Which of the following BEST protects organizational data within a production cloud environment?
The GREATEST benefit of introducing continuous monitoring to an IT control environment is that it:
After entering a large number of low-risk scenarios into the risk register, it is MOST important for the risk practitioner to:
When formulating a social media policy lo address information leakage, which of the following is the MOST important concern to address?
An organization plans to implement a new Software as a Service (SaaS) speech-to-text solution Which of the following is MOST important to mitigate risk associated with data privacy?
Which of the following is MOST important to the effectiveness of key performance indicators (KPIs)?
Which of the following is the PRIMARY reason for an organization to include an acceptable use banner when users log in?
Which of the following is a risk practitioner ' s BEST recommendation to help reduce IT risk associated with scheduling overruns when starting a new application development project?
After the announcement of a new IT regulatory requirement, it is MOST important for a risk practitioner to;
Following the identification of a risk associated with a major organizational change, which of the following is MOST important to update in the IT risk register?
Which of the following is the BEST approach for determining whether a risk action plan is effective?
A data privacy regulation has been revised to incorporate more stringent requirements for personal data protection. Which of the following provides the MOST important input to help ensure compliance with the revised regulation?
Which of the following MUST be assessed before considering risk treatment options for a scenario with significant impact?
The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of:
Which of the following is the BEST reason to use qualitative measures to express residual risk levels related to emerging threats?
Which of the following describes the relationship between Key risk indicators (KRIs) and key control indicators (KCIS)?
A risk practitioner has been notified of a social engineering attack using artificial intelligence (Al) technology to impersonate senior management personnel. Which of the following would BEST mitigate the impact of such attacks?
Which of the following is the BEST criterion to determine whether higher residual risk ratings in the risk register should be accepted?
Which of the following would be a risk practitioner ' s MOST important action upon learning that an IT control has failed?
During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?
A bank is experiencing an increasing incidence of customer identity theft. Which of the following is the BEST way to mitigate this risk?
An organization ' s IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?
The PRIMARY purpose of a maturity model is to compare the:
An organization discovers significant vulnerabilities in a recently purchased commercial off-the-shelf software product which will not be corrected until the next release. Which of the following is the risk manager ' s BEST course of action?
Which of the following IT controls is MOST useful in mitigating the risk associated with inaccurate data?
The MAIN goal of the risk analysis process is to determine the:
What is the MOST important consideration when aligning IT risk management with the enterprise risk management (ERM) framework?
Which of the following is MOST important when conducting a post-implementation review as part of the system development life cycle (SDLC)?
Which of the following aspects of risk can be transferred to a third party?
Which of the following is the MOST important key risk indicator (KRI) to protect personal information on corporate mobile endpoints?
The patch management process is MOST effectively monitored through which of the following key control indicators (KCIs)?
Implementing which of the following will BEST help ensure that systems comply with an established baseline before deployment?
Which of the following emerging technologies is frequently used for botnet distributed denial of service (DDoS) attacks?
Which of the following is MOST important to consider when determining the value of an asset during the risk identification process?
Which of the following should be the PRIMARY concern when changes to firewall rules do not follow change management requirements?
A risk manager has determined there is excessive risk with a particular technology. Who is the BEST person to own the unmitigated risk of the technology?
An organization is outsourcing a key database to be hosted by an external service provider. Who is BEST suited to assess the impact of potential data loss?
What are the MOST important criteria to consider when developing a data classification scheme to facilitate risk assessment and the prioritization of risk mitigation activities?
A migration from an in-house developed system to an external cloud-based solution is affecting a previously rated key risk scenario related to payroll processing. Which part of the risk register should be updated FIRST?
During the initial risk identification process for a business application, it is MOST important to include which of the following stakeholders?
Optimized risk management is achieved when risk is reduced:
Which of the following is the GREATEST benefit of incorporating IT risk scenarios into the corporate risk register?
It was discovered that a service provider ' s administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the following would BEST protect against a future recurrence?
Which of the following is the BEST evidence of a well-defined risk event?
Which of the following is the BEST way to mitigate the risk to IT infrastructure availability?
Which of the following should be a risk practitioner’s MOST important consideration when developing IT risk scenarios?
To communicate the risk associated with IT in business terms, which of the following MUST be defined?
Which of the following would present the GREATEST challenge for a risk practitioner during a merger of two organizations?
Following a significant change to a business process, a risk practitioner believes the associated risk has been reduced. The risk practitioner should advise the risk owner to FIRST
An IT risk practitioner is evaluating an organization ' s change management controls over the last six months. The GREATEST concern would be an increase in: