A key risk indicator (KRI) indicates a reduction in the percentage of appropriately patched servers. Which of the following is the risk practitioner's BEST course of action?
In the three lines of defense model, a PRIMARY objective of the second line is to:
An IT risk practitioner has determined that mitigation activities differ from an approved risk action plan. Which of the following is the risk practitioner's BEST course of action?
An organization has established a policy prohibiting ransom payments if subjected to a ransomware attack. Which of the following is the MOST effective control to support this policy?
The MOST essential content to include in an IT risk awareness program is how to:
An organization wants to launch a campaign to advertise a new product Using data analytics, the campaign can be targeted to reach potential customers. Which of the following should be of GREATEST concern to the risk practitioner?
Which of the following BEST enforces access control for an organization that uses multiple cloud technologies?
Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?
Which of the following is the MOST useful information an organization can obtain from external sources about emerging threats?
A service organization is preparing to adopt an IT control framework to comply with the contractual requirements of a new client. Which of the following would be MOST helpful to the risk practitioner?
A risk practitioner is involved in a comprehensive overhaul of the organizational risk management program. Which of the following should be reviewed FIRST to help identify relevant IT risk scenarios?
Which of the following is the BEST measure of the effectiveness of an employee deprovisioning process?
Which of the following is MOST important for an organization to have in place when developing a risk management framework?
After conducting a risk assessment for regulatory compliance, an organization has identified only one possible mitigating control. The cost of the control has been determined to be higher than the penalty of noncompliance. Which of the following would be the risk practitioner's BEST recommendation?
Which of the following requirements is MOST important to include in an outsourcing contract to help ensure sensitive data stored with a service provider is secure?
During the initial risk identification process for a business application, it is MOST important to include which of the following stakeholders?
Which of the following is the PRIMARY reason for an organization to include an acceptable use banner when users log in?
External penetration tests MUST include:
Which of the following is MOST important to ensure before using risk reports in decision making?
Which of the following is the GREATEST benefit of updating the risk register to include outcomes from a risk assessment?
Which of the following is the MOST important consideration when multiple risk practitioners capture risk scenarios in a single risk register?
An organization is considering allowing users to access company data from their personal devices. Which of the following is the MOST important factor when assessing the risk?
It is MOST appropriate for changes to be promoted to production after they are:
An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure for the business. Which of the following should be of GREATEST concern to the risk practitioner?
Which of the following is the PRIMARY objective of providing an aggregated view of IT risk to business management?
Which of the following is the MOST important key performance indicator (KPI) to establish in the service level agreement (SLA) for an outsourced data center?
Winch of the following key control indicators (KCIs) BEST indicates whether security requirements are identified and managed throughout a project He cycle?
Which of the following is MOST important requirement to include in a Software as a Service (SaaS) vendor contract to ensure data is protected?
A risk practitioner is preparing a report to communicate changes in the risk and control environment. The BEST way to engage stakeholder attention is to:
Senior management has requested more information regarding the risk associated with introducing a new application into the environment. Which of the following should be done FIRST?
Which of the following is the BEST control to minimize the risk associated with scope creep in software development?
Which of the following is MOST helpful in identifying loss magnitude during risk analysis of a new system?
Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?
Which of the following is MOST important when developing key performance indicators (KPIs)?
Which of the following is the GREATEST concern associated with business end users developing their own applications on end user spreadsheets and database programs?
A recent big data project has resulted in the creation of an application used to support important investment decisions. Which of the following should be of GREATEST concern to the risk practitioner?
Which of the following is the MOST important objective of establishing an enterprise risk management (ERM) function within an organization?
Which of the following is the BEST method for identifying vulnerabilities?
Which of the following is the BEST metric to measure the effectiveness of an organization's disaster recovery program?
Which of the following provides the MOST useful information when determining if a specific control should be implemented?
An organization wants to transfer risk by purchasing cyber insurance. Which of the following would be MOST important for the risk practitioner to communicate to senior management for contract negotiation purposes?
To reduce costs, an organization is combining the second and third tines of defense in a new department that reports to a recently appointed C-level executive. Which of the following is the GREATEST concern with this situation?
Which of the following is the GREATEST benefit for an organization with a strong risk awareness culture?
Reviewing which of the following provides the BEST indication of an organizations risk tolerance?
Which of the following should be a risk practitioner's PRIMARY focus when tasked with ensuring organization records are being retained for a sufficient period of time to meet legal obligations?
Which of the following shortcomings of perimeter security does Zero Trust aim to resolve?
The MOST effective way to increase the likelihood that risk responses will be implemented is to:
A risk practitioner finds that data has been misclassified. Which of the following is the GREATEST concern?
A control process has been implemented in response to a new regulatory requirement, but has significantly reduced productivity. Which of the following is the BEST way to resolve this concern?
Which of the following is the PRIMARY reason to adopt key control indicators (KCIs) in the risk monitoring and reporting process?