Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Isaca > Isaca Certification > CRISC

CRISC Certified in Risk and Information Systems Control Question and Answers

Question # 4

Vulnerabilities have been detected on an organization ' s systems. Applications installed on these systems will not operate if the underlying servers are updated. Which of the following is the risk practitioner ' s BEST course of action?

A.

Recommend the business change the application.

B.

Recommend a risk treatment plan.

C.

Include the risk in the next quarterly update to management.

D.

Implement compensating controls.

Full Access
Question # 5

Which of the following would MOST effectively enable a business operations manager to identify events exceeding risk thresholds?

A.

Continuous monitoring

B.

A control self-assessment

C.

Transaction logging

D.

Benchmarking against peers

Full Access
Question # 6

A risk assessment has identified that an organization may not be in compliance with industry regulations. The BEST course of action would be to:

A.

conduct a gap analysis against compliance criteria.

B.

identify necessary controls to ensure compliance.

C.

modify internal assurance activities to include control validation.

D.

collaborate with management to meet compliance requirements.

Full Access
Question # 7

Which of the following is MOST helpful in reducing the likelihood of inaccurate risk assessment results?

A.

Involving relevant stakeholders in the risk assessment process

B.

Updating organizational risk tolerance levels

C.

Reviewing the applicable risk assessment methodologies

D.

Having internal audit validate control effectiveness

Full Access
Question # 8

Which of the following is a KEY consideration for a risk practitioner to communicate to senior management evaluating the introduction of artificial intelligence (Al) solutions into the organization?

A.

Al requires entirely new risk management processes.

B.

Al potentially introduces new types of risk.

C.

Al will result in changes to business processes.

D.

Third-party Al solutions increase regulatory obligations.

Full Access
Question # 9

During a post-implementation review for a new system, users voiced concerns about missing functionality. Which of the following is the BEST way for the organization to avoid this situation in the future?

A.

Test system reliability and performance.

B.

Adopt an Agile development approach.

C.

Conduct user acceptance testing (UAT).

D.

Adopt a phased changeover approach.

Full Access
Question # 10

Mapping open risk issues to an enterprise risk heat map BEST facilitates:

A.

risk response.

B.

control monitoring.

C.

risk identification.

D.

risk ownership.

Full Access
Question # 11

Which of the following should be the PRIMARY area of focus when reporting changes to an organization ' s risk profile to executive management?

A.

Risk management resources

B.

Risk tolerance

C.

Cyberattack threats

D.

Risk trends

Full Access
Question # 12

Which of the following is the MOST important information to cover in a business continuity awareness training program for all employees of the organization?

A.

Recovery time objectives (RTOs)

B.

Communication plan

C.

Critical asset inventory

D.

Separation of duties

Full Access
Question # 13

What can be determined from the risk scenario chart?

A.

Relative positions on the risk map

B.

Risk treatment options

C.

Capability of enterprise to implement

D.

The multiple risk factors addressed by a chosen response

Full Access
Question # 14

An organization recently invested in an identity and access management (IAM) solution to manage user activities across corporate mobile devices. Which of the following is MOST important to update in the risk register?

A.

Inherent risk

B.

Risk appetite

C.

Risk tolerance

D.

Residual risk

Full Access
Question # 15

A threat intelligence team has identified an indicator of compromise related to an advanced persistent threat (APT) actor. Which of the following is the risk practitioner ' s BEST course of action?

A.

Review the most recent vulnerability scanning report.

B.

Determine the business criticality of the asset.

C.

Determine the adequacy of existing security controls.

D.

Review prior security incidents related to the asset.

Full Access
Question # 16

Which of the following is the MOST important criteria for selecting key risk indicators (KRIs)?

A.

Historical data availability

B.

Implementation and reporting effort

C.

Ability to display trends

D.

Sensitivity and reliability

Full Access
Question # 17

Which of the following BEST facilitates the identification of appropriate key performance indicators (KPIs) for a risk management program?

A.

Reviewing control objectives

B.

Aligning with industry best practices

C.

Consulting risk owners

D.

Evaluating KPIs in accordance with risk appetite

Full Access
Question # 18

The MOST appropriate key performance indicator (KPI) to communicate the effectiveness of an enterprise IT risk management program is:

A.

The percentage of risk scenarios that are within organizational tolerance

B.

The percentage of IT staff trained in risk management

C.

The number of critical business services covered by a risk assessment

D.

The amount of IT risk realized that impacted the business

Full Access
Question # 19

Which of the following would BEST help to ensure that suspicious network activity is identified?

A.

Analyzing intrusion detection system (IDS) logs

B.

Analyzing server logs

C.

Using a third-party monitoring provider

D.

Coordinating events with appropriate agencies

Full Access
Question # 20

Which of the following is the MOST important consideration when selecting either a qualitative or quantitative risk analysis?

A.

Expertise in both methodologies

B.

Maturity of the risk management program

C.

Time available for risk analysis

D.

Resources available for data analysis

Full Access
Question # 21

Who is PRIMARILY accountable for risk treatment decisions?

A.

Risk owner

B.

Business manager

C.

Data owner

D.

Risk manager

Full Access
Question # 22

Which of the following should be the PRIMARY consideration when assessing the automation of control monitoring?

A.

impact due to failure of control

B.

Frequency of failure of control

C.

Contingency plan for residual risk

D.

Cost-benefit analysis of automation

Full Access
Question # 23

An organization has asked an IT risk practitioner to conduct an operational risk assessment on an initiative to outsource the organization ' s customer service operations overseas. Which of the following would MOST significantly impact management ' s decision?

A.

Time zone difference of the outsourcing location

B.

Ongoing financial viability of the outsourcing company

C.

Cross-border information transfer restrictions in the outsourcing country

D.

Historical network latency between the organization and outsourcing location

Full Access
Question # 24

Which of the following would be MOST helpful to a risk practitioner when preparing a summary of current IT risk for senior management review?

A.

Changes in risk mitigation plans

B.

Resolution status of audit findings

C.

Areas of elevated risk

D.

Industry risk management benchmarks

Full Access
Question # 25

External penetration tests MUST include:

A.

use of consultants to ensure completeness.

B.

communications to users of the target systems.

C.

changes to target data to prove the attack was successful.

D.

advance approval from system owners.

Full Access
Question # 26

The number of tickets to rework application code has significantly exceeded the established threshold. Which of the following would be the risk practitioner s BEST recommendation?

A.

Perform a root cause analysis

B.

Perform a code review

C.

Implement version control software.

D.

Implement training on coding best practices

Full Access
Question # 27

Which of the following is the MOST important consideration for prioritizing risk treatment plans when faced with budget limitations?

A.

Inherent risk and likelihood

B.

Management action plans associated with audit findings

C.

Residual risk relative to appetite and tolerance

D.

Key risk indicator (KRI) trends

Full Access
Question # 28

Which of the following is the PRIMARY benefit of integrating risk and security requirements in an organization ' s enterprise architecture (EA)?

A.

Adherence to legal and compliance requirements

B.

Reduction in the number of test cases in the acceptance phase

C.

Establishment of digital forensic architectures

D.

Consistent management of information assets

Full Access
Question # 29

Which of the following is the BEST recommendation to address recent IT risk trends that indicate social engineering attempts are increasing in the organization?

A.

Conduct a simulated phishing attack.

B.

Update spam filters

C.

Revise the acceptable use policy

D.

Strengthen disciplinary procedures

Full Access
Question # 30

Which of the following is the PRIMARY role of the board of directors in corporate risk governance?

A.

Approving operational strategies and objectives

B.

Monitoring the results of actions taken to mitigate risk

C.

Ensuring the effectiveness of the risk management program

D.

Ensuring risk scenarios are identified and recorded in the risk register

Full Access
Question # 31

Which of the following should be the PRIMARY consideration when identifying and assigning ownership of IT-related risk?

A.

Accountability for control operation

B.

Ability to design controls to mitigate the risk

C.

Accountability for losses due to impact

D.

Span of control within the organization

Full Access
Question # 32

Which of the following potential scenarios associated with the implementation of a new database technology presents the GREATEST risk to an organization?

A.

The organization may not have a sufficient number of skilled resources.

B.

Application and data migration cost for backups may exceed budget.

C.

Data may not be recoverable due to system failures.

D.

The database system may not be scalable in the future.

Full Access
Question # 33

Which of the following would MOST effectively reduce the potential for inappropriate exposure of vulnerabilities documented in an organization ' s risk register?

A.

Limit access to senior management only.

B.

Encrypt the risk register.

C.

Implement role-based access.

D.

Require users to sign a confidentiality agreement.

Full Access
Question # 34

An organization has implemented immutable backups to prevent successful ransomware attacks. Which of the following is the MOST effective control for the risk practitioner to review?

A.

Data recovery testing of the backups

B.

Physical security of the backups

C.

Configuration of the backup solution

D.

Retention policy for the backups

Full Access
Question # 35

Which of the following is MOST important to sustainable development of secure IT services?

A.

Security training for systems development staff

B.

\Well-documented business cases

C.

Security architecture principles

D.

Secure coding practices

Full Access
Question # 36

Improvements in the design and implementation of a control will MOST likely result in an update to:

A.

inherent risk.

B.

residual risk.

C.

risk appetite

D.

risk tolerance

Full Access
Question # 37

An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios applicable to IT. Which of the following is the BEST way to ensure alignment between these two registers?

A.

Map the granular risk scenarios to the high-level risk register items.

B.

List application and server vulnerabilities in the IT risk register.

C.

Identify overlapping risk scenarios between the two registers.

D.

Maintain both high-level and granular risk scenarios in a single register.

Full Access
Question # 38

Which of the following should be the PRIMARY focus of an independent review of a risk management process?

A.

Accuracy of risk tolerance levels

B.

Consistency of risk process results

C.

Participation of stakeholders

D.

Maturity of the process

Full Access
Question # 39

Which of the following is the PRIMARY reason for a risk practitioner to examine a post-implementation review report for a control automation tool?

A.

To verify that budget for the project is managed effectively

B.

To confirm compliance with project management methodology

C.

To ensure the risk is managed to an acceptable level

D.

To ensure audit findings are addressed in a timely manner

Full Access
Question # 40

Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?

A.

Standards-based policies

B.

Audit readiness

C.

Efficient operations

D.

Regulatory compliance

Full Access
Question # 41

The PRIMARY benefit of conducting continuous monitoring of access controls is the ability to identify:

A.

inconsistencies between security policies and procedures

B.

possible noncompliant activities that lead to data disclosure

C.

leading or lagging key risk indicators (KRIs)

D.

unknown threats to undermine existing access controls

Full Access
Question # 42

Which of the following risk scenarios would be the GREATEST concern as a result of a single sign-on implementation?

A.

User access may be restricted by additional security.

B.

Unauthorized access may be gained to multiple systems.

C.

Security administration may become more complex.

D.

User privilege changes may not be recorded.

Full Access
Question # 43

Which of the following will BEST help to ensure implementation of corrective action plans?

A.

Contracting to third parties

B.

Establishing employee awareness training

C.

Setting target dates to complete actions

D.

Assigning accountability to risk owners

Full Access
Question # 44

Which of the following practices MOST effectively safeguards the processing of personal data?

A.

Personal data attributed to a specific data subject is tokenized.

B.

Data protection impact assessments are performed on a regular basis.

C.

Personal data certifications are performed to prevent excessive data collection.

D.

Data retention guidelines are documented, established, and enforced.

Full Access
Question # 45

Which of the following trends would cause the GREATEST concern regarding the effectiveness of an organization ' s user access control processes? An increase in the:

A.

ratio of disabled to active user accounts.

B.

percentage of users with multiple user accounts.

C.

average number of access entitlements per user account.

D.

average time between user transfers and access updates.

Full Access
Question # 46

Which of the following activities is a responsibility of the second line of defense?

A.

Challenging risk decision making

B.

Developing controls to manage risk scenarios

C.

Implementing risk response plans

D.

Establishing organizational risk appetite

Full Access
Question # 47

An organization wants to grant remote access to a system containing sensitive data to an overseas third party. Which of the following should be of GREATEST concern to management?

A.

Transborder data transfer restrictions

B.

Differences in regional standards

C.

Lack of monitoring over vendor activities

D.

Lack of after-hours incident management support

Full Access
Question # 48

Which of the following is the BEST key performance indicator (KPI) for a server patch management process?

A.

The percentage of servers with allowed patching exceptions

B.

The number of servers with local credentials to install patches

C.

The percentage of servers patched within required service level agreements

D.

The number of servers running the software patching service

Full Access
Question # 49

Which of the following is a PRIMARY objective of privacy impact assessments (PIAs)?

A.

To identify threats introduced by business processes

B.

To identify risk when personal information is collected

C.

To ensure senior management has approved the use of personal information

D.

To ensure compliance with data privacy laws and regulations

Full Access
Question # 50

Which of the following is MOST important to consider when selecting key risk indicators (KRIs)? The ability to:

A.

Measure changes in the threat landscape.

B.

Refine the organization’s risk appetite.

C.

Monitor the performance of a process.

D.

Assess the risk associated with risk scenarios.

Full Access
Question # 51

Which of the following is the MAIN benefit to an organization using key risk indicators (KRIs)?

A.

KRIs provide an early warning that a risk threshold is about to be reached.

B.

KRIs signal that a change in the control environment has occurred.

C.

KRIs provide a basis to set the risk appetite for an organization.

D.

KRIs assist in the preparation of the organization ' s risk profile.

Full Access
Question # 52

Which stakeholders are PRIMARILY responsible for determining enterprise IT risk appetite?

A.

Audit and compliance management

B.

The chief information officer (CIO) and the chief financial officer (CFO)

C.

Enterprise risk management and business process owners

D.

Executive management and the board of directors

Full Access
Question # 53

Which of the following is MOST important for a risk practitioner to consider when analyzing the risk associated with migrating to a new cloud service provider?

A.

The cloud service provider ' s control environment

B.

The complexity of the cloud services

C.

The date of the cloud service provider ' s last risk assessment

D.

Past incidents related to acquired cloud services

Full Access
Question # 54

During a risk assessment, what should an assessor do after identifying threats to organizational assets?

A.

Request funding for the security program

B.

Determine threats to be reported to upper management

C.

Implement controls to achieve target risk levels

D.

Evaluate the controls currently in place

Full Access
Question # 55

Which of the following would require updates to an organization ' s IT risk register?

A.

Discovery of an ineffectively designed key IT control

B.

Management review of key risk indicators (KRls)

C.

Changes to the team responsible for maintaining the register

D.

Completion of the latest internal audit

Full Access
Question # 56

An organization is developing a risk awareness program for contractors and consultants. Which of the following is MOST important for the organization to keep confidential?

A.

Key risk indicator (KRI) threshold methodology

B.

Names of key cloud providers

C.

Unmitigated vulnerabilities

D.

Corporate security policies

Full Access
Question # 57

Which of the following BEST prevents control gaps in the Zero Trust model when implementing in the environment?

A.

Relying on multiple solutions for Zero Trust

B.

Utilizing rapid development during implementation

C.

Establishing a robust technical architecture

D.

Starting with a large initial scope

Full Access
Question # 58

Which of the following BEST helps to mitigate risk associated with excessive access by authorized users?

A.

Monitoring user activity using security logs

B.

Revoking access for users changing roles

C.

Granting access based on least privilege

D.

Conducting periodic reviews of authorizations granted

Full Access
Question # 59

When updating a risk register with the results of an IT risk assessment, the risk practitioner should log:

A.

high impact scenarios.

B.

high likelihood scenarios.

C.

treated risk scenarios.

D.

known risk scenarios.

Full Access
Question # 60

An organization recently received an independent security audit report of its cloud service provider that indicates significant control weaknesses. What should be done NEXT in response to this report?

A.

Migrate all data to another compliant service provider.

B.

Analyze the impact of the provider ' s control weaknesses to the business.

C.

Conduct a follow-up audit to verify the provider ' s control weaknesses.

D.

Review the contract to determine if penalties should be levied against the provider.

Full Access
Question # 61

Which of the following is the BEST indication that an organization ' s IT asset life cycle is poorly managed?

A.

Increased hardware maintenance costs

B.

Sensitive data found on discarded devices

C.

Lack of asset labeling

D.

Inadequate employee training

Full Access
Question # 62

The MAJOR reason to classify information assets is

A.

maintain a current inventory and catalog of information assets

B.

determine their sensitivity and critical

C.

establish recovery time objectives (RTOs)

D.

categorize data into groups

Full Access
Question # 63

When evaluating a number of potential controls for treating risk, it is MOST important to consider:

A.

risk appetite and control efficiency.

B.

inherent risk and control effectiveness.

C.

residual risk and cost of control.

D.

risk tolerance and control complexity.

Full Access
Question # 64

What should a risk practitioner do FIRST when a shadow IT application is identified in a business owner ' s business impact analysis (BIA)?

A.

Include the application in the business continuity plan (BCP).

B.

Determine the business purpose of the application.

C.

Segregate the application from the network.

D.

Report the finding to management.

Full Access
Question # 65

The FIRST step for a startup company when developing a disaster recovery plan (DRP) should be to identify:

A.

Current vulnerabilities

B.

Recovery time objectives (RTOs)

C.

Critical business processes

D.

A suitable alternate site

Full Access
Question # 66

Which of the following contributes MOST to the effective implementation of risk responses?

A.

Clear understanding of the risk

B.

Comparable industry risk trends

C.

Appropriate resources

D.

Detailed standards and procedures

Full Access
Question # 67

Which of the following is a risk practitioner ' s MOST important action to reduce the likelihood of internal fraud?

A.

Recommend fraud awareness training for staff

B.

Communicate legal consequences for internal fraud.

C.

Update the internal fraud risk likelihood in the risk register.

D.

Verify the effectiveness of separation of duties.

Full Access
Question # 68

The BEST indication that risk management is effective is when risk has been reduced to meet:

A.

risk levels.

B.

risk budgets.

C.

risk appetite.

D.

risk capacity.

Full Access
Question # 69

Which of the following would be a weakness in procedures for controlling the migration of changes to production libraries?

A.

The programming project leader solely reviews test results before approving the transfer to production.

B.

Test and production programs are in distinct libraries.

C.

Only operations personnel are authorized to access production libraries.

D.

A synchronized migration of executable and source code from the test environment to the production environment is allowed.

Full Access
Question # 70

Which of the following is the MOST important component of effective security incident response?

A.

Network time protocol synchronization

B.

Identification of attack sources

C.

Early detection of breaches

D.

A documented communications plan

Full Access
Question # 71

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?

A.

Escalate the non-cooperation to management

B.

Exclude applicable controls from the assessment.

C.

Review the supplier ' s contractual obligations.

D.

Request risk acceptance from the business process owner.

Full Access
Question # 72

Which of the following should be determined FIRST when a new security vulnerability is made public?

A.

Whether the affected technology is used within the organization

B.

Whether the affected technology is Internet-facing

C.

What mitigating controls are currently in place

D.

How pervasive the vulnerability is within the organization

Full Access
Question # 73

When establishing leading indicators for the information security incident response process it is MOST important to consider the percentage of reported incidents:

A.

that results in a full root cause analysis.

B.

used for verification within the SLA.

C.

that are verified as actual incidents.

D.

resolved within the SLA.

Full Access
Question # 74

Which of the following is MOST useful when performing a quantitative risk assessment?

A.

RACI matrix

B.

Financial models

C.

Management support

D.

Industry benchmarking

Full Access
Question # 75

Which of the following would provide the BEST evidence of an effective internal control environment/?

A.

Risk assessment results

B.

Adherence to governing policies

C.

Regular stakeholder briefings

D.

Independent audit results

Full Access
Question # 76

An organization mandates the escalation of a service ticket when a key application is offline for 5 minutes or more due to potential risk exposure. The risk practitioner has been asked by management to prepare a report of application offline times using both 3- and 5-minute thresholds. What does the 3-minute threshold represent?

A.

Recovery Time Objective (RTO)

B.

Key Risk Indicator (KRI)

C.

Recovery Point Objective (RPO)

D.

Key Performance Indicator (KPI)

Full Access
Question # 77

Which of the following is the GREATEST risk associated with an environment that lacks documentation of the architecture?

A.

Unknown vulnerabilities

B.

Legacy technology systems

C.

Network isolation

D.

Overlapping threats

Full Access
Question # 78

Which of the following is the MAIN reason for documenting the performance of controls?

A.

Obtaining management sign-off

B.

Demonstrating effective risk mitigation

C.

Justifying return on investment

D.

Providing accurate risk reporting

Full Access
Question # 79

An organization has decided to commit to a business activity with the knowledge that the risk exposure is higher than the risk appetite. Which of the following is the risk practitioner ' s MOST important action related to this decision?

A.

Recommend risk remediation

B.

Change the level of risk appetite

C.

Document formal acceptance of the risk

D.

Reject the business initiative

Full Access
Question # 80

An organization must make a choice among multiple options to respond to a risk. The stakeholders cannot agree and decide to postpone the decision. Which of the following risk responses has the organization adopted?

A.

Transfer

B.

Mitigation

C.

Avoidance

D.

Acceptance

Full Access
Question # 81

When determining risk ownership, the MAIN consideration should be:

A.

who owns the business process.

B.

the amount of residual risk.

C.

who is responsible for risk mitigation.

D.

the total cost of risk treatment.

Full Access
Question # 82

A large organization is replacing its enterprise resource planning (ERP) system and has decided not to deploy the payroll module of the new system. Instead, the current payroll system will continue to be

used. Of the following, who should own the risk if the ERP and payroll system fail to operate as expected?

A.

The business owner

B.

The ERP administrator

C.

The project steering committee

D.

The IT project manager

Full Access
Question # 83

Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?

A.

Changes in control design

B.

A decrease in the number of key controls

C.

Changes in control ownership

D.

An increase in residual risk

Full Access
Question # 84

During a risk assessment of a financial institution, a risk practitioner discovers that tellers can initiate and approve transactions of significant value. This team is also responsible for ensuring transactions are recorded and balances are reconciled by the end of the day. Which of the following is the risk practitioner ' s BEST recommendation to mitigate the associated risk?

A.

Implement continuous monitoring.

B.

Require a second level of approval.

C.

Implement separation of duties.

D.

Require a code of ethics.

Full Access
Question # 85

Which of the following is the BEST indication of the effectiveness of a business continuity program?

A.

Business continuity tests are performed successfully and issues are addressed.

B.

Business impact analyses are reviewed and updated in a timely manner.

C.

Business continuity and disaster recovery plans are regularly updated.

D.

Business units are familiar with the business continuity plans and process.

Full Access
Question # 86

Which of the following is the BEST approach to use when creating a comprehensive set of IT risk scenarios?

A.

Derive scenarios from IT risk policies and standards.

B.

Map scenarios to a recognized risk management framework.

C.

Gather scenarios from senior management.

D.

Benchmark scenarios against industry peers.

Full Access
Question # 87

Which of the following is MOST important to consider before determining a response to a vulnerability?

A.

The likelihood and impact of threat events

B.

The cost to implement the risk response

C.

Lack of data to measure threat events

D.

Monetary value of the asset

Full Access
Question # 88

An organization has detected unauthorized logins to its client database servers. Which of the following should be of GREATEST concern?

A.

Potential increase in regulatory scrutiny

B.

Potential system downtime

C.

Potential theft of personal information

D.

Potential legal risk

Full Access
Question # 89

Which of the following is MOST important for successful incident response?

A.

The quantity of data logged by the attack control tools

B.

Blocking the attack route immediately

C.

The ability to trace the source of the attack

D.

The timeliness of attack recognition

Full Access
Question # 90

During a routine check, a system administrator identifies unusual activity indicating an intruder within a firewall. Which of the following controls has MOST likely been compromised?

A.

Data validation

B.

Identification

C.

Authentication

D.

Data integrity

Full Access
Question # 91

A business unit has decided to accept the risk of implementing an off-the-shelf, commercial software package that uses weak password controls. The BEST course of action would be to:

A.

obtain management approval for policy exception.

B.

develop an improved password software routine.

C.

select another application with strong password controls.

D.

continue the implementation with no changes.

Full Access
Question # 92

An organization uses an automated vulnerability scanner to identify potential vulnerabilities on various enterprise systems. Who is accountable for ensuring the vulnerabilities are mitigated?

A.

Data owners

B.

Information security manager

C.

System administrators

D.

System owners

Full Access
Question # 93

The risk associated with a high-risk vulnerability in an application is owned by the:

A.

security department.

B.

business unit

C.

vendor.

D.

IT department.

Full Access
Question # 94

Which of the following is MOST important to ensure before using risk reports in decision making?

A.

Root cause analysis is included.

B.

Risk analysis results are validated.

C.

Real-time risk information is provided.

D.

Quantitative risk data is provided.

Full Access
Question # 95

An organization has determined that risk is not being adequately tracked and

managed due to a distributed operating model. Which of the following is the

BEST way to address this issue?

A.

Increase the frequency of risk assessments.

B.

Revalidate the organization ' s risk appetite

C.

Create a centralized portfolio of risk scenarios.

D.

Create dashboards for risk metrics.

Full Access
Question # 96

An organization maintains independent departmental risk registers that are not automatically aggregated. Which of the following is the GREATEST concern?

A.

Management may be unable to accurately evaluate the risk profile.

B.

Resources may be inefficiently allocated.

C.

The same risk factor may be identified in multiple areas.

D.

Multiple risk treatment efforts may be initiated to treat a given risk.

Full Access
Question # 97

Which of the following is the GREATEST risk of relying on artificial intelligence (Al) within heuristic security systems?

A.

Al may result in less reliance on human intervention.

B.

Malicious activity may inadvertently be classified as normal during baselining.

C.

Risk assessments of heuristic security systems are more difficult.

D.

Predefined patterns of malicious activity may quickly become outdated.

Full Access
Question # 98

An IT risk practitioner ' s report includes a treatment plan and projected risk ratings if recommendations are implemented. Once corrective actions are taken by the system owner, which of the following types of risk will the projected risk become?

A.

Control

B.

Inherent

C.

Residual

D.

Compliance

Full Access
Question # 99

Of the following, who is responsible for approval when a change in an application system is ready for release to production?

A.

Information security officer

B.

IT risk manager

C.

Business owner

D.

Chief risk officer (CRO)

Full Access
Question # 100
A.

To gain stakeholder support for the implementation of controls

B.

To address multiple risk scenarios mitigated by technical controls

C.

To comply with industry best practices by balancing multiple types of controls

D.

To improve the effectiveness of controls that mitigate risk

Full Access
Question # 101

Which of the following should be done FIRST when information is no longer required to support business objectives?

A.

Archive the information to a backup database.

B.

Protect the information according to the classification policy.

C.

Assess the information against the retention policy.

D.

Securely and permanently erase the information

Full Access
Question # 102

A systems interruption has been traced to a personal USB device plugged into the corporate network by an IT employee who bypassed internal control procedures. Of the following, who should be accountable?

A.

Business continuity manager (BCM)

B.

Human resources manager (HRM)

C.

Chief risk officer (CRO)

D.

Chief information officer (CIO)

Full Access
Question # 103

IT management has deployed a major update to reduce the risk of system compromise. What is the BEST way to validate the effectiveness of this control?

A.

Conduct social engineering testing.

B.

Perform penetration testing.

C.

Run vulnerability scans.

D.

Review mean time to apply critical patches.

Full Access
Question # 104

Which of the following would be a risk practitioner ' s MOST important action upon learning that an IT control has failed?

A.

Implement a replacement control.

B.

Adjust residual risk rating.

C.

Escalate to senior management.

D.

Review compensating controls.

Full Access
Question # 105

Which of the following is the BEST evidence that a user account has been properly authorized?

A.

An email from the user accepting the account

B.

Notification from human resources that the account is active

C.

User privileges matching the request form

D.

Formal approval of the account by the user ' s manager

Full Access
Question # 106

Which of the following is the BEST approach to mitigate the risk associated with outsourcing network management to an external vendor who will have access to sensitive information assets?

A.

Prepare a skills matrix to illustrate tasks and required expertise.

B.

Require periodic security assessments of the vendor within the contract.

C.

Perform due diligence to enable holistic assessment of the vendor.

D.

Plan a phased approach for the transition of processes to the vendor.

Full Access
Question # 107

In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities. The risk practitioner ' s BEST recommendation to further reduce the impact of ransomware attacks would be to implement:

A.

two-factor authentication.

B.

continuous data backup controls.

C.

encryption for data at rest.

D.

encryption for data in motion.

Full Access
Question # 108

Which of the following BEST enables the selection of appropriate risk treatment in the event of a disaster?

A.

Business impact analysis (BIA)

B.

Risk scenario analysis

C.

Failover procedures

D.

Risk treatment plan

Full Access
Question # 109

Which of the following is the BEST way to support communication of emerging risk?

A.

Update residual risk levels to reflect the expected risk impact.

B.

Adjust inherent risk levels upward.

C.

Include it on the next enterprise risk committee agenda.

D.

Include it in the risk register for ongoing monitoring.

Full Access
Question # 110

Which of the following is MOST helpful in identifying loss magnitude during risk analysis of a new system?

A.

Recovery time objective (RTO)

B.

Cost-benefit analysis

C.

Business impact analysis (BIA)

D.

Cyber insurance coverage

Full Access
Question # 111

A web-based service provider with a low risk appetite for system outages is reviewing its current risk profile for online security. Which of the following observations would be MOST relevant to escalate to senior management?

A.

An increase in attempted distributed denial of service (DDoS) attacks

B.

An increase in attempted website phishing attacks

C.

A decrease in achievement of service level agreements (SLAs)

D.

A decrease in remediated web security vulnerabilities

Full Access
Question # 112

Which of the following would BEST mitigate the ongoing risk associated with operating system (OS) vulnerabilities?

A.

Temporarily mitigate the OS vulnerabilities

B.

Document and implement a patching process

C.

Evaluate permanent fixes such as patches and upgrades

D.

Identify the vulnerabilities and applicable OS patches

Full Access
Question # 113

Which of the following should be initiated when a high number of noncompliant conditions are observed during review of a control procedure?

A.

Disciplinary action

B.

A control self-assessment

C.

A review of the awareness program

D.

Root cause analysis

Full Access
Question # 114

Which of the following is the MOST important consideration when determining whether to accept residual risk after security controls have been implemented on a critical system?

A.

Cost versus benefit of additional mitigating controls

B.

Annualized loss expectancy (ALE) for the system

C.

Frequency of business impact

D.

Cost of the Information control system

Full Access
Question # 115

An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner ' s FIRST course of action?

A.

Determine whether the impact is outside the risk appetite.

B.

Request a formal acceptance of risk from senior management.

C.

Report the ineffective control for inclusion in the next audit report.

D.

Deploy a compensating control to address the identified deficiencies.

Full Access
Question # 116

Which of the following should a risk practitioner review FIRST when evaluating risk events associated with the organization ' s data flow model?

A.

Results of data classification activities

B.

Recent changes to enterprise architecture (EA)

C.

High-level network diagrams

D.

Notes from interviews with the data owners

Full Access
Question # 117

The MOST significant benefit of using a consistent risk ranking methodology across an organization is that it enables:

A.

allocation of available resources

B.

clear understanding of risk levels

C.

assignment of risk to the appropriate owners

D.

risk to be expressed in quantifiable terms

Full Access
Question # 118

Which of the following activities would BEST contribute to promoting an organization-wide risk-aware culture?

A.

Performing a benchmark analysis and evaluating gaps

B.

Conducting risk assessments and implementing controls

C.

Communicating components of risk and their acceptable levels

D.

Participating in peer reviews and implementing best practices

Full Access
Question # 119

IT disaster recovery point objectives (RPOs) should be based on the:

A.

maximum tolerable downtime.

B.

maximum tolerable loss of data.

C.

need of each business unit.

D.

type of business.

Full Access
Question # 120

When reviewing management ' s IT control self-assessments, a risk practitioner noted an ineffective control that links to several low residual risk scenarios. What should be the NEXT course of action?

A.

Assess management ' s risk tolerance.

B.

Recommend management accept the low-risk scenarios.

C.

Propose mitigating controls

D.

Re-evaluate the risk scenarios associated with the control

Full Access
Question # 121

A chief risk officer (CRO) has asked to have the IT risk register integrated into the enterprise risk management (ERM) process. Which of the following will BEST facilitate the reporting of IT risk at the enterprise level?

A.

Aggregating the IT risk scenarios into a maturity benchmark value

B.

Using an IT risk heat map to depict likelihood and impact

C.

Using the same risk taxonomy across the organization

D.

Providing a summary of open IT risk-related audit findings

Full Access
Question # 122

Which of the following has the MOST validity for conducting risk assessments?

A.

Internal control effectiveness measured through inference from external assessment

B.

Control effectiveness determined through subject matter expertise estimation

C.

Inferences of internal control effectiveness from peer reports

D.

Internal control effectiveness measured through direct testing

Full Access
Question # 123

An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?

A.

Nondisclosure agreements (NDAs)

B.

Data anonymization

C.

Data cleansing

D.

Data encryption

Full Access
Question # 124

Management has required information security awareness training to reduce the risk associated with credential compromise. What is the BEST way to assess the effectiveness of the training?

A.

Conduct social engineering testing.

B.

Audit security awareness training materials.

C.

Administer an end-of-training quiz.

D.

Perform a vulnerability assessment.

Full Access
Question # 125

A cloud service provider has completed upgrades to its cloud infrastructure to enhance service availability. Which of the following is the MOST important key risk indicator (KRI) for management to monitor?

A.

Peak demand on the cloud service during business hours

B.

Percentage of technology upgrades resulting in security breaches

C.

Number of incidents with downtime exceeding contract threshold

D.

Percentage of servers not patched per policy

Full Access
Question # 126

Which of the following would be MOST helpful to a risk owner when making risk-aware decisions?

A.

Risk exposure expressed in business terms

B.

Recommendations for risk response options

C.

Resource requirements for risk responses

D.

List of business areas affected by the risk

Full Access
Question # 127

Which of the following is the PRIMARY purpose of analyzing control effectiveness during risk analysis?

A.

To enable a control cost-benefit analysis

B.

To evaluate the risk impact

C.

To determine the likelihood of occurrence

D.

To determine the current risk level

Full Access
Question # 128

Which of the following is the MOST significant risk associated with using cloud computing for disaster recovery?

A.

Cloud vendor lock-in and dependency

B.

Lack of adequate incident management capabilities

C.

Use of multiple cloud access service brokers (CASBs)

D.

Availability issues with cloud storage solutions

Full Access
Question # 129

Which of the following is the MOST critical element to maximize the potential for a successful security implementation?

A.

The organization ' s knowledge

B.

Ease of implementation

C.

The organization ' s culture

D.

industry-leading security tools

Full Access
Question # 130

Which of the following is the BEST approach for an organization in a heavily regulated industry to comprehensively test application functionality?

A.

Use production data in a non-production environment

B.

Use masked data in a non-production environment

C.

Use test data in a production environment

D.

Use anonymized data in a non-production environment

Full Access
Question # 131

Which of The following is the MOST comprehensive input to the risk assessment process specific to the effects of system downtime?

A.

Business continuity plan (BCP) testing results

B.

Recovery lime objective (RTO)

C.

Business impact analysis (BIA)

D.

results Recovery point objective (RPO)

Full Access
Question # 132

Which of the following is MOST important to review when evaluating the ongoing effectiveness of the IT risk register?

A.

The costs associated with mitigation options

B.

The status of identified risk scenarios

C.

The cost-benefit analysis of each risk response

D.

The timeframes for risk response actions

Full Access
Question # 133

The BEST key performance indicator (KPI) to measure the effectiveness of a backup process would be the number of:

A.

resources to monitor backups

B.

restoration monitoring reports

C.

backup recovery requests

D.

recurring restore failures

Full Access
Question # 134

Which of the following is MOST important to consider when determining the risk associated with re-identification of obfuscated personal data?

A.

The type of shared data

B.

The level of residual risk after data loss prevention (DLP) controls are implemented

C.

The monetary value of the unique records that could be re-identified

D.

The impact to affected stakeholders

Full Access
Question # 135

A risk practitioner wants to identify potential risk events that affect the continuity of a critical business process. Which of the following should the risk practitioner do FIRST?

A.

Evaluate current risk management alignment with relevant regulations.

B.

Determine if business continuity procedures are reviewed and updated on a regular basis.

C.

Review the methodology used to conduct the business impact analysis (BIA).

D.

Conduct a benchmarking exercise against industry peers.

Full Access
Question # 136

The PRIMARY reason for tracking the status of risk mitigation plans is to ensure:

A.

the proposed controls are implemented as scheduled.

B.

security controls are tested prior to implementation.

C.

compliance with corporate policies.

D.

the risk response strategy has been decided.

Full Access
Question # 137

A user has contacted the risk practitioner regarding malware spreading laterally across the organization ' s corporate network. Which of the following is the risk practitioner’s BEST course of action?

A.

Review all log files generated during the period of malicious activity.

B.

Perform a root cause analysis.

C.

Notify the cybersecurity incident response team.

D.

Update the risk register.

Full Access
Question # 138

Which of the following is MOST helpful in aligning IT risk with business objectives?

A.

Introducing an approved IT governance framework

B.

Integrating the results of top-down risk scenario analyses

C.

Performing a business impact analysis (BlA)

D.

Implementing a risk classification system

Full Access
Question # 139

Which of the following is the MOST important reason for a risk practitioner to identify stakeholders for each IT risk scenario?

A.

To ensure enterprise-wide risk management

B.

To establish control ownership

C.

To enable a comprehensive view of risk

D.

To identify key risk indicators (KRIs)

Full Access
Question # 140

An IT department originally planned to outsource the hosting of its data center at an overseas location to reduce operational expenses. After a risk assessment, the department has decided to keep the data center in-house. How should the risk treatment response be reflected in the risk register?

A.

Risk mitigation

B.

Risk avoidance

C.

Risk acceptance

D.

Risk transfer

Full Access
Question # 141

Which of the following is the PRIMARY purpose of a risk register?

A.

It guides management in determining risk appetite.

B.

It provides management with a risk inventory.

C.

It aligns risk scenarios to business objectives.

D.

It monitors the performance of risk and control owners.

Full Access
Question # 142

Which of the following IT controls is MOST useful in mitigating the risk associated with inaccurate data?

A.

Encrypted storage of data

B.

Links to source data

C.

Audit trails for updates and deletions

D.

Check totals on data records and data fields

Full Access
Question # 143

The PRIMARY objective of collecting information and reviewing documentation when performing periodic risk analysis should be to:

A.

Identify new or emerging risk issues.

B.

Satisfy audit requirements.

C.

Survey and analyze historical risk data.

D.

Understand internal and external threat agents.

Full Access
Question # 144

Which of the following is the PRIMARY objective of aggregating the impact of IT risk scenarios and reflecting the results in the enterprise risk register?

A.

To ensure IT risk appetite is communicated across the organization

B.

To ensure IT risk impact can be compared to the IT risk appetite

C.

To ensure IT risk ownership is assigned at the appropriate organizational level

D.

To ensure IT risk scenarios are consistently assessed within the organization

Full Access
Question # 145

To enable effective integration of IT risk scenarios and ERM, it is MOST important to have a consistent approach to reporting:

A.

Risk impact and likelihood

B.

Risk velocity

C.

Key risk indicators (KRIs)

D.

Risk response plans and owners

Full Access
Question # 146

An IT license audit has revealed that there are several unlicensed copies of co be to:

A.

immediately uninstall the unlicensed software from the laptops

B.

centralize administration rights on laptops so that installations are controlled

C.

report the issue to management so appropriate action can be taken.

D.

procure the requisite licenses for the software to minimize business impact.

Full Access
Question # 147

Which of the following is the MOST important consideration when selecting key risk indicators (KRIs) to monitor risk trends over time?

A.

Ongoing availability of data

B.

Ability to aggregate data

C.

Ability to predict trends

D.

Availability of automated reporting systems

Full Access
Question # 148

Which of the following is the BEST way to quantify the likelihood of risk materialization?

A.

Balanced scorecard

B.

Threat and vulnerability assessment

C.

Compliance assessments

D.

Business impact analysis (BIA)

Full Access
Question # 149

An organization ' s IT department wants to complete a proof of concept (POC) for a security tool. The project lead has asked for approval to use the production data for testing purposes as it will yield the best results. Which of the following is the risk practitioner ' s BEST recommendation?

A.

Accept the risk of using the production data to ensure accurate results.

B.

