<< Prev Question Next Question >>

Question 587/702

Key risk indicators (KRIs) BEST support risk treatment when they:

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (702q)
Question 1: Which of the following is MOST likely to be identified from ...
Question 2: Malware has recently affected an organization. The MOST effe...
Question 3: A risk practitioner has been asked to propose a risk accepta...
Question 4: Which of the following is the MOST important reason to commu...
Question 5: Which of the following should a risk practitioner do FIRST w...
Question 6: Which of the following is the BEST approach for obtaining ma...
Question 7: Which of the following is the PRIMARY purpose of periodicall...
Question 8: Which of the following metrics is BEST used to communicate t...
Question 9: A risk assessment has revealed that the probability of a suc...
Question 10: Which of the following is MOST important to review when dete...
Question 11: The BEST criteria when selecting a risk response is the:...
Question 12: Which of the following BEST enables a risk practitioner to i...
Question 13: An organization's capability to implement a risk management ...
Question 14: Which of the following is the MOST effective way to reduce p...
Question 15: An IT operations team implements disaster recovery controls ...
Question 16: Which of the following is the MOST important reason to restr...
Question 17: A risk practitioner wants to identify potential risk events ...
Question 18: Which of the following is the BEST approach for determining ...
Question 19: It is MOST appropriate for changes to be promoted to product...
Question 20: Which of the following BEST helps to identify significant ev...
Question 21: Which of the following is the BEST method for assessing cont...
Question 22: Which of the following is the BEST approach to mitigate the ...
Question 23: A risk practitioner has just learned about new done FIRST?...
Question 24: Which of the following should be included in a risk assessme...
Question 25: Which of the following is the BEST key performance indicator...
Question 26: A control owner responsible for the access management proces...
Question 27: Which of the following is a drawback in the use of quantitat...
Question 28: A risk practitioner has been made aware of a problem in an I...
Question 29: Which of the following is the BEST key performance indicator...
Question 30: Which of the following is the MOST important objective from ...
Question 31: Which of the following management actions will MOST likely c...
Question 32: When performing a risk assessment of a new service to suppor...
Question 33: The design of procedures to prevent fraudulent transactions ...
Question 34: Who should be responsible for determining which stakeholders...
Question 35: Which of the following would provide executive management wi...
Question 36: A recent big data project has resulted in the creation of an...
Question 37: A highly regulated enterprise is developing a new risk manag...
Question 38: An organization has engaged a third party to provide an Inte...
Question 39: Which stakeholder is MOST important to include when defining...
Question 40: A risk practitioner is performing a risk assessment of recen...
Question 41: One of an organization's key IT systems cannot be patched be...
Question 42: Which of the following is the BEST indication of the effecti...
Question 43: An organization is considering adopting artificial intellige...
Question 44: Which of the following will BEST help to ensure key risk ind...
Question 45: An organization's IT infrastructure is running end-of-life s...
Question 46: It was discovered that a service provider's administrator wa...
Question 47: Which of the following is the BEST evidence that a user acco...
Question 48: A risk practitioner has been notified that an employee sent ...
Question 49: While reviewing a contract of a cloud services vendor, it wa...
Question 50: Which of the following is MOST helpful in verifying that the...
Question 51: Which of the following is the MOST important course of actio...
Question 52: Which of the following would be MOST helpful to a risk owner...
Question 53: Which of the following BEST indicates the efficiency of a pr...
Question 54: An organization has committed to a business initiative with ...
Question 55: Which of the following BEST supports the integration of IT r...
Question 56: A highly regulated organization acquired a medical technolog...
Question 57: An organization has adopted an emerging technology without f...
Question 58: Which of the following is MOST important for an organization...
Question 59: Which of the following is of GREATEST concern when uncontrol...
Question 60: A risk practitioner has been asked to advise management on d...
Question 61: Which of the following is the BEST evidence that risk manage...
Question 62: Which of the following is a risk practitioner's BEST course ...
Question 63: Management has noticed storage costs have increased exponent...
Question 64: Which of the following would BEST help to address the risk a...
Question 65: Which of the following BEST enables an organization to addre...
Question 66: Calculation of the recovery time objective (RTO) is necessar...
Question 67: The BEST way to mitigate the high cost of retrieving electro...
Question 68: Which of the following should be a risk practitioner's GREAT...
Question 69: Which element of an organization's risk register is MOST imp...
Question 70: An organization has provided legal text explaining the right...
Question 71: Which of the following is the BEST key performance indicator...
Question 72: Which of the following BEST protects organizational data wit...
Question 73: Of the following, who is accountable for ensuing the effecti...
Question 74: Senior management wants to increase investment in the organi...
Question 75: Which of the following is necessary to enable an IT risk reg...
