benefit for an organization with a strong risk awareness culture?
An organization has updated its acceptable use policy to mitigate the risk of employees disclosing confidential information. Which of the following is the BEST way to reinforce the effectiveness of this policy?
A key performance indicator (KPI) shows that a process is operating inefficiently, even though no control issues were noted during the most recent risk assessment. Which of the following should be done FIRST?
Which of the following approaches MOST effectively enables accountability for data protection?
Which of the following should be the PRIMARY focus of a risk owner once a decision is made to mitigate a risk?
An organization has outsourced its IT security operations to a third party. Who is ULTIMATELY accountable for the risk associated with the outsourced operations?
Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?
After the implementation of a remediation plan, an assessment of associated control design and operating effectiveness can determine the level of:
An organization has recently updated its disaster recovery plan (DRP). Which of the following would be the GREATEST risk if the new plan is not tested?
Which of the following is the PRIMARY factor in determining a recovery time objective (RTO)?
Which of the following trends would cause the GREATEST concern regarding the effectiveness of an organization ' s user access control processes? An increase in the:
A risk practitioner is conducting a risk assessment after discovering the use of unauthorized cloud software on personal devices to accomplish work-related tasks. Which of the following is the risk practitioner ' s BEST course of action?
What is the GREATEST concern with maintaining decentralized risk registers instead of a consolidated risk register?
A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from being exploded?
The risk associated with an asset after controls are applied can be expressed as:
An organization ' s control environment is MOST effective when:
Which of the following is the PRIMARY advantage of having a single integrated business continuity plan (BCP) rather than each business unit developing its own BCP?
Which of the following would MOST likely result in updates to an IT risk appetite statement?
Which of the following will BEST mitigate the risk associated with IT and business misalignment?
While evaluating control costs, management discovers that the annual cost exceeds the annual loss expectancy (ALE) of the risk. This indicates the:
What is the BEST information to present to business control owners when justifying costs related to controls?
Which of the following provides the BEST measurement of an organization ' s risk management maturity level?
An organization striving to be on the leading edge in regard to risk monitoring would MOST likely implement:
Which of the following should be determined FIRST when a new security vulnerability is made public?
Which of the following would be MOST effective in monitoring changes in an organization ' s IT risk environment?
Which of the following BEST helps to identify significant events that could impact an organization?
A risk assessment has identified that an organization may not be in compliance with industry regulations. The BEST course of action would be to:
Which of the following is the MOST common concern associated with outsourcing to a service provider?
Improvements in the design and implementation of a control will MOST likely result in an update to:
Which of the following is the PRIMARY benefit of using an entry in the risk register to track the aggregate risk associated with server failure?
Which of the following problems is BEST solved by a cloud access security broker (CASB)?
Which of the following is the GREATEST benefit to an organization when updates to the risk register are made promptly after the completion of a risk assessment?
Which process is MOST effective to determine relevance of threats for risk scenarios?
An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?
The MAIN reason for prioritizing IT risk responses is to enable an organization to:
What are the MOST important criteria to consider when developing a data classification scheme to facilitate risk assessment and the prioritization of risk mitigation activities?
Which of the following is the GREATEST concern when an organization uses a managed security service provider as a firewall administrator?
A cote data center went offline abruptly for several hours affecting many transactions across multiple locations. Which of the to " owing would provide the MOST useful information to determine mitigating controls?
Which of the following is the BEST way to assess the effectiveness of an access management process?
The MOST effective approach to prioritize risk scenarios is by:
An organization has received notification that it is a potential victim of a cybercrime that may have compromised sensitive customer data. What should be The FIRST course of action?
A review of an organization s controls has determined its data loss prevention {DLP) system is currently failing to detect outgoing emails containing credit card data. Which of the following would be MOST impacted?
Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application?
Which of the following would BEST help to ensure that identified risk is efficiently managed?
Which of the following would be MOST helpful when communicating roles associated with the IT risk management process?
Which of the following is the BEST way to ensure adequate resources will be allocated to manage identified risk?