Assess the risk of using production data for testing before making a decision.

C.

Benchmark against what peer organizations are doing with POC testing environments.

D.

Deny the request, as production data should not be used for testing purposes.

Full Access
Question # 150

Which of the following observations would be GREATEST concern to a risk practitioner reviewing the implementation status of management action plans?

A.

Management has not determined a final implementation date.

B.

Management has not completed an early mitigation milestone.

C.

Management has not secured resources for mitigation activities.

D.

Management has not begun the implementation.

Full Access
Question # 151

The BEST way to mitigate the high cost of retrieving electronic evidence associated with potential litigation is to implement policies and procedures for:

A.

data classification and labeling.

B.

data logging and monitoring.

C.

data retention and destruction.

D.

data mining and analytics.

Full Access
Question # 152

Which of the following is the BEST method to identify unnecessary controls?

A.

Evaluating the impact of removing existing controls

B.

Evaluating existing controls against audit requirements

C.

Reviewing system functionalities associated with business processes

D.

Monitoring existing key risk indicators (KRIs)

Full Access
Question # 153

Which of the following would be MOST useful when measuring the progress of a risk response action plan?

A.

Percentage of mitigated risk scenarios

B.

Annual loss expectancy (ALE) changes

C.

Resource expenditure against budget

D.

An up-to-date risk register

Full Access
Question # 154

After identifying new risk events during a project, the project manager s NEXT step should be to:

A.

determine if the scenarios need 10 be accepted or responded to.

B.

record the scenarios into the risk register.

C.

continue with a qualitative risk analysis.

D.

continue with a quantitative risk analysis.

Full Access
Question # 155

A bank is experiencing an increasing incidence of customer identity theft. Which of the following is the BEST way to mitigate this risk?

A.

Implement monitoring techniques.

B.

Implement layered security.

C.

Outsource to a local processor.

D.

Conduct an awareness campaign.

Full Access
Question # 156

Which of the following is MOST important to compare against the corporate risk profile?

A.

Industry benchmarks

B.

Risk tolerance

C.

Risk appetite

D.

Regulatory compliance

Full Access
Question # 157

A business manager wants to leverage an existing approved vendor solution from another area within the organization. Which of the following is the risk practitioner ' s BEST course of action?

A.

Recommend allowing the new usage based on prior approval.

B.

Request a new third-party review.

C.

Request revalidation of the original use case.

D.

Assess the risk associated with the new use case.

Full Access
Question # 158

Which of the following would be MOST useful to senior management when determining an appropriate risk response?

A.

A comparison of current risk levels with established tolerance

B.

A comparison of cost variance with defined response strategies

C.

A comparison of current risk levels with estimated inherent risk levels

D.

A comparison of accepted risk scenarios associated with regulatory compliance

Full Access
Question # 159

Which of the following is the MOST important objective of establishing an enterprise risk management (ERM) function within an organization?

A.

To have a unified approach to risk management across the organization

B.

To have a standard risk management process for complying with regulations

C.

To optimize risk management resources across the organization

D.

To ensure risk profiles are presented in a consistent format within the organization

Full Access
Question # 160

Who should have the authority to approve an exception to a control?

A.

information security manager

B.

Control owner

C.

Risk owner

D.

Risk manager

Full Access
Question # 161

The PRIMARY objective of a risk identification process is to:

A.

evaluate how risk conditions are managed.

B.

determine threats and vulnerabilities.

C.

estimate anticipated financial impact of risk conditions.

D.

establish risk response options.

Full Access
Question # 162

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner ' s NEXT step?

A.

Develop a mechanism for monitoring residual risk.

B.

Update the risk register with the results.

C.

Prepare a business case for the response options.

D.

Identify resources for implementing responses.

Full Access
Question # 163

Which of the following is the MOST important document regarding the treatment of sensitive data?

A.

Encryption policy

B.

Organization risk profile

C.

Digital rights management policy

D.

Information classification policy

Full Access
Question # 164

Which of the following is MOST effective against external threats to an organizations confidential information?

A.

Single sign-on

B.

Data integrity checking

C.

Strong authentication

D.

Intrusion detection system

Full Access
Question # 165

Which of the following should be the PRIMARY input to determine risk tolerance?

A.

Regulatory requirements

B.

Organizational objectives

C.

Annual loss expectancy (ALE)

D.

Risk management costs

Full Access
Question # 166

Which of the following is the MOST appropriate role to determine risk appetite and tolerance?

A.

Senior management

B.

Internal auditor

C.

Risk owner

D.

Business process owner

Full Access
Question # 167

Which of the following is the PRIMARY purpose of creating and documenting control procedures?

A.

To facilitate ongoing audit and control testing

B.

To help manage risk to acceptable tolerance levels

C.

To establish and maintain a control inventory

D.

To increase the likelihood of effective control operation

Full Access
Question # 168

Which of the following data would be used when performing a business impact analysis (BIA)?

A.

Cost-benefit analysis of running the current business

B.

Cost of regulatory compliance

C.

Projected impact of current business on future business

D.

Expected costs for recovering the business

Full Access
Question # 169

Which of the following represents a vulnerability?

A.

An identity thief seeking to acquire personal financial data from an organization

B.

Media recognition of an organization ' s market leadership in its industry

C.

A standard procedure for applying software patches two weeks after release

D.

An employee recently fired for insubordination

Full Access
Question # 170

A robotic process automation (RPA) project has implemented new robots to enhance the efficiency of a sales business process. Which of the following provides the BEST evidence that the new controls have been implemented successfully?

A.

A post-implementation review has been conducted by key personnel.

B.

A qualified independent party assessed the new controls as effective.

C.

Senior management has signed off on the design of the controls.

D.

Robots have operated without human interference on a daily basis.

Full Access
Question # 171

Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?

A.

To deliver projects on time and on budget

B.

To assess inherent risk

C.

To include project risk in the enterprise-wide IT risk profit.

D.

To assess risk throughout the project

Full Access
Question # 172

From a risk management perspective, the PRIMARY objective of using maturity models is to enable:

A.

solution delivery.

B.

resource utilization.

C.

strategic alignment.

D.

performance evaluation.

Full Access
Question # 173

Which of the following is the BEST key performance indicator (KPI) to measure the effectiveness of IT policies? The number of:

A.

IT policy exceptions granted.

B.

Senior management approvals.

C.

Key technology controls covered by IT policies.

D.

Processes covered by IT policies.

Full Access
Question # 174

Which of the following would BEST facilitate the implementation of data classification requirements?

A.

Assigning a data owner

B.

Implementing technical control over the assets

C.

Implementing a data loss prevention (DLP) solution

D.

Scheduling periodic audits

Full Access
Question # 175

Digital signatures are an effective control method for information exchange over an insecure network because they:

A.

authenticate the user biometrically.

B.

are under the sole custody of the receiver.

C.

are constant over time.

D.

enable nonrepudiation.

Full Access
Question # 176

The PRIMARY reason for a risk practitioner to review business processes is to:

A.

Benchmark against peer organizations.

B.

Identify appropriate controls within business processes.

C.

Assess compliance with global standards.

D.

Identify risk owners related to business processes.

Full Access
Question # 177

Which of the following would be a risk practitioner ' s BEST course of action when a project team has accepted a risk outside the established risk appetite?

A.

Reject the risk acceptance and require mitigating controls.

B.

Monitor the residual risk level of the accepted risk.

C.

Escalate the risk decision to the project sponsor for review.

D.

Document the risk decision in the project risk register.

Full Access
Question # 178

Well-developed, data-driven risk measurements should be:

A.

reflective of the lowest organizational level.

B.

a data feed taken directly from operational production systems.

C.

reported to management the same day data is collected.

D.

focused on providing a forward-looking view.

Full Access
Question # 179

Which of the following activities BEST facilitates effective risk management throughout the organization?

A.

Reviewing risk-related process documentation

B.

Conducting periodic risk assessments

C.

Performing a business impact analysis (BIA)

D.

Performing frequent audits

Full Access
Question # 180

Which of the following is the BEST time for an enterprise project management team to use risk analysis?

A.

When the final testing phase begins

B.

During the project initiation phase

C.

At the end of the project

D.

During business impact analysis (BIA)

Full Access
Question # 181

Which of the following is MOST important when defining controls?

A.

Identifying monitoring mechanisms

B.

Including them in the risk register

C.

Aligning them with business objectives

D.

Prototyping compensating controls

Full Access
Question # 182

Which of the following is the MOST significant risk related to an organization ' s use of AI technology?

A.

The AI system ' s contract does not include a right-to-audit clause

B.

The AI system is being used beyond its intended purpose

C.

The AI system is on unsupported infrastructure

D.

The AI system results have not been validated

Full Access
Question # 183

A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner s NEXT step? r

A.

Prepare a business case for the response options.

B.

Identify resources for implementing responses.

C.

Develop a mechanism for monitoring residual risk.

D.

Update the risk register with the results.

Full Access
Question # 184

An organization ' s control environment is MOST effective when:

A.

controls perform as intended.

B.

controls operate efficiently.

C.

controls are implemented consistent

D.

control designs are reviewed periodically

Full Access
Question # 185

Which of the following roles should be assigned accountability for monitoring risk levels?

A.

Risk practitioner

B.

Business manager

C.

Risk owner

D.

Control owner

Full Access
Question # 186

Which of me following is MOST helpful to mitigate the risk associated with an application under development not meeting business objectives?

A.

Identifying tweets that may compromise enterprise architecture (EA)

B.

Including diverse Business scenarios in user acceptance testing (UAT)

C.

Performing risk assessments during the business case development stage

D.

Including key stakeholders in review of user requirements

Full Access
Question # 187

Which of the following will BEST mitigate the risk associated with IT and business misalignment?

A.

Establishing business key performance indicators (KPIs)

B.

Introducing an established framework for IT architecture

C.

Establishing key risk indicators (KRIs)

D.

Involving the business process owner in IT strategy

Full Access
Question # 188

Which of the following provides The MOST useful information when determining a risk management program ' s maturity level?

A.

Risk assessment results

B.

A recently reviewed risk register

C.

Key performance indicators (KPIs)

D.

The organization ' s risk framework

Full Access
Question # 189

An organization is reviewing a contract for a Software as a Service (SaaS) sales application with a 99.9% uptime service level agreement (SLA). Which of the following BEST describes ownership of availability risk?

A.

The risk is shared by both organizations.

B.

The liability for the risk is owned by the cloud provider.

C.

The risk is transferred to the cloud provider.

D.

The liability for the risk is owned by the sales department.

Full Access
Question # 190

An organization has identified that terminated employee accounts are not disabled or deleted within the time required by corporate policy. Unsure of the reason, the organization has decided to monitor the situation for three months to obtain more information. As a result of this decision, the risk has been:

A.

avoided.

B.

accepted.

C.

mitigated.

D.

transferred.

Full Access
Question # 191

When classifying and prioritizing risk responses, the areas to address FIRST are those with:

A.

low cost effectiveness ratios and high risk levels

B.

high cost effectiveness ratios and low risk levels.

C.

high cost effectiveness ratios and high risk levels

D.

low cost effectiveness ratios and low risk levels.

Full Access
Question # 192

Which of the following conditions presents the GREATEST risk to an application?

A.

Application controls are manual.

B.

Application development is outsourced.

C.

Source code is escrowed.

D.

Developers have access to production environment.

Full Access
Question # 193

Which of the following describes the relationship between Key risk indicators (KRIs) and key control indicators (KCIS)?

A.

KCIs are independent from KRIs KRIs.

B.

KCIs and KRIs help in determining risk appetite.

C.

KCIs are defined using data from KRIs.

D.

KCIs provide input for KRIs

Full Access
Question # 194

An organization moved its payroll system to a Software as a Service (SaaS) application. A new data privacy regulation stipulates that data can only be processed within the countrywhere it is collected. Which of the following should be done FIRST when addressing this situation?

A.

Analyze data protection methods.

B.

Understand data flows.

C.

Include a right-to-audit clause.

D.

Implement strong access controls.

Full Access
Question # 195

What is the BEST course of action when the business impact of a risk event is rated high, but the likelihood of risk materialization has decreased?

A.

Adjust risk tolerance thresholds.

B.

Adjust the associated key risk indicator (KRI).

C.

Further mitigate the risk.

D.

Accept the risk if within tolerance.

Full Access
Question # 196

Which of the following is the BEST recommendation to senior management when the results of a risk and control assessment indicate a risk scenario can only be partially mitigated?

A.

Implement controls to bring the risk to a level within appetite and accept the residual risk.

B.

Implement a key performance indicator (KPI) to monitor the existing control performance.

C.

Accept the residual risk in its entirety and obtain executive management approval.

D.

Separate the risk into multiple components and avoid the risk components that cannot be mitigated.

Full Access
Question # 197

A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?

A.

Conduct risk classification for associated IT controls.

B.

Determine whether risk responses still effectively address risk.

C.

Perform vulnerability and threat assessments.

D.

Analyze and update IT control assessments.

Full Access
Question # 198

Which of the following provides the MOST useful information when developing a risk profile for management approval?

A.

Residual risk and risk appetite

B.

Strength of detective and preventative controls

C.

Effectiveness and efficiency of controls

D.

Inherent risk and risk tolerance

Full Access
Question # 199

Which of the following should be a risk practitioner ' s NEXT action after identifying a high probability of data loss in a system?

A.

Enhance the security awareness program.

B.

Increase the frequency of incident reporting.

C.

Purchase cyber insurance from a third party.

D.

Conduct a control assessment.

Full Access
Question # 200

Which of the following would BEST help an enterprise prioritize risk scenarios?

A.

Industry best practices

B.

Placement on the risk map

C.

Degree of variances in the risk

D.

Cost of risk mitigation

Full Access
Question # 201

Which of the following is the PRIMARY factor in determining a recovery time objective (RTO)?

A.

Cost of offsite backup premises

B.

Cost of downtime due to a disaster

C.

Cost of testing the business continuity plan

D.

Response time of the emergency action plan

Full Access
Question # 202

Which of the following is MOST important when developing key performance indicators (KPIs)?

A.

Alignment to risk responses

B.

Alignment to management reports

C.

Alerts when risk thresholds are reached

D.

Identification of trends

Full Access
Question # 203

Which of the following should be the risk practitioner ' s FIRST course of action when an organization plans to adopt a cloud computing strategy?

A.

Request a budget for implementation

B.

Conduct a threat analysis.

C.

Create a cloud computing policy.

D.

Perform a controls assessment.

Full Access
Question # 204

Which of the following is the BEST key performance indicator (KPI) for determining how well an IT policy is aligned to business requirements?

A.

Total cost to support the policy

B.

Number of exceptions to the policy

C.

Total cost of policy breaches

D.

Number of inquiries regarding the policy

Full Access
Question # 205

Which of the following is the MOST useful information for a risk practitioner when planning response activities after risk identification?

A.

Risk register

B.

Risk appetite

C.

Risk priorities

D.

Risk heat maps

Full Access
Question # 206

Which of the following is the MOST important objective of an enterprise risk management (ERM) program?

A.

To create a complete repository of risk to the organization

B.

To create a comprehensive view of critical risk to the organization

C.

To provide a bottom-up view of the most significant risk scenarios

D.

To optimize costs of managing risk scenarios in the organization

Full Access
Question # 207

A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:

A.

updating the risk register.

B.

validating the risk scenarios.

C.

documenting the risk scenarios.

D.

identifying risk mitigation controls.

Full Access
Question # 208

Which of the following provides the MOST insight regarding an organization ' s risk culture?

A.

Awareness training participation rate

B.

Risk assessment results

C.

Senior management interviews

D.

Risk management framework

Full Access
Question # 209

Using key risk indicators (KRIs) to illustrate changes in the risk profile PRIMARILY helps to:

A.

communicate risk trends to stakeholders.

B.

assign ownership of emerging risk scenarios.

C.

highlight noncompliance with the risk policy

D.

identify threats to emerging technologies.

Full Access
Question # 210

A risk practitioner discovers that an IT operations team manager bypassed web filtering controls by using a mobile device, in violation of the network security policy. Which of the following should the risk practitioner do FIRST?

A.

Report the incident.

B.

Plan a security awareness session.

C.

Assess the new risk.

D.

Update the risk register.

Full Access
Question # 211

Which of the following will BEST help ensure that risk factors identified during an information systems review are addressed?

A.

Informing business process owners of the risk

B.

Reviewing and updating the risk register

C.

Assigning action items and deadlines to specific individuals

D.

Implementing new control technologies

Full Access
Question # 212

Business areas within an organization have engaged various cloud service providers directly without assistance from the IT department. What should the risk practitioner do?

A.

Recommend the IT department remove access to the cloud services.

B.

Engage with the business area managers to review controls applied.

C.

Escalate to the risk committee.

D.

Recommend a risk assessment be conducted.

Full Access
Question # 213

The PRIMARY reason for periodically monitoring key risk indicators (KRIs) is to:

A.

rectify errors in results of KRIs.

B.

detect changes in the risk profile.

C.

reduce costs of risk mitigation controls.

D.

continually improve risk assessments.

Full Access
Question # 214

When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?

A.

Compliance with industry frameworks

B.

Alignment with applicable legal and regulatory requirements

C.

Approval of mitigating and compensating controls

D.

Adoption of mission and vision statements

Full Access
Question # 215

Which of the following is the MOST important consideration when multiple risk practitioners capture risk scenarios in a single risk register?

A.

Aligning risk ownership and control ownership

B.

Developing risk escalation and reporting procedures

C.

Maintaining up-to-date risk treatment plans

D.

Using a consistent method for risk assessment

Full Access
Question # 216

Which of the following is MOST important to the successful development of IT risk scenarios?

A.

Cost-benefit analysis

B.

Internal and external audit reports

C.

Threat and vulnerability analysis

D.

Control effectiveness assessment

Full Access
Question # 217

Which of the following would be a risk practitioners’ BEST recommendation for preventing cyber intrusion?

A.

Establish a cyber response plan

B.

Implement data loss prevention (DLP) tools.

C.

Implement network segregation.

D.

Strengthen vulnerability remediation efforts.

Full Access
Question # 218

How does the identification of risk scenarios contribute to effective IT risk management?

A.

By facilitating post-incident investigations

B.

By enabling proactive risk assessment

C.

By identifying cybersecurity incidents

D.

By creating awareness of risk mitigation strategies

Full Access
Question # 219

Which of the following is MOST important for an organization to have in place when developing a risk management framework?

A.

A strategic approach to risk including an established risk appetite

B.

A risk-based internal audit plan for the organization

C.

A control function within the risk management team

D.

An organization-wide risk awareness training program

Full Access
Question # 220

Which of the following is the GREATEST benefit when enterprise risk management (ERM) provides oversight of IT risk management?

A.

Aligning IT with short-term and long-term goals of the organization

B.

Ensuring the IT budget and resources focus on risk management

C.

Ensuring senior management ' s primary focus is on the impact of identified risk

D.

Prioritizing internal departments that provide service to customers

Full Access
Question # 221

When creating a separate IT risk register for a large organization, which of the following is MOST important to consider with regard to the existing corporate risk ' register?

A.

Leveraging business risk professionals

B.

Relying on generic IT risk scenarios

C.

Describing IT risk in business terms

D.

Using a common risk taxonomy

Full Access
Question # 222

In addition to the risk exposure, which of the following is MOST important for senior management to understand prior to approving the use of artificial intelligence (Al) solutions?

A.

Potential benefits from use of Al solutions

B.

Monitoring techniques required for AI solutions

C.

Changes to existing infrastructure to support Al solutions

D.

Skills required to support Al solutions

Full Access
Question # 223

A risk practitioner has identified that the agreed recovery time objective (RTO) with a Software as a Service (SaaS) provider is longer than the business expectation. Which ot the following is the risk practitioner ' s BEST course of action?

A.

Collaborate with the risk owner to determine the risk response plan.

B.

Document the gap in the risk register and report to senior management.

C.

Include a right to audit clause in the service provider contract.

D.

Advise the risk owner to accept the risk.

Full Access
Question # 224

Which of the following provides the MOST useful information to senior management about risk mitigation status?

A.

Risk strategy

B.

Risk register

C.

Gap analysis

D.

Business impact analysis (BIA)

Full Access
Question # 225

Which of the following is the PRIMARY benefit of using a risk map with stakeholders?

A.

Consolidates risk response options by severity

B.

Aligns risk appetite with business objectives

C.