Question 76: A change management process has recently been updated with n...
Question 77: Which of the following is MOST likely to cause a key risk in...
Question 78: Which of the following will BEST ensure that information sec...
Question 79: A risk practitioner is developing a set of bottom-up IT risk...
Question 80: Which of the following observations would be GREATEST concer...
Question 81: An IT risk practitioner has been asked to regularly report o...
Question 82: It is MOST important for a risk practitioner to have an awar...
Question 83: Which of the following approaches BEST identifies informatio...
Question 84: Which of the following should be the PRIMARY input when desi...
Question 85: Which of the following would be MOST beneficial as a key ris...
Question 86: Which of the following functions can be performed by any of ...
Question 87: Which of the following BEST measures the efficiency of an in...
Question 88: Which of the following will be MOST effective to mitigate th...
Question 89: Which of the following represents a vulnerability?...
Question 90: Which of the following tools is MOST effective in identifyin...
Question 91: The annualized loss expectancy (ALE) method of risk analysis...
Question 92: An organization learns of a new ransomware attack affecting ...
Question 93: Which of the following is a responsibility of the second lin...
Question 94: The MOST effective way to increase the likelihood that risk ...
Question 95: Which of the following would be the BEST way for a risk prac...
Question 96: Which of the following indicates an organization follows IT ...
Question 97: Which of the following is MOST important to sustainable deve...
Question 98: In a public company, which group is PRIMARILY accountable fo...
Question 99: An organization has allowed its cyber risk insurance to laps...
Question 100: Using key risk indicators (KRIs) to illustrate changes in th...
Question 101: An organization is developing a risk universe to create a ho...
Question 102: The risk associated with inadvertent disclosure of database ...
Question 103: When determining the accuracy of a key risk indicator (KRI),...
Question 104: The results of a risk assessment reveal risk scenarios with ...
Question 105: Which of the following should be of GREATEST concern to a ri...
Question 106: Which of the following presents the GREATEST challenge to ma...
Question 107: The PRIMARY purpose of vulnerability assessments is to:...
Question 108: Which of the following is the MOST effective way to validate...
Question 109: Which of the following BEST enables risk mitigation associat...
Question 110: Which of the following BEST enables a risk practitioner to e...
Question 111: Which of these documents is MOST important to request from a...
Question 112: What is the PRIMARY purpose of a business impact analysis (B...
Question 113: Which of the following is MOST commonly compared against the...
Question 114: Which of the following is a risk practitioner's BEST course ...
Question 115: Which of the following would provide the MOST helpful input ...
Question 116: Who should be responsible (of evaluating the residual risk a...
Question 117: Which of the following controls BEST helps to ensure that tr...
Question 118: Which of the following is PRIMARILY a risk management respon...
Question 119: Which of the following is the MOST important factor to consi...
Question 120: Which of the following can be used to assign a monetary valu...
Question 121: Which of the following provides the MOST useful information ...
Question 122: Which of the following is the PRIMARY objective of providing...
Question 123: An organization's risk management team wants to develop IT r...
Question 124: Which of the following would BEST help an enterprise priorit...
Question 125: Which of the following is the MOST reliable validation of a ...
Question 126: Which of the following is MOST effective in continuous risk ...
Question 127: Which of the following is the MOST important consideration w...
Question 128: An organization is measuring the effectiveness of its change...
Question 129: Accountability for a particular risk is BEST represented in ...
Question 130: Which of the following should be of GREATEST concern lo a ri...
Question 131: The MOST important measure of the effectiveness of risk mana...
Question 132: Which of the following is the MOST important consideration w...
Question 133: Which of the following is the MAIN benefit to an organizatio...
Question 134: Which of the following will BEST support management repottin...
Question 135: Which of the following is MOST important to include when rep...
Question 136: Which of the following key risk indicators (KRIs) is MOST ef...
Question 137: Which of the following BEST helps to balance the costs and b...
Question 138: Which of the following is the GREATEST benefit for an organi...
Question 139: Which of the following is the BEST key performance indicator...
Question 140: A risk practitioner has learned that the number of emergency...
Question 141: To define the risk management strategy which of the followin...
Question 142: Which of the following is the MOST appropriate key performan...
Question 143: Which of the following is the MOST important topic to cover ...
Question 144: Which of the following should be the PRIMARY consideration w...
Question 145: A risk practitioner learns of an urgent threat intelligence ...
Question 146: A company has recently acquired a customer relationship mana...
Question 147: After a high-profile systems breach at an organization s key...
Question 148: An organization is increasingly concerned about loss of sens...
Question 149: When reporting on the performance of an organization's contr...
Question 150: During the control evaluation phase of a risk assessment, it...
Question 151: Which of the following is MOST important to determine as a r...
Question 152: What should a risk practitioner do FIRST when a shadow IT ap...
