Which of the following is MOST important to consider when assessing the likelihood that a recently discovered software vulnerability will be exploited?
When developing a risk awareness training program, which of the following training topics would BEST facilitate a thorough understanding of risk scenarios?
Which of the following is MOST helpful when determining whether a system security control is effective?
A risk practitioner recently discovered that personal information from the production environment is required for testing purposes in non-production environments. Which of the following is the BEST recommendation to address this situation?
Which of the following is the MAIN purpose of monitoring risk?
Which of the following would BEST prevent an unscheduled application of a patch?
An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:
Which of the following would require updates to an organization's IT risk register?
Which of the following is the BEST way to support communication of emerging risk?
Which of the following would be MOST useful to senior management when determining an appropriate risk response?
Senior management is deciding whether to share confidential data with the organization's business partners. The BEST course of action for a risk practitioner would be to submit a report to senior management containing the:
A risk practitioner is concerned with potential data loss in the event of a breach at a hosted third-party provider. Which of the following is the BEST way to mitigate this risk?
While evaluating control costs, management discovers that the annual cost exceeds the annual loss expectancy (ALE) of the risk. This indicates the:
Which of the following would present the GREATEST challenge when assigning accountability for control ownership?
Which of the following is MOST important to understand when determining an appropriate risk assessment approach?
The BEST criteria when selecting a risk response is the:
Analyzing trends in key control indicators (KCIs) BEST enables a risk practitioner to proactively identify impacts on an organization's:
Which of the following BEST informs decision-makers about the value of a notice and consent control for the collection of personal information?
An incentive program is MOST likely implemented to manage the risk associated with loss of which organizational asset?
An organization has implemented a system capable of comprehensive employee monitoring. Which of the following should direct how the system is used?
When determining the accuracy of a key risk indicator (KRI), it is MOST important that the indicator:
Which of the following is the MOST important consideration for a risk practitioner when making a system implementation go-live recommendation?
What is the BEST information to present to business control owners when justifying costs related to controls?
The PRIMARY benefit of conducting a risk workshop using a top-down approach instead of a bottom-up approach is the ability to:
Which of the following is the MOST significant risk related to an organization's use of AI technology?
An organization recently implemented new technologies that enable the use of robotic process automation. Which of the following is MOST important to reassess?
Which of the following would be of GREATEST concern to a risk practitioner reviewing current key risk indicators (KRIs)?
Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?
Which of the following is a PRIMARY objective of privacy impact assessments (PIAs)?
Which of the following BEST reduces the likelihood of fraudulent activity that occurs through use of a digital wallet?
Which of the following BEST assists in justifying an investment in automated controls?
Which of the following is of GREATEST concern when uncontrolled changes are made to the control environment?
Which of the following is MOST helpful to understand the consequences of an IT risk event?
Which of the following is the MOST important consideration when selecting digital signature software?
Which of the following activities would BEST contribute to promoting an organization-wide risk-aware culture?
Which of the following will BEST help to ensure the continued effectiveness of the IT risk management function within an organization experiencing high employee turnover?
The operational risk associated with attacks on a web application should be owned by the individual in charge of:
After identifying new risk events during a project, the project manager s NEXT step should be to:
A risk practitioner observed Vial a high number of pokey exceptions were approved by senior management. Which of the following is the risk practitioner’s BEST course of action to determine root cause?
Which of the following cloud service models is MOST appropriate for client organizations that want to maximize their control over management of the data life cycle?
An organization uses a biometric access control system for authentication and access to its server room. Which control type has been implemented?
An organization has agreed to a 99% availability for its online services and will not accept availability that falls below 98.5%. This is an example of:
An organization is planning to outsource its payroll function to an external service provider Which of the following should be the MOST important consideration when selecting the provider?
Which of the following BEST supports ethical IT risk management practices?
Which of the following poses the GREATEST risk to an organization's operations during a major it transformation?
Which of the following provides The BEST information when determining whether to accept residual risk of a critical system to be implemented?
Which of the following provides the MOST useful information to senior management about risk mitigation status?
The PRIMARY advantage of involving end users in continuity planning is that they:
Which of the following would be of GREATEST concern regarding an organization's asset management?
Which of the following offers the SIMPLEST overview of changes in an organization's risk profile?
PDF + Testing Engine
|
---|
$66 |
Testing Engine
|
---|
$50 |
PDF (Q&A)
|
---|
$42 |
Isaca Free Exams |
---|
![]() |