Correlates risk scenarios to risk appetite

D.

Defines an organizational risk taxonomy

Full Access
Question # 226

Which of the following statements BEST describes risk appetite?

A.

The amount of risk an organization is willing to accept

B.

The effective management of risk and internal control environments

C.

Acceptable variation between risk thresholds and business objectives

D.

The acceptable variation relative to the achievement of objectives

Full Access
Question # 227

Which of the following BEST mitigates the risk associated with inadvertent data leakage by users who work remotely?

A.

Conducting training on the protection of organizational assets

B.

Configuring devices to use virtual IP addresses

C.

Ensuring patching for end-user devices

D.

Providing encrypted access to organizational assets

Full Access
Question # 228

A risk practitioner is concerned with potential data loss in the event of a breach at a hosted third-party provider. Which of the following is the BEST way to mitigate this risk?

A.

Include an indemnification clause in the provider ' s contract.

B.

Monitor provider performance against service level agreements (SLAs).

C.

Purchase cyber insurance to protect against data breaches.

D.

Ensure appropriate security controls are in place through independent audits.

Full Access
Question # 229

Which of We following is the MOST effective control to address the risk associated with compromising data privacy within the cloud?

A.

Establish baseline security configurations with the cloud service provider.

B.

Require the cloud prowler 10 disclose past data privacy breaches.

C.

Ensure the cloud service provider performs an annual risk assessment.

D.

Specify cloud service provider liability for data privacy breaches in the contract

Full Access
Question # 230

The PRIMARY basis for selecting a security control is:

A.

to achieve the desired level of maturity.

B.

the materiality of the risk.

C.

the ability to mitigate risk.

D.

the cost of the control.

Full Access
Question # 231

Which of the following activities is MOST likely to be assigned to the second line in the three lines model?

A.

Validating whether IT risk control systems are operational

B.

Monitoring IT security policy compliance

C.

Calculating phishing attack key risk indicators (KRIs)

D.

Appropriately configuring the web application firewall (WAF)

Full Access
Question # 232

Reviewing which of the following BEST helps an organization gain insight into its overall risk profile?

A.

Threat landscape

B.

Risk appetite

C.

Risk register

D.

Risk metrics

Full Access
Question # 233

Which of the following is the PRIMARY benefit of using an entry in the risk register to track the aggregate risk associated with server failure?

A.

It provides a cost-benefit analysis on control options available for implementation.

B.

It provides a view on where controls should be applied to maximize the uptime of servers.

C.

It provides historical information about the impact of individual servers malfunctioning.

D.

It provides a comprehensive view of the impact should the servers simultaneously fail.

Full Access
Question # 234

Which of the following is MOST important to enable well-informed cybersecurity risk decisions?

A.

Determine and understand the risk rating of scenarios.

B.

Conduct risk assessment peer reviews.

C.

Identify roles and responsibilities for security controls.

D.

Engage a third party to perform a risk assessment.

Full Access
Question # 235

Which of the following is the MOST important consideration when selecting digital signature software?

A.

Availability

B.

Nonrepudiation

C.

Accuracy

D.

Completeness

Full Access
Question # 236

Which of the following would be MOST helpful to a risk practitioner when ensuring that mitigated risk remains within acceptable limits?

A.

Building an organizational risk profile after updating the risk register

B.

Ensuring risk owners participate in a periodic control testing process

C.

Designing a process for risk owners to periodically review identified risk

D.

Implementing a process for ongoing monitoring of control effectiveness

Full Access
Question # 237

Which of the following is MOST important for a risk practitioner to confirm once a risk action plan has been completed?

A.

The risk register has been updated.

B.

The risk tolerance has been recalibrated.

C.

The risk has been mitigated to the intended level.

D.

The risk owner has reviewed the outcomes.

Full Access
Question # 238

An organization is analyzing the risk of shadow IT usage. Which of the following is the MOST important input into the assessment?

A.

Business benefits of shadow IT

B.

Application-related expresses

C.

Classification of the data

D.

Volume of data

Full Access
Question # 239

Which of the following is the MOST important key performance indicator (KPI) to monitor the effectiveness of disaster recovery processes?

A.

Percentage of IT systems recovered within the mean time to restore (MTTR) during the disaster recovery test

B.

Percentage of issues arising from the disaster recovery test resolved on time

C.

Percentage of IT systems included in the disaster recovery test scope

D.

Percentage of IT systems meeting the recovery time objective (RTO) during the disaster recovery test

Full Access
Question # 240

Before assigning sensitivity levels to information it is MOST important to:

A.

define recovery time objectives (RTOs).

B.

define the information classification policy

C.

conduct a sensitivity analyse

D.

Identify information custodians

Full Access
Question # 241

Which of the following should be the FIRST step when a company is made aware of new regulatory requirements impacting IT?

A.

Perform a gap analysis.

B.

Prioritize impact to the business units.

C.

Perform a risk assessment.

D.

Review the risk tolerance and appetite.

Full Access
Question # 242

Which of the following is the PRIMARY reason to ensure policies and standards are properly documented within the risk management process?

A.

It facilitates the use of a framework for risk management.

B.

It establishes a means for senior management to formally approve risk practices.

C.

It encourages risk-based decision making for stakeholders.

D.

It provides a basis for benchmarking against industry standards.

Full Access
Question # 243

For a large software development project, risk assessments are MOST effective when performed:

A.

before system development begins.

B.

at system development.

C.

at each stage of the system development life cycle (SDLC).

D.

during the development of the business case.

Full Access
Question # 244

Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?

A.

Vulnerability and threat analysis

B.

Control remediation planning

C.

User acceptance testing (UAT)

D.

Control self-assessment (CSA)

Full Access
Question # 245

Which of the following is the PRIMARY reason to conduct risk assessments at periodic intervals?

A.

To ensure emerging risk is identified and monitored

B.

To establish the maturity level of risk assessment processes

C.

To promote a risk-aware culture among staff

D.

To ensure risk trend data is collected and reported

Full Access
Question # 246

Before implementing instant messaging within an organization using a public solution, which of the following should be in place to mitigate data leakage risk?

A.

A data extraction tool

B.

An access control list

C.

An intrusion detection system (IDS)

D.

An acceptable usage policy

Full Access
Question # 247

When developing a response plan to address security incidents regarding sensitive data loss, it is MOST important

A.

revalidate current key risk indicators (KRIs).

B.

revise risk management procedures.

C.

review the data classification policy.

D.

revalidate existing risk scenarios.

Full Access
Question # 248

The MOST important objective of information security controls is to:

A.

Identify threats and vulnerability

B.

Ensure alignment with industry standards

C.

Provide measurable risk reduction

D.

Enforce strong security solutions

Full Access
Question # 249

Which of the following is MOST important for a risk practitioner to review during an IT risk assessment?

A.

Published records of loss from peer organizations

B.

The organization ' s historical threats and monetary loss

C.

Information system assets and associated threats

D.

Information system control weaknesses and audit findings

Full Access
Question # 250

Which of the following is the MOST important factor when deciding on a control to mitigate risk exposure?

A.

Relevance to the business process

B.

Regulatory compliance requirements

C.

Cost-benefit analysis

D.

Comparison against best practice

Full Access
Question # 251

Which of the following roles would be MOST helpful in providing a high-level view of risk related to customer data loss?

A.

Customer database manager

B.

Customer data custodian

C.

Data privacy officer

D.

Audit committee

Full Access
Question # 252

The PRIMARY benefit associated with key risk indicators (KRls) is that they:

A.

help an organization identify emerging threats.

B.

benchmark the organization ' s risk profile.

C.

identify trends in the organization ' s vulnerabilities.

D.

enable ongoing monitoring of emerging risk.

Full Access
Question # 253

An IT risk practitioner has been asked to regularly report on the overall status and effectiveness of the IT risk management program. Which of the following is MOST useful for this purpose?

A.

Balanced scorecard

B.

Capability maturity level

C.

Internal audit plan

D.

Control self-assessment (CSA)

Full Access
Question # 254

Which of the following is the BEST evidence that risk management is driving business decisions in an organization?

A.

Compliance breaches are addressed in a timely manner.

B.

Risk ownership is identified and assigned.

C.

Risk treatment options receive adequate funding.

D.

Residual risk is within risk tolerance.

Full Access
Question # 255

Which of the following is the MOST important reason to validate that risk responses have been executed as outlined in the risk response plan ' '

A.

To ensure completion of the risk assessment cycle

B.

To ensure controls arc operating effectively

C.

To ensure residual risk Is at an acceptable level

D.

To ensure control costs do not exceed benefits

Full Access
Question # 256

The design of procedures to prevent fraudulent transactions within an enterprise resource planning (ERP) system should be based on:

A.

stakeholder risk tolerance.

B.

benchmarking criteria.

C.

suppliers used by the organization.

D.

the control environment.

Full Access
Question # 257

Which of the following is the MOST important course of action to foster an ethical, risk-aware culture?

A.

Implement a fraud detection and prevention framework.

B.

Ensure the alignment of the organization ' s policies and standards to the defined risk appetite.

C.

Establish an enterprise-wide ethics training and awareness program.

D.

Perform a comprehensive review of all applicable legislative frameworks and requirements.

Full Access
Question # 258

Which of the following is MOST helpful in verifying that the implementation of a risk mitigation control has been completed as intended?

A.

An updated risk register

B.

Risk assessment results

C.

Technical control validation

D.

Control testing results

Full Access
Question # 259

Which of the following is the BEST method to mitigate the risk of an unauthorized employee viewing confidential data in a database ' '

A.

Implement role-based access control

B.

Implement a data masking process

C.

Include sanctions in nondisclosure agreements (NDAs)

D.

Install a data loss prevention (DLP) tool

Full Access
Question # 260

Which of the following is the BEST recommendation when a key risk indicator (KRI) is generating an excessive volume of events?

A.

Reevaluate the design of the KRIs.

B.

Develop a corresponding key performance indicator (KPI).

C.

Monitor KRIs within a specific timeframe.

D.

Activate the incident response plan.

Full Access
Question # 261

Several network user accounts were recently created without the required management approvals. Which of the following would be the risk practitioner ' s BEST recommendation to address this situation?

A.

Conduct a comprehensive compliance review.

B.

Develop incident response procedures for noncompliance.

C.

Investigate the root cause of noncompliance.

D.

Declare a security breach and Inform management.

Full Access
Question # 262

It is MOST important to the effectiveness of an IT risk management function that the associated processes are:

A.

aligned to an industry-accepted framework.

B.

reviewed and approved by senior management.

C.

periodically assessed against regulatory requirements.

D.

updated and monitored on a continuous basis.

Full Access
Question # 263

Which of the following is MOST important to ensure when reviewing an organization ' s risk register?

A.

Risk ownership is recorded.

B.

Vulnerabilities have separate entries.

C.

Control ownership is recorded.

D.

Residual risk is less than inherent risk.

Full Access
Question # 264

Which of the following is the MAIN benefit of involving stakeholders in the selection of key risk indicators (KRIs)?

A.

Improving risk awareness

B.

Obtaining buy-in from risk owners

C.

Leveraging existing metrics

D.

Optimizing risk treatment decisions

Full Access
Question # 265

Which of the following is the BEST approach for a risk practitioner to use for identifying the level of technical debt in an organization?

A.

Review business cases for large organizational projects.

B.

Measure the alignment of technical standards with information security policies.

C.

Analyze trends in technology investments over time.

D.

Compare the current state to the target enterprise architecture (EA).

Full Access
Question # 266

An organization is developing a risk universe to create a holistic view of its overall risk profile. Which of the following is the GREATEST barrier to achieving the initiative ' s objectives?

A.

Lack of cross-functional risk assessment workshops within the organization

B.

Lack of common understanding of the organization ' s risk culture

C.

Lack of quantitative methods to aggregate the total risk exposure

D.

Lack of an integrated risk management system to aggregate risk scenarios

Full Access
Question # 267

While reviewing the risk register, a risk practitioner notices that different business units have significant variances in inherent risk for the same risk scenario. Which of the following is the BEST course of action?

A.

Update the risk register with the average of residual risk for both business units.

B.

Review the assumptions of both risk scenarios to determine whether the variance is reasonable.

C.

Update the risk register to ensure both risk scenarios have the highest residual risk.

D.

Request that both business units conduct another review of the risk.

Full Access
Question # 268

Which of the following is the PRIMARY objective for automating controls?

A.

Reducing the need for audit reviews

B.

Facilitating continuous control monitoring

C.

Improving control process efficiency

D.

Complying with functional requirements

Full Access
Question # 269

Which of the following should be determined FIRST when a new security vulnerability is made public?

A.

How severe the vulnerability is across the industry

B.

Whether the affected technology is internet-facing

C.

Whether the affected technology is used within the organization

D.

What mitigating controls are currently in place

Full Access
Question # 270

The MAIN purpose of a risk register is to:

A.

document the risk universe of the organization.

B.

promote an understanding of risk across the organization.

C.

enable well-informed risk management decisions.

D.

identify stakeholders associated with risk scenarios.

Full Access
Question # 271

While reviewing an organization ' s monthly change management metrics, a risk practitioner notes that the number of emergency changes has increased substantially Which of the following would be the BEST approach for the risk practitioner to take?

A.

Temporarily suspend emergency changes.

B.

Document the control deficiency in the risk register.

C.

Conduct a root cause analysis.

D.

Continue monitoring change management metrics.

Full Access
Question # 272

Which of the following shortcomings of perimeter security does Zero Trust aim to resolve?

A.

Lack of access verification for systems on the internal network

B.

Identification and authentication failures for users

C.

Poorly configured firewall rules introducing security breaches

D.

Ineffective load balancing on network devices

Full Access
Question # 273

Which of the following provides the BEST evidence that robust risk management practices are in place within an organization?

A.

A management-approved risk dashboard

B.

A current control framework

C.

A regularly updated risk register

D.

Regularly updated risk management procedures

Full Access
Question # 274

Which of the following is the MOST important step to ensure regulatory requirements are adequately addressed within an organization?

A.

Obtain necessary resources to address regulatory requirements

B.

Develop a policy framework that addresses regulatory requirements

C.

Perform a gap analysis against regulatory requirements.

D.

Employ IT solutions that meet regulatory requirements.

Full Access
Question # 275

Which of the following is the FIRST step in managing the security risk associated with wearable technology in the workplace?

A.

Identify the potential risk.

B.

Monitor employee usage.

C.

Assess the potential risk.

D.

Develop risk awareness training.

Full Access
Question # 276

A risk practitioner is reporting on an increasing trend of ransomware attacks in the industry. Which of the following information is MOST important to include to enable an informed response decision by key stakeholders?

A.

Methods of attack progression

B.

Losses incurred by industry peers

C.

Most recent antivirus scan reports

D.

Potential impact of events

Full Access
Question # 277

A risk practitioner has been asked to propose a risk acceptance framework for an organization. Which of the following is the MOST important consideration for the risk practitioner to address in the framework?

A.

Consistent forms to document risk acceptance rationales

B.

Acceptable scenarios to override risk appetite or tolerance thresholds

C.

Individuals or roles authorized to approve risk acceptance

D.

Communication protocols when a risk is accepted

Full Access
Question # 278

Which of the following BEST enables a proactive approach to minimizing the potential impact of unauthorized data disclosure?

A.

Cyber insurance

B.

Data backups

C.

Incident response plan

D.

Key risk indicators (KRIs)

Full Access
Question # 279

Which of the following would have the GREATEST impact on reducing the risk associated with the implementation of a big data project?

A.

Data processing

B.

Data quality

C.

Data scalability

D.

Data governance

Full Access
Question # 280

Who is the BEST person to an application system used to process employee personal data?

A.

Compliance manager

B.

Data privacy manager

C.

System administrator

D.

Human resources (HR) manager

Full Access
Question # 281

Which of the following is the MOST reliable validation of a new control?

A.

Approval of the control by senior management

B.

Complete and accurate documentation of control objectives

C.

Control owner attestation of control effectiveness

D.

Internal audit review of control design

Full Access
Question # 282

In an organization dependent on data analytics to drive decision-making, which of the following would BEST help to minimize the risk associated with inaccurate data?

A.

Establishing an intellectual property agreement

B.

Evaluating each of the data sources for vulnerabilities

C.

Periodically reviewing big data strategies

D.

Benchmarking to industry best practice

Full Access
Question # 283

Which of the following is the PRIMARY objective of risk management?

A.

Identify and analyze risk.

B.

Achieve business objectives

C.

Minimi2e business disruptions.

D.

Identify threats and vulnerabilities.

Full Access
Question # 284

A risk practitioner is reviewing a vendor contract and finds there is no clause to control privileged access to the organization ' s systems by vendor employees. Which of the following is the risk practitioner ' s BEST course of action?

A.

Contact the control owner to determine if a gap in controls exists.

B.

Add this concern to the risk register and highlight it for management review.

C.

Report this concern to the contracts department for further action.

D.

Document this concern as a threat and conduct an impact analysis.

Full Access
Question # 285

Which of the following risk management practices BEST facilitates the incorporation of IT risk scenarios into the enterprise-wide risk register?

A.

Key risk indicators (KRls) are developed for key IT risk scenarios

B.

IT risk scenarios are assessed by the enterprise risk management team

C.

Risk appetites for IT risk scenarios are approved by key business stakeholders.

D.

IT risk scenarios are developed in the context of organizational objectives.

Full Access
Question # 286

From a business perspective, which of the following is the MOST important objective of a disaster recovery test?

A.

The organization gains assurance it can recover from a disaster

B.

Errors are discovered in the disaster recovery process.

C.

All business-critical systems are successfully tested.

D.

All critical data is recovered within recovery time objectives (RTOs).

Full Access
Question # 287

Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?

A.

Cause-and-effect diagram

B.

Delphi technique

C.

Bottom-up approach

D.

Top-down approach

Full Access
Question # 288

As part of its risk strategy, an organization decided to transition its financial system from a cloud-based provider to an internally managed system. Which of the following should the risk practitioner do FIRST?

A.

Reassess whether the risk responses properly address known risks and vulnerabilities

B.

Analyze the risk register to identify potential updates and changes

C.

Evaluate existing control test plans of the system for potential changes

D.

Update the processes within impacted financial control assessments

Full Access
Question # 289

Which of the following should be the PRIMARY focus of an IT risk awareness program?

A.

Ensure compliance with the organization ' s internal policies

B.

Cultivate long-term behavioral change.

C.

Communicate IT risk policy to the participants.

D.

Demonstrate regulatory compliance.

Full Access
Question # 290

Which of the following should be the FIRST course of action if the risk associated with a new technology is found to be increasing?

A.

Re-evaluate current controls.

B.

Revise the current risk action plan.

C.

Escalate the risk to senior management.

D.

Implement additional controls.

Full Access
Question # 291

When updating the risk register after a risk assessment, which of the following is MOST important to include?

A.

Historical losses due to past risk events

B.

Cost to reduce the impact and likelihood

C.

Likelihood and impact of the risk scenario

D.

Actor and threat type of the risk scenario

Full Access
Question # 292

Which of the following is the BEST way to determine whether system settings are in alignment with control baselines?

A.

Configuration validation

B.

Control attestation

C.

Penetration testing

D.

Internal audit review

Full Access
Question # 293

Which of the following is MOST important for a risk practitioner to confirm when reviewing an organization’s information security policies?

A.

Aligned with information security procedures.

B.

Written at a high level to communicate the organization’s intentions.

C.

Frequently updated to address minor technology changes.

D.

Drafted at a technical level to focus on common security industry practices.

Full Access
Question # 294

Which of the following techniques is MOST helpful when quantifying the potential loss impact of cyber risk?

A.

Cost-benefit analysis

B.

Penetration testing

C.

Business impact analysis (BIA)

D.

Security assessment

Full Access
Question # 295

Which of the following will MOST likely change as a result of the decrease in risk appetite due to a new privacy regulation?

A.

Key risk indicator (KRI) thresholds

B.

Risk trends

C.

Key performance indicators (KPIs)

D.

Risk objectives

Full Access
Question # 296

Which of the following is the MOST important objective of regularly presenting the project risk register to the project steering committee?

A.

To allocate budget for resolution of risk issues

B.

To determine if new risk scenarios have been identified

C.

To ensure the project timeline is on target

D.