Question 153: Which of the following activities should be performed FIRST ...
Question 154: It is MOST important to the effectiveness of an IT risk mana...
Question 155: Which key performance indicator (KPI) BEST measures the effe...
Question 156: During the control evaluation phase of a risk assessment, it...
Question 157: After migrating a key financial system to a new provider, it...
Question 158: Which of the following is the MOST effective way 10 identify...
Question 159: The risk associated with an asset before controls are applie...
Question 160: Prudent business practice requires that risk appetite not ex...
Question 161: An organization has identified the need to implement an asse...
Question 162: Within the three lines of defense model, the accountability ...
Question 163: The MOST significant benefit of using a consistent risk rank...
Question 164: An organization is outsourcing a key database to be hosted b...
Question 165: Which of the following would BEST help to ensure that suspic...
Question 166: The PRIMARY reason for establishing various Threshold levels...
Question 167: An online payment processor would be severely impacted if th...
Question 168: Which of the following would provide the BEST guidance when ...
Question 169: Which of the following BEST supports the communication of ri...
Question 170: An organization has established a policy prohibiting ransom ...
Question 171: Which of the following cloud service models is MOST appropri...
Question 172: An organization is implementing encryption for data at rest ...
Question 173: A risk practitioner recently discovered that personal inform...
Question 174: What is the MAIN benefit of using a top-down approach to dev...
Question 175: Which of the following provides the MOST comprehensive infor...
Question 176: Which of the following approaches would BEST help to identif...
Question 177: An organization with a large number of applications wants to...
Question 178: An organization control environment is MOST effective when:...
Question 179: Which of the following is the FIRST step in managing the sec...
Question 180: Which of the following is MOST helpful to facilitate the dec...
Question 181: Which of the following would be MOST helpful when communicat...
Question 182: An organization has established a contract with a vendor tha...
Question 183: Which of the following is the BEST approach to mitigate the ...
Question 184: Which of the following would be MOST helpful to an informati...
Question 185: Which of the following is the GREATEST concern associated wi...
Question 186: Which of the following MUST be assessed before considering r...
Question 187: Which of the following roles would be MOST helpful in provid...
Question 188: Which of the following BEST helps to mitigate risk associate...
Question 189: The MAIN reason for prioritizing IT risk responses is to ena...
Question 190: An organization has outsourced a critical process involving ...
Question 191: Which of the following provides the BEST evidence of the eff...
Question 192: An application owner has specified the acceptable downtime i...
Question 193: Which of the following is MOST important when developing ris...
Question 194: A key risk indicator (KRI) is reported to senior management ...
Question 195: Which of the following situations reflects residual risk?...
Question 196: An assessment of information security controls has identifie...
Question 197: it was determined that replication of a critical database us...
Question 198: Which of the following is the MOST appropriate action when a...
Question 199: An organization has allowed several employees to retire earl...
Question 200: Which of the following is the MOST important component of ef...
Question 201: The PRIMARY objective of a risk identification process is to...
Question 202: Which of the following is the GREATEST concern associated wi...
Question 203: What is the BEST information to present to business control ...
Question 204: Which of the following is the MOST essential factor for mana...
Question 205: Which of the following is a PRIMARY reason for considering e...
Question 206: The PRIMARY purpose of a maturity model is to compare the:...
Question 207: Which of the following is the BEST recommendation when a key...
Question 208: Which of the following is the BEST way to reduce the likelih...
Question 209: An organization operates in an environment where the impact ...
Question 210: External penetration tests MUST include:...
Question 211: An organization has an approved bring your own device (BYOD)...
Question 212: An organization recently implemented an extensive risk aware...
Question 213: Which of the following is MOST important when developing key...
Question 214: Which of the following is the BEST approach when a risk prac...
Question 215: A risk practitioner has identified that the organization's s...
Question 216: An organization is subject to a new regulation that requires...
Question 217: Which of the following poses the GREATEST risk to an organiz...
Question 218: A cote data center went offline abruptly for several hours a...
Question 219: Which of the following is the BEST way to identify changes t...
Question 220: The MOST important characteristic of an organization s polic...
Question 221: Which of the following will BEST help an organization select...
Question 222: An organization has raised the risk appetite for technology ...
Question 223: Which of the following is the BEST way for a risk practition...
Question 224: Which of the following BEST indicates how well a web infrast...
Question 225: An organization is unable to implement a multi-factor authen...
Question 226: Which of the following is the MOST important consideration w...
Question 227: Which of the following is the PRIMARY objective of maintaini...
Question 228: While reviewing the risk register, a risk practitioner notic...
Question 229: Which of the following provides the MOST useful information ...
Question 230: After an annual risk assessment is completed, which of the f...
