Which of the following is the MOST important benefit of reporting risk assessment results to senior management?
A risk practitioner discovers that an IT operations team manager bypassed web filtering controls by using a mobile device, in violation of the network security policy. Which of the following should the risk practitioner do FIRST?
An organization ' s financial analysis department uses an in-house forecasting application for business projections. Who is responsible for defining access roles to protect the sensitive data within this application?
Which of the following is the BEST method to track asset inventory?
Which of the following would BEST provide early warning of a high-risk condition?
Which of the following BEST reduces the risk associated with the theft of a laptop containing sensitive information?
Which of the following would BEST help identify the owner for each risk scenario in a risk register?
Who is MOST likely to be responsible for the coordination between the IT risk strategy and the business risk strategy?
A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
Which of the following is the BEST key performance indicator (KPI) to measure the maturity of an organization ' s security incident handling process?
The risk associated with an asset after controls are applied can be expressed as:
Who is the MOST appropriate owner for newly identified IT risk?
An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?
Which of the following is the GREATEST benefit of using IT risk scenarios?
Several vulnerabilities have been identified in an organization’s core financial systems. Which of the following would be the risk practitioner’s BEST course of action?
Which of the following should be management ' s PRIMARY consideration when approving risk response action plans?
Which of the following is the MOST important responsibility of a risk owner?
Which of the following BEST helps to mitigate risk associated with excessive access by authorized users?
A business is conducting a proof of concept on a vendor ' s Al technology. Which of the following is the MOST important consideration for managing risk?
An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:
Which of the following is MOST essential for an effective change control environment?
WhichT5f the following is the MOST effective way to promote organization-wide awareness of data security in response to an increase in regulatory penalties for data leakage?
It is MOST important to the effectiveness of an IT risk management function that the associated processes are:
Which of the following could BEST detect an in-house developer inserting malicious functions into a web-based application?
Which of the following is the PRIMARY function of the first line in the three lines model?
Which of the following is the GREATEST concern when an organization uses a managed security service provider as a firewall administrator?
Which of the following would cause the GREATEST concern for a risk practitioner reviewing the IT risk scenarios recorded in an organization’s IT risk register?
An organization’s board of directors is concerned about recent data breaches in the news and wants to assess its exposure to similar scenarios. Which of the following is the BEST course of action?
Which of the following presents the GREATEST concern associated with the
use of artificial intelligence (Al) systems?
Before assigning sensitivity levels to information it is MOST important to:
An internally developed payroll application leverages Platform as a Service (PaaS) infrastructure from the cloud. Who owns the related data confidentiality risk?
Which of the following would provide the MOST useful information for communicating an organization’s risk level to senior management?
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:
Which of the following would provide executive management with the BEST information to make risk decisions as a result of a risk assessment?
Which of the following is the BEST way to confirm whether appropriate automated controls are in place within a recently implemented system?
As part of an overall IT risk management plan, an IT risk register BEST helps management:
Effective risk communication BEST benefits an organization by:
Which of the following is the MOST important reason to communicate control effectiveness to senior management?
Which of the following is the BEST method of creating risk awareness in an organization?
When assigning control ownership, it is MOST important to verify that the owner has accountability for:
Which of the following is the MOST important reason to integrate IT risk management practices into the enterprise-wide operational risk management framework?
An upward trend in which of the following metrics should be of MOST concern?
Which of the following presents the GREATEST security risk associated with Internet of Things (IoT) technology?
Which of the following is MOST important to consider when determining risk appetite?
Which of the following should be considered FIRST when managing a risk event related to theft and disclosure of customer information?
From a governance perspective, which of the following is MOST important to ensure when risk management policies are being updated to facilitate the pursuit of new opportunities?
A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization ' s data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?
A risk practitioner is conducting a risk assessment after discovering the use of unauthorized cloud software on personal devices to accomplish work-related tasks. Which of the following is the risk practitioner ' s BEST course of action?
An organization mandates the escalation of a service ticket when a key application is offline for 5 minutes or more due to potential risk exposure. The risk practitioner has been asked by management to prepare a report of application offline times using both 3- and 5-minute thresholds. What does the 3-minute threshold represent?
A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner ' s GREATEST concern?