To track the status of risk mitigation actions

Full Access
Question # 297

An updated report from a trusted research organization shows that attacks have increased in the organization ' s industry segment. What should be done FIRST to integrate this data into risk assessments?

A.

Average the ransomware attack frequencies together

B.

Revise the threat frequency for ransomware attack types

C.

Adjust impact amounts based on the average ransom

D.

Use the new frequency as the maximum value in a Monte Carlo simulation

Full Access
Question # 298

The annualized loss expectancy (ALE) method of risk analysis:

A.

helps in calculating the expected cost of controls

B.

uses qualitative risk rankings such as low. medium and high.

C.

can be used m a cost-benefit analysts

D.

can be used to determine the indirect business impact.

Full Access
Question # 299

Which of the following risk register updates is MOST important for senior management to review?

A.

Extending the date of a future action plan by two months

B.

Retiring a risk scenario no longer used

C.

Avoiding a risk that was previously accepted

D.

Changing a risk owner

Full Access
Question # 300

Which of the following is MOST important for management to consider when deciding whether to invest in an IT initiative that exceeds management ' s risk appetite?

A.

Risk management budget

B.

Risk management industry trends

C.

Risk tolerance

D.

Risk capacity

Full Access
Question # 301

Which of the following is the MOST effective control to maintain the integrity of system configuration files?

A.

Recording changes to configuration files

B.

Implementing automated vulnerability scanning

C.

Restricting access to configuration documentation

D.

Monitoring against the configuration standard

Full Access
Question # 302

An IT department has organized training sessions to improve user awareness of organizational information security policies. Which of the following is the BEST key performance indicator (KPI) to reflect effectiveness of the training?

A.

Number of training sessions completed

B.

Percentage of staff members who complete the training with a passing score

C.

Percentage of attendees versus total staff

D.

Percentage of staff members who attend the training with positive feedback

Full Access
Question # 303

Which of the following is the MOST important requirement when implementing a data loss prevention (DLP) system?

A.

Identifying users who have access

B.

Selecting an encryption solution

C.

Defining the data retention period

D.

Determining the value of data

Full Access
Question # 304

Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application?

A.

The third-party risk manager

B.

The application vendor

C.

The business process owner

D.

The information security manager

Full Access
Question # 305

An organization has initiated a project to launch an IT-based service to customers and take advantage of being the first to market. Which of the following should be of GREATEST concern to senior management?

A.

More time has been allotted for testing.

B.

The project is likely to deliver the product late.

C.

A new project manager is handling the project.

D.

The cost of the project will exceed the allotted budget.

Full Access
Question # 306

Who is BEST suited to provide objective input when updating residual risk to reflect the results of control effectiveness?

A.

Control owner

B.

Risk owner

C.

Internal auditor

D.

Compliance manager

Full Access
Question # 307

A process maturity model is MOST useful to the risk management process because it helps:

A.

determine the cost of control improvements

B.

determine the gap between actual and desired state.

C.

benchmark maturity against industry standards

D.

reduce audit and regulatory findings

Full Access
Question # 308

Which of the following is a risk practitioner ' s MOST important course of action after learning that an organization ' s industry peers have experienced an increase in ransomware attacks?

A.

Recommend additional preventive controls to reduce residual risk.

B.

Document this scenario as a risk event for further risk analysis.

C.

Propose risk acceptance until the organization is directly affected.

D.

Raise a security incident to proactively prevent similar attacks.

Full Access
Question # 309

Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?

A.

Apply data classification policy

B.

Utilize encryption with logical access controls

C.

Require logical separation of company data

D.

Obtain the right to audit

Full Access
Question # 310

A vendor’s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?

A.

Business application owner

B.

Business continuity manager

C.

Chief risk officer (CRO)

D.

IT infrastructure manager

Full Access
Question # 311

Which of the following statements in an organization ' s current risk profile report is cause for further action by senior management?

A.

Key performance indicator (KPI) trend data is incomplete.

B.

New key risk indicators (KRIs) have been established.

C.

Key performance indicators (KPIs) are outside of targets.

D.

Key risk indicators (KRIs) are lagging.

Full Access
Question # 312

An IT department has provided a shared drive for personnel to store information to which all employees have access. Which of the following parties is accountable for the risk of potential loss of confidential information?

A.

Risk manager

B.

Data owner

C.

End user

D.

IT department

Full Access
Question # 313

A business unit is unable to fully implement the security policy on a critical business application. Which type of process should be in place to BEST manage the related risk?

A.

Change management

B.

Exception management

C.

Configuration management

D.

Incident management

Full Access
Question # 314

Which of the following BEST mitigates ethical risk?

A.

Ethics committees

B.

Contingency scenarios

C.

Awareness of consequences for violations

D.

Routine changes in senior management

Full Access
Question # 315

Which of the following, who should be PRIMARILY responsible for performing user entitlement reviews?

A.

IT security manager

B.

IT personnel

C.

Data custodian

D.

Data owner

Full Access
Question # 316

An IT operations team implements disaster recovery controls based on decisions from application owners regarding the level of resiliency needed. Who is the risk owner in this scenario?

A.

Business resilience manager

B.

Disaster recovery team lead

C.

Application owner

D.

IT operations manager

Full Access
Question # 317

The BEST metric to demonstrate that servers are configured securely is the total number of servers:

A.

exceeding availability thresholds

B.

experiencing hardware failures

C.

exceeding current patching standards.

D.

meeting the baseline for hardening.

Full Access
Question # 318

An organization has outsourced its IT security operations to a third party. Who is ULTIMATELY accountable for the risk associated with the outsourced operations?

A.

The third party s management

B.

The organization ' s management

C.

The control operators at the third party

D.

The organization ' s vendor management office

Full Access
Question # 319

Who is the BEST person to the employee personal data?

A.

Human resources (HR) manager

B.

System administrator

C.

Data privacy manager

D.

Compliance manager

Full Access
Question # 320

An organization recently implemented new technologies that enable the use of robotic process automation. Which of the following is MOST important to reassess?

A.

Risk profile

B.

Risk tolerance

C.

Risk capacity

D.

Risk appetite

Full Access
Question # 321

During which phase of the system development life cycle (SDLC) should information security requirements for the implementation of a new IT system be defined?

A.

Monitoring

B.

Development

C.

Implementation

D.

Initiation

Full Access
Question # 322

A department allows multiple users to perform maintenance on a system using a single set of credentials. A risk practitioner determined this practice to be high-risk. Which of the following is the MOST effective way to mitigate this risk?

A.

Single sign-on

B.

Audit trail review

C.

Multi-factor authentication

D.

Data encryption at rest

Full Access
Question # 323

An organization has four different projects competing for funding to reduce overall IT risk. Which project should management defer?

A.

Project Charlie

B.

Project Bravo

C.

Project Alpha

D.

Project Delta

Full Access
Question # 324

Which of the following is the GREATEST benefit of using IT risk scenarios?

A.

They support compliance with regulations.

B.

They provide evidence of risk assessment.

C.

They facilitate communication of risk.

D.

They enable the use of key risk indicators (KRls)

Full Access
Question # 325

Which of the following would be MOST helpful to an information security management team when allocating resources to mitigate exposures?

A.

Relevant risk case studies

B.

Internal audit findings

C.

Risk assessment results

D.

Penetration testing results

Full Access
Question # 326

Technical controls affecting access permissions for systems should be implemented according to:

A.

Integration testing requirements.

B.

Separation of duties.

C.

Configuration baselines.

D.

Contingency scenarios.

Full Access
Question # 327

Which of the following is the BEST way to identify changes to the risk landscape?

A.

Internal audit reports

B.

Access reviews

C.

Threat modeling

D.

Root cause analysis

Full Access
Question # 328

Concerned about system load capabilities during the month-end close process, management requires monitoring of the average time to complete tasks and monthly reporting of the findings. What type of measure has been established?

A.

Service level agreement (SLA)

B.

Critical success factor (CSF)

C.

Key risk indicator (KRI)

D.

Key performance indicator (KPI)

Full Access
Question # 329

The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:

A.

obtain the support of executive management.

B.

map the business processes to supporting IT and other corporate resources.

C.

identify critical business processes and the degree of reliance on support services.

D.

document the disaster recovery process.

Full Access
Question # 330

From a data protection and regulatory compliance perspective, which of the following is the MOST important reason for a global organization to use immutable backups?

A.

Immutable backups can be used for data recovery testing.

B.

Data contains time stamps that indicate when it was backed up.

C.

Immutable backups enable effective disaster recovery response.

D.

Data cannot be tampered with through the use of encryption capabilities

Full Access
Question # 331

A management team is on an aggressive mission to launch a new product to penetrate new markets and overlooks IT risk factors, threats, and vulnerabilities. This scenario BEST demonstrates an organization ' s risk:

A.

management.

B.

tolerance.

C.

culture.

D.

analysis.

Full Access
Question # 332

Which of the following is the BEST method for identifying vulnerabilities?

A.

Batch job failure monitoring

B.

Periodic network scanning

C.

Annual penetration testing

D.

Risk assessments

Full Access
Question # 333

Which of the following risk impacts should be the PRIMARY consideration for determining recovery priorities in a disaster recovery situation?

A.

Data security

B.

Recovery costs

C.

Business disruption

D.

Recovery resource availability

Full Access
Question # 334

Which of the following BEST indicates that an organization has implemented IT performance requirements?

A.

Service level agreements(SLA)

B.

Vendor references

C.

Benchmarking data

D.

Accountability matrix

Full Access
Question # 335

Which of the following is MOST helpful to understand the consequences of an IT risk event?

A.

Fault tree analysis

B.

Historical trend analysis

C.

Root cause analysis

D.

Business impact analysis (BIA)

Full Access
Question # 336

An organization ' s senior management is considering whether to acquire cyber insurance. Which of the following is the BEST way for the risk practitioner to enable management’s decision?

A.

Perform a cost-benefit analysis.

B.

Conduct a SWOT analysis.

C.

Provide data on the number of risk events from the last year.

D.

Report on recent losses experienced by industry peers.

Full Access
Question # 337

The risk associated with inadvertent disclosure of database records from a public cloud service provider (CSP) would MOST effectively be reduced by:

A.

encrypting the data

B.

including a nondisclosure clause in the CSP contract

C.

assessing the data classification scheme

D.

reviewing CSP access privileges

Full Access
Question # 338

An IT manager insists on accepting an IT risk associated with a key business process due to the limited resources available to mitigate. Which of the following is the risk practitioner ' s MOST important action?

A.

Seek additional resources for risk mitigation.

B.

Document the business rationale for risk acceptance.

C.

Validate the decision with the process owner

D.

Conduct a follow-up business process analysis.

Full Access
Question # 339

Which of the following is the PRIMARY benefit of stakeholder involvement in risk scenario development?

A.

Ability to determine business impact

B.

Up-to-date knowledge on risk responses

C.

Decision-making authority for risk treatment

D.

Awareness of emerging business threats

Full Access
Question # 340
A.

Some risk remediation activities from the last assessment are still in progress.

B.

The risk scenarios have never been updated.

C.

The risk scenario development process was led by an external consultant.

D.

The number of risk scenarios is very high.

Full Access
Question # 341

Which of the following is PRIMARILY responsible for providing assurance to the board of directors and senior management during the evaluation of a risk management program implementation?

A.

Risk management

B.

Business units

C.

External audit

D.

Internal audit

Full Access
Question # 342

Which of the following is the BEST way for a risk practitioner to help management prioritize risk response?

A.

Align business objectives to the risk profile.

B.

Assess risk against business objectives

C.

Implement an organization-specific risk taxonomy.

D.

Explain risk details to management.

Full Access
Question # 343

Which of the following BEST enables risk-based decision making in support of a business continuity plan (BCP)?

A.

Impact analysis

B.

Control analysis

C.

Root cause analysis

D.

Threat analysis

Full Access
Question # 344

An organization has been made aware of a newly discovered critical vulnerability in a regulatory reporting system. Which of the following is the risk practitioner ' s BEST course of action?

A.

Perform an impact assessment.

B.

Perform a penetration test.

C.

Request an external audit.

D.

Escalate the risk to senior management.

Full Access
Question # 345

Which of the following is the PRIMARY reason to perform ongoing risk assessments?

A.

Emerging risk must be continuously reported to management.

B.

New system vulnerabilities emerge at frequent intervals.

C.

The risk environment is subject to change.

D.

The information security budget must be justified.

Full Access
Question # 346

Which of the following would provide the MOST reliable evidence of the effectiveness of security controls implemented for a web application?

A.

Penetration testing

B.

IT general controls audit

C.

Vulnerability assessment

D.

Fault tree analysis

Full Access
Question # 347

An organization is conducting a review of emerging risk. Which of the following is the BEST input for this exercise?

A.

Audit reports

B.

Industry benchmarks

C.

Financial forecasts

D.

Annual threat reports

Full Access
Question # 348

How does an organization benefit by purchasing cyber theft insurance?

A.

It decreases the amount of organizational loss if risk events occur.

B.

It justifies the acceptance of risk associated with cyber theft events.

C.

It transfers risk ownership along with associated liabilities to a third party.

D.

It decreases the likelihood of risk events occurring.

Full Access
Question # 349

How should an organization approach the retention of data that is no longer needed for business operations?

A.

Data should be retained for a reasonable period of time in case of system rollback.

B.

Data should be destroyed or retained on the basis of a cost-benefit analysis.

C.

Data should be retained based on regulatory requirements.

D.

Data should be destroyed to avoid any risk exposure.

Full Access
Question # 350

A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization ' s data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?

A.

Request a policy exception from senior management.

B.

Comply with the organizational policy.

C.

Report the noncompliance to the local regulatory agency.

D.

Request an exception from the local regulatory agency.

Full Access
Question # 351

Which of the following BEST facilitates the mitigation of identified gaps between current and desired risk environment states?

A.

Develop a risk treatment plan.

B.

Validate organizational risk appetite.

C.

Review results of prior risk assessments.

D.

Include the current and desired states in the risk register.

Full Access
Question # 352

When of the following provides the MOST tenable evidence that a business process control is effective?

A.

Demonstration that the control is operating as designed

B.

A successful walk-through of the associated risk assessment

C.

Management attestation that the control is operating effectively

D.

Automated data indicating that risk has been reduced

Full Access
Question # 353

A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?

A.

Request a regulatory risk reporting methodology

B.

Require critical success factors (CSFs) for IT risks.

C.

Establish IT-specific compliance objectives

D.

Communicate IT key risk indicators (KRIs) and triggers

Full Access
Question # 354

Which of the following is MOST important for a risk practitioner to consider when evaluating plans for changes to IT services?

A.

Change testing schedule

B.

Impact assessment of the change

C.

Change communication plan

D.

User acceptance testing (UAT)

Full Access
Question # 355

Which of the following is the PRIMARY purpose of conducting risk and control self-assessments?

A.

To better understand inherent and residual risk within the organization

B.

To gain objective insight into the effectiveness and efficiency of controls

C.

To demonstrate compliance with regulatory and legal control requirements

D.

To facilitate timely and accurate updates to the risk register

Full Access
Question # 356

Which of the following is the BEST way to help ensure risk will be managed properly after a business process has been re-engineered?

A.

Reassessing control effectiveness of the process

B.

Conducting a post-implementation review to determine lessons learned

C.

Reporting key performance indicators (KPIs) for core processes

D.

Establishing escalation procedures for anomaly events

Full Access
Question # 357

Which of the following is the ULTIMATE objective of utilizing key control indicators (KCIs) in the risk management process?

A.

To provide insight into the effectiveness of the internal control environment

B.

To provide a basis for determining the criticality of risk mitigation controls

C.

To provide benchmarks for assessing control design effectiveness against industry peers

D.

To provide early warning signs of a potential change in risk level

Full Access
Question # 358

A key risk indicator (KRI) is reported to senior management on a periodic basis as exceeding thresholds, but each time senior management has decided to take no action to reduce the risk. Which of the following is the MOST likely reason for senior management ' s response?

A.

The underlying data source for the KRI is using inaccurate data and needs to be corrected.

B.

The KRI is not providing useful information and should be removed from the KRI inventory.

C.

The KRI threshold needs to be revised to better align with the organization s risk appetite

D.

Senior management does not understand the KRI and should undergo risk training.

Full Access
Question # 359

The risk associated with an asset before controls are applied can be expressed as:

A.

a function of the likelihood and impact

B.

the magnitude of an impact

C.

a function of the cost and effectiveness of control.

D.

the likelihood of a given threat

Full Access
Question # 360

Which of the following BEST indicates effective information security incident management?

A.

Monthly trend of information security-related incidents

B.

Average time to identify critical information security incidents

C.

Frequency of information security incident response plan testing

D.

Percentage of high-risk security incidents

Full Access
Question # 361

Which of the following is MOST helpful to review when assessing the risk exposure associated with ransomware?

A.

Potentially impacted business processes

B.

Recent changes in the environment

C.

Key performance indicators (KPIs)

D.

Suspected phishing events

Full Access
Question # 362

Which of the following provides the BEST evidence that a selected risk treatment plan is effective?

A.

Identifying key risk indicators (KRIs)

B.

Evaluating the return on investment (ROI)

C.

Evaluating the residual risk level

D.

Performing a cost-benefit analysis

Full Access
Question # 363

The BEST criteria when selecting a risk response is the:

A.

capability to implement the response

B.

importance of IT risk within the enterprise

C.

effectiveness of risk response options

D.

alignment of response to industry standards

Full Access
Question # 364

Which of the following is a responsibility of the second line of defense in the three lines of defense model?

A.

Performing duties independently to provide assurance

B.

Alerting operational management to emerging issues

C.

Implementing corrective actions to address deficiencies

D.

Owning risk scenarios and bearing the consequences of loss

Full Access
Question # 365

When prioritizing risk response, management should FIRST:

A.

evaluate the organization s ability and expertise to implement the solution.

B.

evaluate the risk response of similar organizations.

C.

address high risk factors that have efficient and effective solutions.

D.

determine which risk factors have high remediation costs

Full Access
Question # 366

Which of the following is the PRIMARY consideration when determining the impact to an organization after the discovery of malware on an endpoint device?

A.

Asset criticality and sensitivity

B.

Currency of anti-malware signatures

C.

Availability of patches and security updates

D.

Currency of the incident response plan

Full Access
Question # 367

Which of the following is the BEST way to determine the ongoing efficiency of control processes?

A.

Perform annual risk assessments.

B.

Interview process owners.

C.

Review the risk register.

D.

Analyze key performance indicators (KPIs).

Full Access
Question # 368

Which of the following activities should only be performed by the third line of defense?

A.

Operating controls for risk mitigation

B.

Testing the effectiveness and efficiency of internal controls

C.

Providing assurance on risk management processes

D.

Recommending risk treatment options

Full Access
Question # 369

An organization has outsourced its backup and recovery procedures to a third-party cloud provider. Which of the following is the risk practitioner s BEST course of action?

A.

Accept the risk and document contingency plans for data disruption.

B.

Remove the associated risk scenario from the risk register due to avoidance.

C.

Mitigate the risk with compensating controls enforced by the third-party cloud provider.

D.

Validate the transfer of risk and update the register to reflect the change.

Full Access
Question # 370

An organization is unable to implement a multi-factor authentication requirement until the next fiscal year due to budget constraints. Consequently, a policy exception must be submitted. Which of the following is MOST important to include in the analysis of the exception?

A.

Sections of the policy that may justify not implementing the requirement

B.

Risk associated with the inability to implement the requirement

C.

Budget justification to implement the new requirement during the current year

D.

Industry best practices with respect to implementation of the proposed control

Full Access
Question # 371

Which of the following is MOST helpful when prioritizing action plans for identified risk?

A.

Comparing risk rating against appetite

B.

Obtaining input from business units

C.

Determining cost of controls to mitigate risk

D.

Ranking the risk based on likelihood of occurrence

Full Access
Question # 372

Which of the following would MOST effectively reduce risk associated with an increase of online transactions on a retailer website?

A.

Scalable infrastructure

B.

A hot backup site

C.

Transaction limits

D.

Website activity monitoring

Full Access
Question # 373

Which of the following will help ensure the elective decision-making of an IT risk management committee?

A.

Key stakeholders are enrolled as members

B.

Approved minutes ate forwarded to senior management

C.

Committee meets at least quarterly

D.

Functional overlap across the business is minimized

Full Access
Question # 374

Senior management has asked the risk practitioner for the overall residual risk level for a process that contains numerous risk scenarios. Which of the following should be provided?

