Which of the following BEST enables a risk practitioner to focus on risk factors that could potentially affect the results of an IT initiative?
An organization has identified that terminated employee accounts are not disabled or deleted within the time required by corporate policy. Unsure of the reason, the organization has decided to monitor the situation for three months to obtain more information. As a result of this decision, the risk has been:
Which of the following would be the GREATEST challenge when implementing a corporate risk framework for a global organization?
Which of the following is the GREATEST impact of implementing a risk mitigation strategy?
Which of the following is the MOST effective way to help ensure future risk levels do not exceed the organization's risk appetite?
The BEST key performance indicator (KPI) for monitoring adherence to an organization's user accounts provisioning practices is the percentage of:
Which of the following is MOST important to ensure before using risk reports in decision making?
Which strategy employed by risk management would BEST help to prevent internal fraud?
Which of the following is MOST useful input when developing risk scenarios?
A risk practitioner implemented a process to notify management of emergency changes that may not be approved. Which of the following is the BEST way to provide this information to management?
Which of the following is MOST important to consider when assessing the likelihood that a recently discovered software vulnerability will be exploited?
When determining the accuracy of a key risk indicator (KRI), it is MOST important that the indicator:
Which of the following is the BEST metric to measure employee adherence to organizational security policies?
An organization uses a biometric access control system for authentication and access to its server room. Which control type has been implemented?
A risk practitioner has learned that an effort to implement a risk mitigation action plan has stalled due to lack of funding. The risk practitioner should report that the associated risk has been:
Several network user accounts were recently created without the required management approvals. Which of the following would be the risk practitioner's BEST recommendation to address this situation?
An organization has opened a subsidiary in a foreign country. Which of the following would be the BEST way to measure the effectiveness of the subsidiary's IT systems controls?
When an organization’s disaster recovery plan (DRP) has a reciprocal agreement, which of the following risk treatment options is being applied?
An organization's internal audit department is considering the implementation of robotics process automation (RPA) to automate certain continuous auditing tasks. Who would own the risk associated with ineffective design of the software bots?
What is the MOST important consideration when aligning IT risk management with the enterprise risk management (ERM) framework?
Which of the following represents a vulnerability?
Which of the following would MOST effectively reduce risk associated with an increased volume of online transactions on a retailer website?
A multinational organization is considering implementing standard background checks to' all new employees A KEY concern regarding this approach
Which of the following is the MOST important reason to communicate control effectiveness to senior management?
A hospital recently implemented a new technology to allow virtual patient appointments. Which of the following should be the risk practitioner's FIRST course of action?
Who is MOST likely to be responsible for the coordination between the IT risk strategy and the business risk strategy?
A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization's data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?
Which of the following is a risk practitioner's BEST course of action after identifying risk scenarios related to noncompliance with new industry regulations?
Which of the following is the MOST important consideration when identifying stakeholders to review risk scenarios developed by a risk analyst? The reviewers are:
Which of the following is the PRIMARY benefit when senior management periodically reviews and updates risk appetite and tolerance levels?
Which of the following should be done FIRST when a new risk scenario has been identified
A risk practitioner recently discovered that personal information from the production environment is required for testing purposes in non-production environments. Which of the following is the BEST recommendation to address this situation?
Which of the following should be the risk practitioner s PRIMARY focus when determining whether controls are adequate to mitigate risk?
Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?
A risk practitioner has just learned about new done FIRST?
A risk practitioner has learned that the number of emergency change management tickets without subsequent approval has doubled from the same period of the previous year. Which of the following is the MOST important action for the risk practitioner to take?
Which of the following BEST facilitates the development of effective IT risk scenarios?
Which of the following provides the BEST assurance of…..
Who should be responsible for approving the cost of controls to be implemented for mitigating risk?
When evaluating enterprise IT risk management it is MOST important to:
A risk practitioner has been asked by executives to explain how existing risk treatment plans would affect risk posture at the end of the year. Which of the following is MOST helpful in responding to this request?
Which of the following is the BEST way to maintain a current list of organizational risk scenarios?
The PRIMARY purpose of using control metrics is to evaluate the:
Which of the following is the MOST efficient method for monitoring control effectiveness?
Which of the following is the BEST indicator of the effectiveness of a control monitoring program?
Which of the following provides the MOST useful information when developing a risk profile for management approval?
Which of the following is the MOST important consideration when selecting key risk indicators (KRIs) to monitor risk trends over time?
A control process has been implemented in response to a new regulatory requirement, but has significantly reduced productivity. Which of the following is the BEST way to resolve this concern?
Which of the following presents the GREATEST security risk associated with Internet of Things (IoT) technology?
From a business perspective, which of the following is the MOST important objective of a disaster recovery test?