It is MOST important to the effectiveness of an IT risk management function that the associated processes are:
Which of the following should a risk practitioner recommend FIRST when an increasing trend of risk events and subsequent losses has been identified?
Which of the following is the BEST evidence that a user account has been properly authorized?
Which of the following is the PRIMARY benefit of implementing key control indicators (KCIs)?
Which of the following is the BEST way to ensure data is properly sanitized while in cloud storage?
Which of the following BEST indicates that an organization ' s risk management processes are mature?
Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?
A financial institution has identified high risk of fraud in several business applications. Which of the following controls will BEST help reduce the risk of fraudulent internal transactions?
Which of the following is the BEST approach for selecting controls to minimize risk?
Which of the following risk activities is BEST facilitated by enterprise architecture (EA)?
The PRIMARY advantage of implementing an IT risk management framework is the:
The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:
A new regulator/ requirement imposes severe fines for data leakage involving customers ' personally identifiable information (Pll). The risk practitioner has recommended avoiding the risk. Which of the following actions would BEST align with this recommendation?
Which of the following would be MOST helpful when estimating the likelihood of negative events?
Which of the following is MOST important to the effectiveness of a senior oversight committee for risk monitoring?
The PRIMARY advantage of involving end users in continuity planning is that they:
Which of the following is MOST important for managing ethical risk?
Which of the following is the MOST important reason to communicate control effectiveness to senior management?
Which of the following should a risk practitioner recommend FIRST when a risk assessment identifies the exposure of a significant number of personal customer records in a database?
An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?
Which of the following key risk indicators (KRIs) provides the BEST insight into the risk associated with IT systems being unable to meet the required availability service level in the future?
Establishing and organizational code of conduct is an example of which type of control?
During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?
Vulnerabilities have been detected on an organization ' s systems. Applications installed on these systems will not operate if the underlying servers are updated. Which of the following is the risk practitioner ' s BEST course of action?
An organization is implementing data warehousing infrastructure. Senior management is concerned about safeguarding client data security in this new environment. Which of the following should the risk practitioner recommend be done NEXT?
Which of the following practices BEST mitigates risk related to enterprise-wide ethical decision making in a multi-national organization?
Which of the following is the MOST effective control to maintain the integrity of system configuration files?
An organization operates in an environment where reduced time-to-market for new software products is a top business priority. Which of the following should be the risk practitioner ' s GREATEST concern?
Which of the following is the PRIMARY reason to compare the business impact analysis (BIA) against the organization ' s business continuity plan (BCP)?
Which of the following is MOST important for mitigating ethical risk when establishing accountability for control ownership?
Which of the following should be done FIRST upon learning that the organization will be affected by a new regulation in its industry?
In the three lines of defense model, a PRIMARY objective of the second line is to:
Which of the following is the MOST essential characteristic of a good IT risk scenario?
Which of the following metrics is BEST used to communicate to senior management that the control environment manages risk within appetite and tolerance?
Which of the following is the BEST way to address IT regulatory compliance risk?
An organization is subject to a new regulation that requires nearly real-time recovery of its services following a disruption. Which of the following is the BEST way to manage the risk in this situation?
Which of the following is the BEST approach for a risk practitioner to use for identifying the level of technical debt in an organization?
After conducting a risk assessment for regulatory compliance, an organization has identified only one possible mitigating control. The cost of the control has been determined to be higher than the penalty of noncompliance. Which of the following would be the risk practitioner ' s BEST recommendation?
Owners of technical controls should be PRIMARILY accountable for ensuring the controls are:
An updated report from a trusted research organization shows that attacks have increased in the organization ' s industry segment. What should be done FIRST to integrate this data into risk assessments?
An organization is reviewing a contract for a Software as a Service (SaaS) sales application with a 99.9% uptime service level agreement (SLA). Which of the following BEST describes ownership of availability risk?
Which of the following should be the PRIMARY basis for prioritizing risk responses?
The PRIMARY purpose of vulnerability assessments is to:
An organization has recently been experiencing frequent data corruption incidents. Implementing a file corruption detection tool as a risk response strategy will help to:
The PRIMARY objective of a risk identification process is to:
Which of the following would BEST help an enterprise prioritize risk scenarios?
Which of the following BEST describes the role of the IT risk profile in strategic IT-related decisions?
Which of the following is the BEST approach for determining whether a risk action plan is effective?
An organization is implementing Zero Trust architecture to improve its security posture. Which of the following is the MOST important input to develop the architecture?
The patch management process is MOST effectively monitored through which of the following key control indicators (KCIs)?