A.

The sum of residual risk levels for each scenario

B.

The loss expectancy for aggregated risk scenarios

C.

The highest loss expectancy among the risk scenarios

D.

The average of anticipated residual risk levels

Full Access
Question # 375

Which of the following provides the MOST useful information for developing key risk indicators (KRIs)?

A.

Business impact analysis (BIA) results

B.

Risk scenario ownership

C.

Risk thresholds

D.

Possible causes of materialized risk

Full Access
Question # 376

Which of the following is the BEST way to mitigate the risk to IT infrastructure availability?

A.

Establishing a disaster recovery plan (DRP)

B.

Establishing recovery time objectives (RTOs)

C.

Maintaining a current list of staff contact delays

D.

Maintaining a risk register

Full Access
Question # 377

Which of the following is the BEST measure of the effectiveness of an employee deprovisioning process?

A.

Number of days taken to remove access after staff separation dates

B.

Number of days taken for IT to remove access after receipt of HR instructions

C.

Number of termination requests processed per reporting period

D.

Number of days taken for HR to provide instructions to IT after staff separation dates

Full Access
Question # 378

An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on the devices?

A.

Periodically review application on BYOD devices

B.

Include BYOD in organizational awareness programs

C.

Implement BYOD mobile device management (MDM) controls.

D.

Enable a remote wee capability for BYOD devices

Full Access
Question # 379

Which of the following is the PRIMARY reason for an organization to ensure the risk register is updated regularly?

A.

Risk assessment results are accessible to senior management and stakeholders.

B.

Risk mitigation activities are managed and coordinated.

C.

Key risk indicators (KRIs) are evaluated to validate they are still within the risk threshold.

D.

Risk information is available to enable risk-based decisions.

Full Access
Question # 380

What would be MOST helpful to ensuring the effective implementation of a new cybersecurity program?

A.

Creating metrics to report the number of security incidents

B.

Hiring subject matter experts for the program

C.

Establishing a budget for additional resources

D.

Assigning clear ownership of the program

Full Access
Question # 381

An organization ' s risk register contains a large volume of risk scenarios that senior management considers overwhelming. Which of the following would BEST help to improve the risk register?

A.

Analyzing the residual risk components

B.

Performing risk prioritization

C.

Validating the risk appetite level

D.

Conducting a risk assessment

Full Access
Question # 382

Which of the following is the BEST indication that key risk indicators (KRls) should be revised?

A.

A decrease in the number of critical assets covered by risk thresholds

B.

An Increase In the number of risk threshold exceptions

C.

An increase in the number of change events pending management review

D.

A decrease In the number of key performance indicators (KPls)

Full Access
Question # 383

When reviewing a risk response strategy, senior management ' s PRIMARY focus should be placed on the:

A.

cost-benefit analysis.

B.

investment portfolio.

C.

key performance indicators (KPIs).

D.

alignment with risk appetite.

Full Access
Question # 384

Which of the following should a risk practitioner recommend FIRST when an increasing trend of risk events and subsequent losses has been identified?

A.

Conduct root cause analyses for risk events.

B.

Educate personnel on risk mitigation strategies.

C.

Integrate the risk event and incident management processes.

D.

Implement controls to prevent future risk events.

Full Access
Question # 385

Which of the following approaches MOST effectively enables accountability for data protection?

A.

Establishing ownership for data within applications and systems

B.

Establishing discipline for policy violations by data owners

C.

Implementing data protection policies across the organization

D.

Conducting data protection awareness and training campaigns

Full Access
Question # 386

During an acquisition, which of the following would provide the MOST useful input to the parent company ' s risk practitioner when developing risk scenarios for the post-acquisition phase?

A.

Risk management framework adopted by each company

B.

Risk registers of both companies

C.

IT balanced scorecard of each company

D.

Most recent internal audit findings from both companies

Full Access
Question # 387

Which of the following would be MOST helpful in assessing the risk associated with data loss due to human vulnerabilities?

A.

Reviewing password change history

B.

Performing periodic access recertification

C.

Conducting social engineering exercises

D.

Reviewing the results of security awareness surveys

Full Access
Question # 388

Which of the following BEST helps to ensure disaster recovery staff members

are able to complete their assigned tasks effectively during a disaster?

A.

Performing parallel disaster recovery testing

B.

Documenting the order of system and application restoration

C.

Involving disaster recovery staff members in risk assessments

D.

Conducting regular tabletop exercises and scenario analysis

Full Access
Question # 389

To minimize the risk of a potential acquisition being exposed externally, an organization has selected a few key employees to be engaged in the due diligence process. A member of the due diligence team realizes a close acquaintance is a high-ranking IT professional at a subsidiary of the company about to be acquired. What is the BEST course of action for this team member?

A.

Enforce segregation of duties.

B.

Disclose potential conflicts of interest.

C.

Delegate responsibilities involving the acquaintance.

D.

Notify the subsidiary ' s legal team.

Full Access
Question # 390

Read " rights to application files in a controlled server environment should be approved by the:

A.

business process owner.

B.

database administrator.

C.

chief information officer.

D.

systems administrator.

Full Access
Question # 391

Which of the following provides the BEST assurance of…..

A.

Penetration testing

B.

Service-level monitoring

C.

Service provider ' s control self-assessment (CSA)

D.

Independent assessment report

Full Access
Question # 392

A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:

A.

based on industry trends.

B.

mapped to incident response plans.

C.

related to probable events.

D.

aligned with risk management capabilities.

Full Access
Question # 393

Which of the following will provide the BEST measure of compliance with IT policies?

A.

Evaluate past policy review reports.

B.

Conduct regular independent reviews.

C.

Perform penetration testing.

D.

Test staff on their compliance responsibilities.

Full Access
Question # 394

When performing a risk assessment of a new service to support a core business process, which of the following should be done FIRST to ensure continuity of operations?

A.

Define metrics for restoring availability.

B.

Identify conditions that may cause disruptions.

C.

Review incident response procedures.

D.

Evaluate the probability of risk events.

Full Access
Question # 395

Which of the following elements of a risk register is MOST likely to change as a result of change in management ' s risk appetite?

A.

Key risk indicator (KRI) thresholds

B.

Inherent risk

C.

Risk likelihood and impact

D.

Risk velocity

Full Access
Question # 396

Which of the following would present the GREATEST challenge when assigning accountability for control ownership?

A.

Weak governance structures

B.

Senior management scrutiny

C.

Complex regulatory environment

D.

Unclear reporting relationships

Full Access
Question # 397

Which of the following indicates an organization follows IT risk management best practice?

A.

The risk register template uses an industry standard.

B.

The risk register is regularly updated.

C.

All fields in the risk register have been completed.

D.

Controls are listed against risk entries in the register.

Full Access
Question # 398

An organization has recently updated its disaster recovery plan (DRP). Which of the following would be the GREATEST risk if the new plan is not tested?

A.

External resources may need to be involved.

B.

Data privacy regulations may be violated.

C.

Recovery costs may increase significantly.

D.

Service interruptions may be longer than anticipated.

Full Access
Question # 399

Which of the following is a PRIMARY benefit of creating an organizational code of conduct?

A.

Clear expectations for employee behavior

B.

Identification of ethical risk facing the organization

C.

Improvement in workforce productivity

D.

Enhanced integrity of management

Full Access
Question # 400

Which of the following is MOST important when creating a program to reduce ethical risk?

A.

Defining strict policies

B.

Developing an organizational communication plan

C.

Conducting a gap analysis

D.

Obtaining senior management commitment

Full Access
Question # 401

Which of the following is the MOST important component in a risk treatment plan?

A.

Technical details

B.

Target completion date

C.

Treatment plan ownership

D.

Treatment plan justification

Full Access
Question # 402

Which of the following changes would be reflected in an organization ' s risk profile after the failure of a critical patch implementation?

A.

Risk tolerance is decreased.

B.

Residual risk is increased.

C.

Inherent risk is increased.

D.

Risk appetite is decreased

Full Access
Question # 403

Which of the following is MOST helpful in providing an overview of an organization ' s risk management program?

A.

Risk scenarios

B.

Risk management framework

C.

Risk assessment results

D.

Risk management treatment plan

Full Access
Question # 404

During an internal IT audit, an active network account belonging to a former employee was identified. Which of the following is the BEST way to prevent future occurrences?

A.

Conduct a comprehensive review of access management processes.

B.

Declare a security incident and engage the incident response team.

C.

Conduct a comprehensive awareness session for system administrators.

D.

Evaluate system administrators ' technical skills to identify if training is required.

Full Access
Question # 405

If preventive controls cannot be Implemented due to technology limitations, which of the following should be done FIRST to reduce risk7

A.

Evaluate alternative controls.

B.

Redefine the business process to reduce the risk.

C.

Develop a plan to upgrade technology.

D.

Define a process for monitoring risk.

Full Access
Question # 406

Which of the following BEST helps to identify significant events that could impact an organization?

Vulnerability analysis

A.

Control analysis

B.

Scenario analysis

C.

Heat map analysis

Full Access
Question # 407

The MOST important consideration when selecting a control to mitigate an identified risk is whether:

A.

the cost of control exceeds the mitigation value

B.

there are sufficient internal resources to implement the control

C.

the mitigation measures create compounding effects

D.

the control eliminates the risk

Full Access
Question # 408

Which of the following is the ULTIMATE objective of utilizing key control indicators (KCIs) in the risk management process?

A.

To provide a basis for determining the criticality of risk mitigation controls

B.

To provide early warning signs of a potential change in risk level

C.

To provide benchmarks for assessing control design effectiveness against industry peers

D.

To provide insight into the effectiveness of the intemnal control environment

Full Access
Question # 409

Which of the following BEST helps to balance the costs and benefits of managing IT risk?

A.

Prioritizing risk responses

B.

Evaluating risk based on frequency and probability

C.

Considering risk factors that can be quantified

D.

Managing the risk by using controls

Full Access
Question # 410

An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?

A.

Acceptance

B.

Avoidance

C.

Transfer

D.

Reduction

Full Access
Question # 411

What is the GREATEST concern with maintaining decentralized risk registers instead of a consolidated risk register?

A.

Aggregated risk may exceed the enterprise ' s risk appetite and tolerance.

B.

Duplicate resources may be used to manage risk registers.

C.

Standardization of risk management practices may be difficult to enforce.

D.

Risk analysis may be inconsistent due to non-uniform impact and likelihood scales.

Full Access
Question # 412

When documenting a risk response, which of the following provides the STRONGEST evidence to support the decision?

A.

Verbal majority acceptance of risk by committee

B.

List of compensating controls

C.

IT audit follow-up responses

D.

A memo indicating risk acceptance

Full Access
Question # 413

Which of the following would be the BEST way to help ensure the effectiveness of a data loss prevention (DLP) control that has been implemented to prevent the loss of credit card data?

A.

Testing the transmission of credit card numbers

B.

Reviewing logs for unauthorized data transfers

C.

Configuring the DLP control to block credit card numbers

D.

Testing the DLP rule change control process

Full Access
Question # 414

Continuous monitoring of key risk indicators (KRIs) will:

A.

ensure that risk will not exceed the defined risk appetite of the organization.

B.

provide an early warning so that proactive action can be taken.

C.

provide a snapshot of the risk profile.

D.

ensure that risk tolerance and risk appetite are aligned.

Full Access
Question # 415

An IT project risk was identified during a monthly steering committee meeting. Which of the following roles is BEST positioned to approve the risk mitigation response?

A.

Product owner

B.

IT manager

C.

Project sponsor

D.

Project coordinator

Full Access
Question # 416

A risk practitioner has learned that an effort to implement a risk mitigation action plan has stalled due to lack of funding. The risk practitioner should report that the associated risk has been:

A.

mitigated

B.

accepted

C.

avoided

D.

deferred

Full Access
Question # 417

An organizational policy requires critical security patches to be deployed in production within three weeks of patch availability. Which of the following is the BEST metric to verify adherence to the policy?

A.

Maximum time gap between patch availability and deployment

B.

Percentage of critical patches deployed within three weeks

C.

Minimum time gap between patch availability and deployment

D.

Number of critical patches deployed within three weeks

Full Access
Question # 418

The BEST way for management to validate whether risk response activities have been completed is to review:

A.

the risk register change log.

B.

evidence of risk acceptance.

C.

control effectiveness test results.

D.

control design documentation.

Full Access
Question # 419

Which of the following BEST indicates that an organizations risk management program is effective?

A.

Fewer security incidents have been reported.

B.

The number of audit findings has decreased.

C.

Residual risk is reduced.

D.

inherent risk Is unchanged.

Full Access
Question # 420

Which of the following is the BEST way to validate privileged access to database accounts?

A.

Regular reviews of privileged access

B.

Confirmation from users with privileged access

C.

Management approval of access requests

D.

Confirmation from the database administrator (DBA)

Full Access
Question # 421
A.

Ensure compliance with local legislation because it has a higher priority.

B.

Conduct a risk assessment and develop mitigation options.

C.

Terminate the current cloud contract and migrate to a local cloud provider.

D.

Accept the risk because foreign legislation does not apply to the organization.

Full Access
Question # 422

An employee lost a personal mobile device that may contain sensitive corporate information. What should be the risk practitioner ' s recommendation?

A.

Conduct a risk analysis.

B.

Initiate a remote data wipe.

C.

Invoke the incident response plan

D.

Disable the user account.

Full Access
Question # 423

It was discovered that a service provider ' s administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the following would BEST protect against a future recurrence?

A.

Data encryption

B.

Intrusion prevention system (IPS)

C.

Two-factor authentication

D.

Contractual requirements

Full Access
Question # 424

Which of the following is MOST helpful in identifying new risk exposures due to changes in the business environment?

A.

Standard operating procedures

B.

SWOT analysis

C.

Industry benchmarking

D.

Control gap analysis

Full Access
Question # 425

An organization has an internal control that requires all access for employees be removed within 15 days of their termination date. Which of the following should the risk practitioner use to monitor

adherence to the 15-day threshold?

A.

Operation level agreement (OLA)

B.

Service level agreement (SLA)

C.

Key performance indicator (KPI)

D.

Key risk indicator (KRI)

Full Access
Question # 426

Which of the following should be a risk practitioner ' s GREATEST concern upon learning of failures in a data migration activity?

A.

Availability of test data

B.

Integrity of data

C.

Cost overruns

D.

System performance

Full Access
Question # 427

Which of the following should be considered FIRST when creating a comprehensive IT risk register?

A.

Risk management budget

B.

Risk mitigation policies

C.

Risk appetite

D.

Risk analysis techniques

Full Access
Question # 428

The BEST way to determine the likelihood of a system availability risk scenario is by assessing the:

A.

availability of fault tolerant software.

B.

strategic plan for business growth.

C.

vulnerability scan results of critical systems.

D.

redundancy of technical infrastructure.

Full Access
Question # 429

Which of the following is the GREATEST risk associated with the use of data analytics?

A.

Distributed data sources

B.

Manual data extraction

C.

Incorrect data selection

D.

Excessive data volume

Full Access
Question # 430

Which of the following would be a risk practitioner’s GREATEST concern related to the monitoring of key risk indicators (KRIs)?

A.

Logs are retained for longer than required.

B.

Logs are reviewed annually.

C.

Logs are stored in a multi-tenant cloud environment.

D.

Logs are modified before analysis is conducted.

Full Access
Question # 431

Which of the following is the PRIMARY reason to obtain independent reviews of risk assessment and response mechanisms?

A.

To ensure risk thresholds are properly defined

B.

To minimize the subjectivity of risk assessment results

C.

To correct errors in the risk assessment process

D.

To validate impact and probability ratings

Full Access
Question # 432

An organization is increasingly concerned about loss of sensitive data and asks the risk practitioner to assess the current risk level. Which of the following should the risk practitioner do FIRST?

A.

Review assignments of data ownership for key assets.

B.

Identify staff who have access to the organization’s sensitive data.

C.

Identify recent and historical incidents involving data loss.

D.

Review the organization ' s data inventory.

Full Access
Question # 433

An organization uses one centralized single sign-on (SSO) control to cover many applications. Which of the following is the BEST course of action when a new application is added to the environment after testing of the SSO control has been completed?

A.

Initiate a retest of the full control

B.

Retest the control using the new application as the only sample.

C.

Review the corresponding change control documentation

D.

Re-evaluate the control during (he next assessment

Full Access
Question # 434

An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:

A.

reduce the risk to an acceptable level.

B.

communicate the consequences for violations.

C.

implement industry best practices.

D.

reduce the organization ' s risk appetite

Full Access
Question # 435

Which of the following is a risk practitioner ' s BEST recommendation to help reduce IT risk associated with scheduling overruns when starting a new application development project?

A.

Implement a tool to track the development team ' s deliverables.

B.

Review the software development life cycle.

C.

Involve the development team in planning.

D.

Assign more developers to the project team.

Full Access
Question # 436

The PRIMARY advantage of involving end users in continuity planning is that they:

A.

have a better understanding of specific business needs

B.

can balance the overall technical and business concerns

C.

can see the overall impact to the business

D.

are more objective than information security management.

Full Access
Question # 437

Which of the following is a specific concern related to machine learning algorithms?

A.

Low software quality

B.

Lack of access controls

C.

Data breaches

D.

Data bias

Full Access
Question # 438

An organization ' s recovery team is attempting to recover critical data backups following a major flood in its data center. However, key team members do not know exactly what steps should be taken to address this crisis. Which of the following is the MOST likely cause of this situation?

A.

Failure to test the disaster recovery plan (DRP)

B.

Lack of well-documented business impact analysis (BIA)

C.

Lack of annual updates to the disaster recovery plan (DRP)

D.

Significant changes in management personnel

Full Access
Question # 439

Which of the following is the BEST way for an organization to enable risk treatment decisions?

A.

Allocate sufficient funds for risk remediation.

B.

Promote risk and security awareness.

C.

Establish clear accountability for risk.

D.

Develop comprehensive policies and standards.

Full Access
Question # 440

Which of the following is the GREATEST risk associated with inappropriate classification of data?

A.

Inaccurate record management data

B.

Inaccurate recovery time objectives (RTOs)

C.

Lack of accountability for data ownership

D.

Users having unauthorized access to data

Full Access
Question # 441

A bank recently incorporated Blockchain technology with the potential to impact known risk within the organization. Which of the following is the risk practitioner’s BEST course of action?

A.

Determine whether risk responses are still adequate.

B.

Analyze and update control assessments with the new processes.

C.

Analyze the risk and update the risk register as needed.

D.

Conduct testing of the control that mitigate the existing risk.

Full Access
Question # 442

The MAIN purpose of conducting a control self-assessment (CSA) is to:

A.

gain a better understanding of the control effectiveness in the organization

B.

gain a better understanding of the risk in the organization

C.

adjust the controls prior to an external audit

D.

reduce the dependency on external audits

Full Access
Question # 443

The MAIN reason a risk practitioner should review control assessment reports is to:

A.

Provide assurance on effective compliance.

B.

Determine exceptions for management acceptance.

C.

Determine overall efficiency of the control environment.

D.

Determine if controls effectively lower risk exposure.

Full Access
Question # 444

Which of the following is the MOST important metric to monitor the performance of the change management process?

A.

Percentage of changes having separation of duties in code deployment

B.

Percentage of changes having completed post-implementation verification

C.

Percentage of changes having user acceptance testing (UAT) sign-off

D.

Percentage of changes having to invoke the rollback plan

Full Access
Question # 445

Which of the following BEST indicates the condition of a risk management program?

A.

Number of risk register entries

B.

Number of controls

C.

Level of financial support

D.

Amount of residual risk

Full Access
Question # 446

An IT risk practitioner has determined that mitigation activities differ from an approved risk action plan. Which of the following is the risk practitioner ' s BEST course of action?

A.

Report the observation to the chief risk officer (CRO).

B.

Validate the adequacy of the implemented risk mitigation measures.

C.

Update the risk register with the implemented risk mitigation actions.

D.

Revert the implemented mitigation measures until approval is obtained

Full Access
Question # 447

An external data source has released an advisory about a critical vulnerability affecting a widely used software application. Which of the following should the risk practitioner do FIRST?

A.

Advise application owners to patch affected software

B.

Determine organizational exposure

C.

Notify senior management of the critical vulnerability

D.

Review the incident response plan

Full Access
Question # 448

Which of the following is the GREATEST concern associated with insufficient focus on addressing blockchain interoperability in the SDLC?

A.

Limited blockchain adoption and support

B.

Reduced transaction speed and system responsiveness

C.

Reduced network integrity and availability

D.

Limited integration with external systems and blockchains

Full Access
Question # 449

Which of the following would present the MOST significant risk to an organization when updating the incident response plan?

A.

Obsolete response documentation

B.

Increased stakeholder turnover

C.

Failure to audit third-party providers

D.

Undefined assignment of responsibility

Full Access
Question # 450

Which of the following is the PRIMARY reason to use key control indicators (KCIs) to evaluate control operating effectiveness?

A.

To measure business exposure to risk

B.

To identify control vulnerabilities

C.

To monitor the achievement of set objectives

D.

To raise awareness of operational issues

Full Access
Question # 451

Which of the following is MOST helpful in identifying gaps between the current and desired state of the IT risk environment?

A.

Analyzing risk appetite and tolerance levels

B.

Assessing identified risk and recording results in the risk register

C.

Evaluating risk scenarios and assessing current controls

D.

Reviewing guidance from industry best practices and standards

Full Access
Question # 452

Which of the following is the BEST way to detect zero-day malware on an end user ' s workstation?

A.

An antivirus program

B.

Database activity monitoring

C.

Firewall log monitoring

D.

File integrity monitoring

Full Access
Question # 453

Which of the following would MOST likely result in agreement on accountability for risk scenarios?

A.

Using a facilitated risk management workshop

B.

Relying on generic risk scenarios

C.

Relying on external IT risk professionals

D.

Distributing predefined scenarios for review

Full Access
Question # 454

An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:

A.

chief risk officer.

B.

project manager.

C.

chief information officer.

D.

business process owner.

Full Access
Question # 455

An organization is outsourcing a key database to be hosted by an external service provider. Who is BEST suited to assess the impact of potential data loss?

A.

Database manager

B.

Public relations manager

C.

Data privacy manager

D.

Business manager

Full Access
Question # 456

Which of the following is the MOST appropriate risk owner for a payroll application that has recently been outsourced to a cloud software provider?

A.

IT executive.

B.

HR executive.

C.

Vendor management executive.

D.

Cloud service provider’s information security executive.

Full Access
Question # 457

Which of the following is the MOST appropriate action when a tolerance threshold is exceeded?

A.

Communicate potential impact to decision makers.

B.

Research the root cause of similar incidents.

C.

Verify the response plan is adequate.

D.

Increase human resources to respond in the interim.

Full Access
Question # 458

An organization has built up its cash reserves and has now become financially able to support additional risk while meeting its objectives. What is this change MOST likely to impact?

A.

Risk profile

B.

Risk capacity

C.

Risk indicators

D.

Risk tolerance

Full Access
Question # 459

Key risk indicators (KRIs) BEST support risk treatment when they:

A.

Set performance expectations for controls.

B.

Align with key business objectives.

C.

Indicate that the risk is approaching predefined thresholds.

D.

Articulate likelihood and impact in quantitative terms.

Full Access
Question # 460

During a review of the asset life cycle process, a risk practitioner identified several unreturned and unencrypted laptops belonging to former employees. Which of the following is the GREATEST concern with this finding?

A.

Insufficient laptops for existing employees

B.

Abuse of leavers ' account privileges

C.

Unauthorized access to organizational data

D.

Financial cost of replacing the laptops

Full Access
Question # 461

Which of the following is MOST important to add to the risk register for a remediated risk scenario?

A.

Notification to technical teams of implementation schedules

B.

Sign-off by senior executives

C.

Evidence of successfully implemented controls

D.

Minutes from control design meetings

Full Access
Question # 462

An organization is planning to acquire a new financial system. Which of the following stakeholders would provide the MOST relevant information for analyzing the risk associated with the new IT solution?

A.

Project sponsor

B.

Process owner

C.

Risk manager

D.

Internal auditor

Full Access
Question # 463

It is MOST important that entries in an organization’s risk register be updated:

A.

when the key risk indicator (KRI) threshold has been reached.

B.

when required by internal audit.

C.

prior to a risk review.

D.

when aspects of the risk scenario change.

Full Access
Question # 464

Which of the following is the PRIMARY reason for a risk practitioner to review an organization ' s IT asset inventory?

A.

To plan for the replacement of assets at the end of their life cycles

B.

To assess requirements for reducing duplicate assets

C.

To understand vulnerabilities associated with the use of the assets

D.

To calculate mean time between failures (MTBF) for the assets

Full Access
Question # 465

An organization ' s HR department has implemented a policy requiring staff members to take a minimum of five consecutive days leave per year to mitigate the risk of malicious insideractivities. Which of the following is the BEST key performance indicator (KPI) of the effectiveness of this policy?

A.

Number of malicious activities occurring during staff members leave

B.

Percentage of staff members seeking exception to the policy

C.

Percentage of staff members taking leave according to the policy

D.

Financial loss incurred due to malicious activities during staff members ' leave

Full Access
Question # 466

A risk practitioner notices that a particular key risk indicator (KRI) has remained below its established trigger point for an extended period of time. Which of the following should be done FIRST?

A.

Recommend a re-evaluation of the current threshold of the KRI.

B.

Notify management that KRIs are being effectively managed.

C.

Update the risk rating associated with the KRI In the risk register.

D.

Update the risk tolerance and risk appetite to better align to the KRI.

Full Access
Question # 467

A vendor ' s planned maintenance schedule will cause a critical application to temporarily lose failover capabilities. Of the following, who should approve this proposed schedule?

A.

IT infrastructure manager

B.

Chief Risk Officer (CRO)

C.

Business continuity manager

D.

Business application owner

Full Access
Question # 468

Which of the following BEST enables senior management to make risk treatment decisions in line with the organization ' s risk appetite?

A.

Quantitative risk analysis

B.

Industry risk benchmarks

C.

Risk scenarios

D.

Risk remediation plans

Full Access
Question # 469

Which of the following BEST helps to identify significant events that could impact an organization?

A.

Control analysis

B.

Vulnerability analysis

C.

Scenario analysis

D.

Heat map analysis

Full Access
Question # 470

An organization has allowed several employees to retire early in order to avoid layoffs Many of these employees have been subject matter experts for critical assets Which type of risk is MOST likely to materialize?

A.

Confidentiality breach

B.

Institutional knowledge loss

C.

Intellectual property loss

D.

Unauthorized access

Full Access
Question # 471

Which of the following is the BEST success criterion for control implementation?

A.

Adequate resources are allocated to perform the control.

B.

Responsibilities for control execution are properly defined.

C.

Risk is at an acceptable level after the control is in place.

D.

Key risk indicators (KRIs) for the control are properly defined.

Full Access
Question # 472

An organization is developing a plan to address new information security risks emerging from business changes. Which of the following BEST enables stakeholders to make decisions impacting organizational strategy?

A.

The impact of the new risk is clearly presented

B.

Benchmarking information is provided

C.

Technical expertise to address new risk scenarios is available

D.

The cost of implementing the strategy is within budget

Full Access
Question # 473

An organization retains footage from its data center security camera for 30 days when the policy requires 90-day retention The business owner challenges whether the situation is worth remediating Which of the following is the risk manager s BEST response '

A.

Identify the regulatory bodies that may highlight this gap

B.

Highlight news articles about data breaches

C.

Evaluate the risk as a measure of probable loss

D.

Verify if competitors comply with a similar policy

Full Access
Question # 474

After the review of a risk record, internal audit questioned why the risk was lowered from medium to low. Which of the following is the BEST course of action in responding to this inquiry?

A.

Obtain industry benchmarks related to the specific risk.

B.

Provide justification for the lower risk rating.

C.

Notify the business at the next risk briefing.

D.

Reopen the risk issue and complete a full assessment.

Full Access
Question # 475

Which of the following is MOST important to the effectiveness of a senior oversight committee for risk monitoring?

A.

Key risk indicators (KRIs)

B.

Risk governance charter

C.

Organizational risk appetite

D.

Cross-business representation

Full Access
Question # 476

A risk practitioner wants to identify potential risk events that affect the continuity of a critical business process. Which of the following should the risk practitioner do FIRST?

A.

Evaluate current risk management alignment with relevant regulations

B.

Determine if business continuity procedures are reviewed and updated on a regular basis

C.

Conduct a benchmarking exercise against industry peers

D.

Review the methodology used to conduct the business impact analysis (BIA)

Full Access
Question # 477

After undertaking a risk assessment of a production system, the MOST appropriate action is fcr the risk manager to

A.

recommend a program that minimizes the concerns of that production system.

B.

inform the process owner of the concerns and propose measures to reduce them.

C.

inform the IT manager of the concerns and propose measures to reduce them.

D.

inform the development team of the concerns and together formulate risk reduction measures.

Full Access
Question # 478

Which of the following BEST assists in justifying an investment in automated controls?

A.

Cost-benefit analysis

B.

Alignment of investment with risk appetite

C.

Elimination of compensating controls

D.

Reduction in personnel costs

Full Access
Question # 479

The PRIMARY objective of the board of directors periodically reviewing the risk profile is to help ensure:

A.

the risk strategy is appropriate

B.

KRIs and KPIs are aligned

C.

performance of controls is adequate

D.

the risk monitoring process has been established

Full Access
Question # 480

During a risk assessment, the risk practitioner finds a new risk scenario without controls has been entered into the risk register. Which of the following is the MOST appropriate action?

A.

Include the new risk scenario in the current risk assessment.

B.

Postpone the risk assessment until controls are identified.

C.

Request the risk scenario be removed from the register.

D.

Exclude the new risk scenario from the current risk assessment

Full Access
Question # 481

Which of the following is MOST important information to review when developing plans for using emerging technologies?

A.

Existing IT environment

B.

IT strategic plan

C.

Risk register

D.

Organizational strategic plan

Full Access
Question # 482

Which of the following findings of a security awareness program assessment would cause the GREATEST concern to a risk practitioner?

A.

The program has not decreased threat counts.

B.

The program has not considered business impact.

C.

The program has been significantly revised

D.

The program uses non-customized training modules.

Full Access
Question # 483

Which of the following is the MOST appropriate key risk indicator (KRI) for backup media that is recycled monthly?

A.

Time required for backup restoration testing

B.

Change in size of data backed up

C.

Successful completion of backup operations

D.

Percentage of failed restore tests

Full Access
Question # 484

Prudent business practice requires that risk appetite not exceed:

A.

inherent risk.

B.

risk tolerance.

C.

risk capacity.

D.

residual risk.

Full Access
Question # 485

Which of the following is MOST helpful to ensure effective security controls for a cloud service provider?

A.

A control self-assessment

B.

A third-party security assessment report

C.

Internal audit reports from the vendor

D.

Service level agreement monitoring

Full Access
Question # 486

Which of the following should be the PRIMARY focus of a risk owner once a decision is made to mitigate a risk?

A.

Updating the risk register to include the risk mitigation plan

B.

Determining processes for monitoring the effectiveness of the controls

C.

Ensuring that control design reduces risk to an acceptable level

D.

Confirming to management the controls reduce the likelihood of the risk

Full Access
Question # 487

What is the PRIMARY purpose of a business impact analysis (BIA)?

A.

To determine the likelihood and impact of threats to business operations

B.

To identify important business processes in the organization

C.

To estimate resource requirements for related business processes

D.

To evaluate the priority of business operations in case of disruption

Full Access
Question # 488

it was determined that replication of a critical database used by two business units failed. Which of the following should be of GREATEST concern1?

A.

The underutilization of the replicated Iink

B.

The cost of recovering the data

C.

The lack of integrity of data

D.

The loss of data confidentiality

Full Access
Question # 489

An automobile manufacturer is considering implementing an Internet of Things (IoT) network to improve customer service by collecting customer and vehicle data. Which of the following would be the risk practitioner’s BEST recommendation?

A.

Establish secure design and coding practices for the IoT network and devices

B.

Conduct a pilot program before implementing the IoT network and devices

C.

Ensure backward compatibility of IoT devices with previous generations of vehicles

D.

Provide a range of IoT device options and configurations for customers

Full Access
Question # 490

Which of the following should a risk practitioner recommend FIRST when a risk assessment identifies the exposure of a significant number of personal customer records in a database?

A.

Revise the information security policy.

B.

Invoke the incident response plan (IRP).

C.

Update the risk register.

D.

Escalate the issue to senior management.

Full Access
Question # 491

A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner ' s FIRST course of action?

A.

Update the KRI threshold.

B.

Recommend additional controls.

C.

Review incident handling procedures.

D.

Perform a root cause analysis.

Full Access
Question # 492

If concurrent update transactions to an account are not processed properly, which of the following will MOST likely be affected?

A.

Confidentiality

B.

Accountability

C.

Availability

D.

Integrity

Full Access
Question # 493

A risk practitioner finds that data has been misclassified. Which of the following is the GREATEST concern?

A.

Unauthorized access

B.

Data corruption

C.

Inadequate retention schedules

D.

Data disruption

Full Access
Question # 494

Which of the following should be the FIRST consideration when a business unit wants to use personal information for a purpose other than for which it was originally collected?

A.

Informed consent

B.

Cross border controls

C.

Business impact analysis (BIA)

D.

Data breach protection

Full Access
Question # 495

Which of the following situations would cause the GREATEST concern around the integrity of application logs?

A.

Weak privileged access management controls

B.

Lack of a security information and event management (SIEM) system

C.

Lack of data classification policies

D.

Use of hashing algorithms

Full Access
Question # 496

The MOST essential content to include in an IT risk awareness program is how to:

A.

define the IT risk framework for the organization

B.

populate risk register entries and build a risk profile for management reporting

C.

comply with the organization ' s IT risk and information security policies

D.

prioritize IT-related actions by considering risk appetite and risk tolerance

Full Access
Question # 497

Which of the following is the MOST essential factor for managing risk in a highly dynamic environment?

A.

Ongoing sharing of information among industry peers

B.

Obtaining support from senior leadership

C.

Adhering to industry-recognized risk management standards

D.

Implementing detection and response measures

Full Access
Question # 498

A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:

A.

mitigation plans for threat events should be prepared in the current planning period.

B.

this risk scenario is equivalent to more frequent but lower impact risk scenarios.

C.

the current level of risk is within tolerance.

D.

an increase in threat events could cause a loss sooner than anticipated.

Full Access
Question # 499

An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?

A.

Provide incentives for whistleblowers to report unethical actions

B.

Communicate sanctions and penalties for unethical actions

C.

Develop company-wide training on business ethics

D.

Create a policy regarding ethical behavior

Full Access
Question # 500

From an IT risk perspective, which of the following has the GREATEST impact on organizational strategy?

A.

Complexity of IT architecture

B.

Changes in IT risk tolerance

C.

Complexity of recovery plans

D.

Methodology for IT risk identification

Full Access
Question # 501

An organization ' s capability to implement a risk management framework is PRIMARILY influenced by the:

A.

guidance of the risk practitioner.

B.

competence of the staff involved.

C.

approval of senior management.

D.

maturity of its risk culture.

Full Access
Question # 502

What is the BEST recommendation to reduce the risk associated with potential system compromise when a vendor stops releasing security patches and updates for a business-critical legacy system?

A.

Segment the system on its own network.

B.

Ensure regular backups take place.

C.

Virtualize the system in the cloud.

D.

Install antivirus software on the system.

Full Access
Question # 503

Which of the following BEST describes the role of the IT risk profile in strategic IT-related decisions?

A.

It compares performance levels of IT assets to value delivered.

B.

It facilitates the alignment of strategic IT objectives to business objectives.

C.

It provides input to business managers when preparing a business case for new IT projects.

D.

It helps assess the effects of IT decisions on risk exposure

Full Access
Question # 504

An organization allows programmers to change production systems in emergency situations. Which of the following is the BEST control?

A.

Implementing an emergency change authorization process

B.

Periodically reviewing operator logs

C.

Limiting the number of super users

D.

Reviewing the programmers ' emergency change reports

Full Access
Question # 505

Which of the following controls BEST enables an organization to ensure a complete and accurate IT asset inventory?

A.

Prohibiting the use of personal devices for business

B.

Performing network scanning for unknown devices

C.

Requesting an asset list from business owners

D.

Documenting asset configuration baselines

Full Access
Question # 506

Which of the following BEST enables the integration of IT risk management across an organization?

A.

Enterprise risk management (ERM) framework

B.

Enterprise-wide risk awareness training

C.

Robust risk reporting practices

D.

Risk management policies

Full Access
Question # 507

Which of the following MUST be captured in a risk treatment plan?

A.

Risk owner

B.

Senior management

C.

Risk register details

D.

Risk financial impact

Full Access
Question # 508

Which of the following is MOST important for a risk practitioner to verify when evaluating the effectiveness of an organization ' s existing controls?

A.

Senior management has approved the control design.

B.

Inherent risk has been reduced from original levels.

C.

Residual risk remains within acceptable levels.

D.

Costs for control maintenance are reasonable.

Full Access
Question # 509

A global company s business continuity plan (BCP) requires the transfer of its customer information….

event of a disaster. Which of the following should be the MOST important risk consideration?

A.

The difference In the management practices between each company

B.

The cloud computing environment is shared with another company

C.

The lack of a service level agreement (SLA) in the vendor contract

D.

The organizational culture differences between each country

Full Access
Question # 510

A Software as a Service (SaaS) provider has determined that the risk of a client ' s sensitive data being compromised is low. Which of the following is the client ' s BEST course of action?

A.

Implement additional controls to address the risk

B.

Accept the risk based on the provider ' s risk assessment

C.

Review the provider ' s independent audit results

D.

Ensure the contract includes breach notification requirements

Full Access
Question # 511

Which of the following roles is BEST suited to help a risk practitioner understand the impact of IT-related events on business objectives?

A.

IT management

B.

Internal audit

C.

Process owners

D.

Senior management

Full Access
Question # 512

Which of the following is the MOST significant benefit of using quantitative risk analysis instead of qualitative risk analysis?

A.

Minimized time to completion

B.

Decreased structure

C.

Minimized subjectivity

D.

Decreased cost

Full Access
Question # 513

The PRIMARY purpose of using control metrics is to evaluate the:

A.

amount of risk reduced by compensating controls.

B.

amount of risk present in the organization.

C.

variance against objectives.

D.

number of incidents.

Full Access
Question # 514

Which of the following is the MOST important consideration when developing risk strategies?

A.

Organization ' s industry sector

B.

Long-term organizational goals

C.

Concerns of the business process owners

D.

History of risk events

Full Access
Question # 515

Which of the following is the MOST effective way to integrate risk and compliance management?

A.

Embedding risk management into compliance decision-making

B.

Designing corrective actions to improve risk response capabilities

C.

Embedding risk management into processes that are aligned with business drivers

D.

Conducting regular self-assessments to verify compliance

Full Access
Question # 516

From a risk management perspective, which of the following is the PRIMARY benefit of using automated system configuration validation tools?

A.

Residual risk is reduced.

B.

Staff costs are reduced.

C.

Operational costs are reduced.

D.

Inherent risk is reduced.

Full Access
Question # 517

Which of the following is MOST useful for measuring the existing risk management process against a desired state?

A.

Balanced scorecard

B.

Risk management framework

C.

Capability maturity model

D.

Risk scenario analysis

Full Access
Question # 518

An organization uses a vendor to destroy hard drives. Which of the following would BEST reduce the risk of data leakage?

A.

Require the vendor to degauss the hard drives

B.

Implement an encryption policy for the hard drives.

C.

Require confirmation of destruction from the IT manager.

D.

Use an accredited vendor to dispose of the hard drives.

Full Access
Question # 519

Which of the following should be implemented to BEST mitigate the risk associated with infrastructure updates?

A.

Role-specific technical training

B.

Change management audit

C.

Change control process

D.

Risk assessment

Full Access
Question # 520

An organization is implementing Zero Trust architecture to improve its security posture. Which of the following is the MOST important input to develop the architecture?

A.

Cloud services risk assessments

B.

The organization ' s threat model

C.

Access control logs

D.

Multi-factor authentication (MFA) architecture

Full Access
Question # 521

Which of the following is MOST important to consider when determining a recovery time objective (RTO)?

A.

Time between backups for critical data

B.

Sensitivity of business data involved

C.

Cost of downtime due to a disaster

D.

Maximum tolerable data loss after an incident

Full Access
Question # 522

Which of the following would be considered a vulnerability?

A.

Delayed removal of employee access

B.

Authorized administrative access to HR files

C.

Corruption of files due to malware

D.

Server downtime due to a denial of service (DoS) attack

Full Access
Question # 523

Which of the following is the MOST important consideration for a risk practitioner when making a system implementation go-live recommendation?

A.

Completeness of system documentation

B.

Results of end user acceptance testing

C.

Variances between planned and actual cost

D.

availability of in-house resources

Full Access
Question # 524

An organization ' s finance team is proposing the adoption of a blockchain technology to provide a secure method for moving funds. Which of the following should the risk practitioner do FIRST?

A.

Recommend permissionless blockchain.

B.

Perform a risk assessment.

C.

Perform a business impact analysis (BIA).

D.

Recommend permissioned blockchain.

Full Access
Question # 525

A compensating control is MOST appropriate when:

A.

Management wants to increase the number of controls.

B.

A vulnerability is identified.

C.

Existing controls are inadequate.

D.

A key control is already in place and operating effectively.

Full Access
Question # 526

Which of the following should be the risk practitioner s FIRST course of action when an organization has decided to expand into new product areas?

A.

Identify any new business objectives with stakeholders.

B.

Present a business case for new controls to stakeholders.

C.

Revise the organization ' s risk and control policy.

D.

Review existing risk scenarios with stakeholders.

Full Access
Question # 527

Which of the following BEST facilitates the identification of emerging risk?

A.

Performing scenario-based assessments

B.

Reviewing audit reports annually

C.

Conducting root cause analyses

D.

Engaging a risk-focused audit team

Full Access
Question # 528

Which of the following provides the BEST evidence of the effectiveness of an organization ' s account provisioning process?

A.

User provisioning

B.

Role-based access controls

C.

Security log monitoring

D.

Entitlement reviews

Full Access
Question # 529

Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?

A.

Segregation of duties

B.

Monetary approval limits

C.

Clear roles and responsibilities

D.

Password policies

Full Access
Question # 530

Which of the following is the GREATEST concern associated with the use of artificial intelligence (AI) language models?

A.

The model could be hacked or exploited.

B.

The model could be used to generate inaccurate content.

C.

Staff could become overly reliant on the model.

D.

It could lead to biased recommendations.

Full Access
Question # 531

The MAIN purpose of having a documented risk profile is to:

A.

comply with external and internal requirements.

B.

enable well-informed decision making.

C.

prioritize investment projects.

D.

keep the risk register up-to-date.

Full Access
Question # 532

Which of the following controls would BEST reduce the risk of account compromise?

A.

Enforce password changes.

B.

Enforce multi-factor authentication (MFA).

C.

Enforce role-based authentication.

D.

Enforce password encryption.

Full Access
Question # 533

An effective control environment is BEST indicated by controls that:

A.

minimize senior management ' s risk tolerance.

B.

manage risk within the organization ' s risk appetite.

C.

reduce the thresholds of key risk indicators (KRIs).

D.

are cost-effective to implement

Full Access
Question # 534

Which of the following should be the risk practitioner s PRIMARY focus when determining whether controls are adequate to mitigate risk?

A.

Sensitivity analysis

B.

Level of residual risk

C.

Cost-benefit analysis

D.

Risk appetite

Full Access
Question # 535

The BEST metric to monitor the risk associated with changes deployed to production is the percentage of:

A.

changes due to emergencies.

B.

changes that cause incidents.

C.

changes not requiring user acceptance testing.

D.

personnel that have rights to make changes in production.

Full Access
Question # 536

Which of the following would cause the GREATEST concern for a risk practitioner reviewing the IT risk scenarios recorded in an organization’s IT risk register?

A.

Some IT risk scenarios have multi-year risk action plans.

B.

Several IT risk scenarios are missing assigned owners.

C.

Numerous IT risk scenarios have been granted risk acceptances.

D.

Many IT risk scenarios are categorized as avoided.

Full Access
Question # 537

Which of the following events is MOST likely to trigger the need to conduct a risk assessment?

A.

An incident resulting in data loss

B.

Changes in executive management

C.

Updates to the information security policy

D.

Introduction of a new product line

Full Access
Question # 538

Which of the following is MOST important to include in a Software as a Service (SaaS) vendor agreement?

A.

An annual contract review

B.

A service level agreement (SLA)

C.

A requirement to adopt an established risk management framework

D.

A requirement to provide an independent audit report

Full Access
Question # 539

Which of the following should be the MAIN consideration when validating an organization ' s risk appetite?

A.

Comparison against regulations

B.

Maturity of the risk culture

C.

Capacity to withstand loss

D.

Cost of risk mitigation options

Full Access
Question # 540

Which of the following is the BEST course of action to reduce risk impact?

A.

Create an IT security policy.

B.

Implement corrective measures.

C.

Implement detective controls.

D.

Leverage existing technology

Full Access
Question # 541

Which of the following should be the FIRST consideration when establishing a new risk governance program?

A.

Developing an ongoing awareness and training program

B.

Creating policies and standards that are easy to comprehend

C.

Embedding risk management into the organization

D.

Completing annual risk assessments on critical resources

Full Access
Question # 542

Which of the following is the BEST way to incorporate continuous monitoring in IT risk policies?

A.

Implement a governance, risk, and compliance (GRC) tool

B.

Establish a cross-functional risk steering committee to oversee risk initiatives.

C.

Define how risk thresholds are aligned with organizational objectives.

D.

Standardize IT risk mitigation for better monitoring of IT risk.

Full Access
Question # 543

An organization is subject to a new regulation that requires nearly real-time recovery of its services following a disruption. Which of the following is the BEST way to manage the risk in this situation?

A.

Move redundant IT infrastructure to a closer location.

B.

Obtain insurance and ensure sufficient funds are available for disaster recovery.

C.

Review the business continuity plan (BCP) and align it with the new business needs.

D.

Outsource disaster recovery services to a third-party IT service provider.

Full Access
Question # 544

A segregation of duties control was found to be ineffective because it did not account for all applicable functions when evaluating access. Who is responsible for ensuring the control is designed to effectively address risk?

A.

Risk manager

B.

Control owner

C.

Control tester

D.

Risk owner

Full Access
Question # 545

Which of the following is the GREATEST benefit of a three lines of defense structure?

A.

An effective risk culture that empowers employees to report risk

B.

Effective segregation of duties to prevent internal fraud

C.

Clear accountability for risk management processes

D.

Improved effectiveness and efficiency of business operations

Full Access
Question # 546

A risk assessment has identified that departments have installed their own WiFi access points on the enterprise network. Which of the following would be MOST important to include in a report to senior management?

A.

The network security policy

B.

Potential business impact

C.

The WiFi access point configuration

D.

Planned remediation actions

Full Access
Question # 547

Which of the following factors will have the GREATEST impact on the implementation of a risk mitigation strategy for an organization?

A.

Cost-benefit analysis

B.

Risk tolerance

C.

Known vulnerabilities

D.

Cyber insurance

Full Access
Question # 548

Which of the following resources is MOST helpful when creating a manageable set of IT risk scenarios?

A.

Results of current and past risk assessments

B.

Organizational strategy and objectives

C.

Lessons learned from materialized risk scenarios

D.

Internal and external audit findings

Full Access
Question # 549

What should be the PRIMARY objective of updating a risk awareness program in response to a steady rise in cybersecurity threats across the industry?

A.

To increase familiarity and understanding of potential security incidents

B.

To ensure compliance with risk management policies and procedures

C.

To reduce the risk of insider threats that could compromise security practices

D.

To lower the organization ' s risk appetite and tolerance levels

Full Access
Question # 550

Who is MOST appropriate to be assigned ownership of a control

A.

The individual responsible for control operation

B.

The individual informed of the control effectiveness

C.

The individual responsible for resting the control

D.

The individual accountable for monitoring control effectiveness

Full Access
Question # 551

Following a review of a third-party vendor, it is MOST important for an organization to ensure:

A.

results of the review are accurately reported to management.

B.

identified findings are reviewed by the organization.

C.

results of the review are validated by internal audit.

D.

identified findings are approved by the vendor.

Full Access
Question # 552

A risk practitioner is performing a risk assessment of recent external advancements in quantum computing. Which of the following would pose the GREATEST concern for the risk practitioner?

A.

The organization has incorporated blockchain technology in its operations.

B.

The organization has not reviewed its encryption standards.

C.

The organization has implemented heuristics on its network firewall.

D.

The organization has not adopted Infrastructure as a Service (laaS) for its operations.

Full Access
Question # 553

Which of the following BEST balances the costs and benefits of managing IT risk*?

A.

Prioritizing and addressing risk in line with risk appetite. Eliminating risk through preventive and detective controls

B.

Considering risk that can be shared with a third party

C.

Evaluating the probability and impact of risk scenarios

Full Access
Question # 554

Which of the following is the BEST recommendation of a risk practitioner for an organization that recently changed its organizational structure?

A.

Communicate the new risk profile.

B.

Implement a new risk assessment process.

C.

Revalidate the corporate risk appetite.

D.

Review and adjust key risk indicators (KRIs).

Full Access
Question # 555

An organization wants to launch a campaign to advertise a new product Using data analytics, the campaign can be targeted to reach potential customers. Which of the following should be of GREATEST concern to the risk practitioner?

A.

Data minimization

B.

Accountability

C.

Accuracy

D.

Purpose limitation

Full Access
Question # 556

A public online information security training course is available to an organization ' s staff. The online course contains free-form discussion fields. Which of the following should be of MOST concern to the organization ' s risk practitioner?

A.

The form may be susceptible to SQL injection attacks.

B.

Data is not encrypted in transit to the site.

C.

Proprietary corporate information may be disclosed.

D.

Staff nondisclosure agreements (NDAs) are not in place.

Full Access
Question # 557

Which of the following should be a risk practitioner’s MOST important consideration when developing IT risk scenarios?

A.

The impact of controls on the efficiency of the business in delivering services

B.

Linkage of identified risk scenarios with enterprise risk management

C.

Potential threats and vulnerabilities that may have an impact on the business

D.

Results of network vulnerability scanning and penetration testing

Full Access
Question # 558

Which of the following is the BEST course of action to help reduce the probability of an incident recurring?

A.

Perform a risk assessment.

B.

Perform root cause analysis.

C.

Initiate disciplinary action.

D.

Update the incident response plan.

Full Access
Question # 559

Which of the following is the GREATEST concern when an organization uses a managed security service provider as a firewall administrator?

A.

Exposure of log data

B.

Lack of governance

C.

Increased number of firewall rules

D.

Lack of agreed-upon standards

Full Access
Question # 560

While reviewing a contract of a cloud services vendor, it was discovered that the vendor refuses to accept liability for a sensitive data breach. Which of the following controls will BES reduce the risk associated with such a data breach?

A.

Ensuring the vendor does not know the encryption key

B.

Engaging a third party to validate operational controls

C.

Using the same cloud vendor as a competitor

D.

Using field-level encryption with a vendor supplied key

Full Access
Question # 561

Which of the following is the BEST approach for determining whether a risk action plan is effective?

A.

Comparing the remediation cost against budget

B.

Assessing changes in residual risk

C.

Assessing the inherent risk

D.

Monitoring changes of key performance indicators(KPIs)

Full Access
Question # 562

An organization is planning to move its application infrastructure from on-premises to the cloud. Which of the following is the BEST course of the actin to address the risk associated with data transfer if the relationship is terminated with the vendor?

A.

Meet with the business leaders to ensure the classification of their transferred data is in place

B.

Ensure the language in the contract explicitly states who is accountable for each step of the data transfer process

C.

Collect requirements for the environment to ensure the infrastructure as a service (IaaS) is configured appropriately.

D.

Work closely with the information security officer to ensure the company has the proper security controls in place.

Full Access
Question # 563

Which of the following is the PRIMARY purpose of a risk register?

A.

To assign control ownership of risk

B.

To provide a centralized view of risk

C.

To identify opportunities to transfer risk

D.

To mitigate organizational risk

Full Access
Question # 564

Where should a risk practitioner document the current state and desired future state of organizational risk?

A.

Risk register

B.

Risk action plan

C.

Risk management strategy

D.

Business continuity plan (BCP)

Full Access
Question # 565

Which of the following would be the GREATEST risk associated with a new implementation of single sign-on?

A.

Inability to access key information

B.

Complex security administration

C.

User resistance to single sign-on

D.

Single point of failure

Full Access
Question # 566

Which of the following is the BEST indication of a potential threat?

A.

Increase in identified system vulnerabilities

B.

Ineffective risk treatment plans

C.

Excessive policy and standard exceptions

D.

Excessive activity in system logs

Full Access
Question # 567

Which of the following would BEST mitigate an identified risk scenario?

A.

Conducting awareness training

B.

Executing a risk response plan

C.

Establishing an organization ' s risk tolerance

D.

Performing periodic audits

Full Access
Question # 568

Which of the following is the MOST useful indicator to measure the efficiency of an identity and access management process?

A.

Number of tickets for provisioning new accounts

B.

Average time to provision user accounts

C.

Password reset volume per month

D.

Average account lockout time

Full Access
Question # 569

Which of the following would provide the MOST comprehensive information for updating an organization ' s risk register?

A.

Results of the latest risk assessment

B.

Results of a risk forecasting analysis

C.

A review of compliance regulations

D.

Findings of the most recent audit

Full Access
Question # 570

When collecting information to identify IT-related risk, a risk practitioner should FIRST focus on IT:

A.

risk appetite.

B.

security policies

C.

process maps.

D.

risk tolerance level

Full Access
Question # 571

When of the following is the BEST key control indicator (KCI) to determine the effectiveness of en intrusion prevention system (IPS)?

A.

Percentage of system uptime

B.

Percentage of relevant threats mitigated

C.

Total number of threats identified

D.

Reaction time of the system to threats

Full Access
Question # 572

Which of the following is the MOST important consideration when establishing a recovery point objective (RPO)?

A.

Latency of the alternate site

B.

Amount of acceptable data loss

C.

Time and resources for offsite backups

D.

Cost of testing the business continuity plan (BCP)

Full Access
Question # 573

Which of the following BEST enables an organization to address risk associated with technical complexity?

A.

Documenting system hardening requirements

B.

Minimizing dependency on technology

C.

Aligning with a security architecture

D.

Establishing configuration guidelines

Full Access
Question # 574

Which of the following would be- MOST helpful to understand the impact of a new technology system on an organization ' s current risk profile?

A.

Hire consultants specializing m the new technology.

B.

Review existing risk mitigation controls.

C.

Conduct a gap analysis.

D.

Perform a risk assessment.

Full Access
Question # 575

Which of the following is the PRIMARY reason to use administrative controls in conjunction with technical controls?

A.

To gain stakeholder support for the implementation of controls

B.

To comply with industry best practices by balancing multiple types of controls

C.

To improve the effectiveness of controls that mitigate risk

D.

To address multiple risk scenarios mitigated by technical controls

Full Access
Question # 576

Which of the following is the BEST indicator of executive management ' s support for IT risk mitigation efforts?

A.

The number of stakeholders involved in IT risk identification workshops

B.

The percentage of corporate budget allocated to IT risk activities

C.

The percentage of incidents presented to the board

D.

The number of executives attending IT security awareness training

Full Access
Question # 577

When developing a risk awareness training program, which of the following is the BEST way to promote a risk-aware culture?

A.

Emphasize individual responsibility for managing risk.

B.

Communicate incident escalation procedures.

C.

Illustrate methods to identify threats and vulnerabilities.

D.

Challenge the effectiveness of business processes.

Full Access
Question # 578

Which of the following is the BEST way for a risk practitioner to consolidate the results of risk assessments across multiple operating units?

A.

Implement a governance, risk, and compliance (GRC) system.

B.

Update departmental risk registers with items from the central risk register.

C.

Aggregate operating unit risk registers to a central risk register.

D.

Perform additional risk assessments and create an enterprise risk matrix.

Full Access
Question # 579

In addition to the risk register, what should a risk practitioner review to develop an understanding of the organization ' s risk profile?

A.

The control catalog

B.

The asset profile

C.

Business objectives

D.

Key risk indicators (KRls)

Full Access
Question # 580

Which of the following is MOST important when discussing risk within an organization?

A.

Adopting a common risk taxonomy

B.

Using key performance indicators (KPIs)

C.

Creating a risk communication policy

D.

Using key risk indicators (KRIs)

Full Access
Question # 581

An application runs a scheduled job that compiles financial data from multiple business systems and updates the financial reporting system. If this job runs too long, it can delay financial reporting. Which of the following is the risk practitioner ' s BEST recommendation?

A.

Implement database activity and capacity monitoring.

B.

Ensure the business is aware of the risk.

C.

Ensure the enterprise has a process to detect such situations.

D.

Consider providing additional system resources to this job.

Full Access
Question # 582

An organization learns of a new ransomware attack affecting organizations worldwide. Which of the following should be done FIRST to reduce the likelihood of infection from the attack?

A.

Identify systems that are vulnerable to being exploited by the attack.

B.

Confirm with the antivirus solution vendor whether the next update will detect the attack.

C.

Verify the data backup process and confirm which backups are the most recent ones available.

D.

Obtain approval for funding to purchase a cyber insurance plan.

Full Access
Question # 583

Which of the following is the MOST important consideration when performing a risk assessment of a fire suppression system within a data center?

A.

Insurance coverage

B.

Onsite replacement availability

C.

Maintenance procedures

D.

Installation manuals

Full Access
Question # 584

Which of the following is the GREATEST concern when using a generic set of IT risk scenarios for risk analysis?

A.

Quantitative analysis might not be possible.

B.

Risk factors might not be relevant to the organization

C.

Implementation costs might increase.

D.

Inherent risk might not be considered.

Full Access
Question # 585

A risk practitioner has received an updated enterprise risk management (ERM) report showing that residual risk is now within the organization ' s defined appetite and tolerance levels. Which of the following is the risk practitioner ' s BEST course of action?

A.

Identify new risk entries to include in ERM.

B.

Remove the risk entries from the ERM register.

C.

Re-perform the risk assessment to confirm results.

D.

Verify the adequacy of risk monitoring plans.

Full Access
Question # 586

Which of the following deficiencies identified during a review of an organization ' s cybersecurity policy should be of MOST concern?

A.

The policy lacks specifics on how to secure the organization ' s systems from cyberattacks.

B.

The policy has gaps against relevant cybersecurity standards and frameworks.

C.

The policy has not been reviewed by the cybersecurity team in over a year.

D.

The policy has not been approved by the organization ' s board.

Full Access
Question # 587

Which of the following is the BEST way to determine the potential organizational impact of emerging privacy regulations?

A.

Evaluate the security architecture maturity.

B.

Map the new requirements to the existing control framework.

C.

Charter a privacy steering committee.

D.

Conduct a privacy impact assessment (PIA).

Full Access
Question # 588

Which of the following would BEST indicate to senior management that IT processes are improving?

A.

Changes in the number of intrusions detected

B.

Changes in the number of security exceptions

C.

Changes in the position in the maturity model

D.

Changes to the structure of the risk register

Full Access
Question # 589

Which of the following is the BEST key performance indicator (KPI) to measure how effectively risk management practices are embedded in the project management office (PMO)?

A.

Percentage of projects with key risk accepted by the project steering committee

B.

Reduction in risk policy noncompliance findings

C.

Percentage of projects with developed controls on scope creep

D.

Reduction in audits involving external risk consultants

Full Access
Question # 590

The MOST important reason to aggregate results from multiple risk assessments on interdependent information systems is to:

A.

establish overall impact to the organization

B.

efficiently manage the scope of the assignment

C.

identify critical information systems

D.

facilitate communication to senior management

Full Access
Question # 591

An organization has engaged a third party to provide an Internet gateway encryption service that protects sensitive data uploaded to a cloud service. This is an example of risk:

A.

mitigation.

B.

avoidance.

C.

transfer.

D.

acceptance.

Full Access
Question # 592

A risk assessment has revealed that the probability of a successful cybersecurity attack is increasing. The potential loss could exceed the organization ' s risk appetite. Which of the following ould be the MOST effective course of action?

A.

Re-evaluate the organization ' s risk appetite.

B.

Outsource the cybersecurity function.

C.

Purchase cybersecurity insurance.

D.

Review cybersecurity incident response procedures.

Full Access