Question 231: Which of the following scenarios presents the GREATEST risk ...
Question 232: Which of the following is MOST important for a multinational...
Question 233: Which of the following should be of MOST concern to a risk p...
Question 234: Which of the following BEST enables an organization to incre...
Question 235: Which of the following is MOST important for a risk practiti...
Question 236: Which of the following is the BEST indication of an improved...
Question 237: After identifying new risk events during a project, the proj...
Question 238: When a risk practitioner is determining a system's criticali...
Question 239: Which of the following BEST indicates that an organization h...
Question 240: A recently purchased IT application does not meet project re...
Question 241: A newly enacted information privacy law significantly increa...
Question 242: Which of the following is the MOST important enabler of effe...
Question 243: A chief information officer (CIO) has identified risk associ...
Question 244: Which of the following controls will BEST detect unauthorize...
Question 245: A maturity model will BEST indicate:...
Question 246: When assessing the maturity level of an organization's risk ...
Question 247: A violation of segregation of duties is when the same:...
Question 248: An identified high probability risk scenario involving a cri...
Question 249: When reporting risk assessment results to senior management,...
Question 250: Which of the following is the MOST effective way to incorpor...
Question 251: Several newly identified risk scenarios are being integrated...
Question 252: Which component of a software inventory BEST enables the ide...
Question 253: How should an organization approach the retention of data th...
Question 254: Which of the following is the MOST important benefit of impl...
Question 255: Winch of the following key control indicators (KCIs) BEST in...
Question 256: Which of the following is the GREATEST concern associated wi...
Question 257: Which of the following provides a risk practitioner with the...
Question 258: Which of the following is the GREATEST benefit to an organiz...
Question 259: Which of the following is the MOST common concern associated...
Question 260: Which of the following provides the MOST useful information ...
Question 261: An organization retains footage from its data center securit...
Question 262: Which of the following is the BEST control to minimize the r...
Question 263: Which of the following BEST facilitates the identification o...
Question 264: Which of the following would be- MOST helpful to understand ...
Question 265: When developing risk scenario using a list of generic scenar...
Question 266: Avoiding a business activity removes the need to determine:...
Question 267: Changes in which of the following would MOST likely cause a ...
Question 268: Which of the following is the PRIMARY reason for sharing ris...
Question 269: Which of the following is MOST important to the integrity of...
Question 270: Which of the following is the FIRST step in risk assessment?...
Question 271: During a risk assessment of a financial institution, a risk ...
Question 272: Which of the following is the BEST way to confirm whether ap...
Question 273: Which of the following elements of a risk register is MOST l...
Question 274: Which of the following describes the relationship between ri...
Question 275: During testing, a risk practitioner finds the IT department'...
Question 276: Which of the following IT controls is MOST useful in mitigat...
Question 277: Which of the following is MOST important to understand when ...
Question 278: Which of the following is the BEST source for identifying ke...
Question 279: To communicate the risk associated with IT in business terms...
Question 280: Which of the following should a risk practitioner recommend ...
Question 281: Which of the following helps ensure compliance with a nonrep...
Question 282: Which of the following is MOST important to consider before ...
Question 283: Which of the following provides the BEST assurance of the ef...
Question 284: Which of the following is the BEST approach when a risk trea...
Question 285: Which of the following risk scenarios would be the GREATEST ...
Question 286: To enable effective risk governance, it is MOST important fo...
Question 287: Which of the following is the GREATEST concern related to th...
Question 288: An organization has determined that risk is not being adequa...
Question 289: Which of the following is the PRIMARY benefit of using a ris...
Question 290: The GREATEST concern when maintaining a risk register is tha...
Question 291: When of the following is the BEST key control indicator (KCI...
Question 292: The BEST way to justify the risk mitigation actions recommen...
Question 293: The PRIMARY goal of a risk management program is to:...
Question 294: Which of the following emerging technologies is frequently u...
Question 295: Which of the following is MOST useful when communicating ris...
Question 296: Which of the following will MOST improve stakeholders' under...
Question 297: A global organization is considering the transfer of its cus...
Question 298: Which of the following should be implemented to BEST mitigat...
Question 299: Which of the following provides the MOST helpful reference p...
Question 300: Which of the following would be of GREATEST assistance when ...
Question 301: Which of the following is MOST useful when performing a quan...
Question 302: An IT department originally planned to outsource the hosting...
Question 303: Which of the following is the PRIMARY reason to establish th...
Question 304: Establishing and organizational code of conduct is an exampl...
Question 305: A risk assessment has been completed on an application and r...
Question 306: A business delegates its application data management to the ...
Question 307: An organization's HR department has implemented a policy req...
Question 308: Which of the following should be a risk practitioner's NEXT ...
Question 309: When creating a program to manage data privacy risk, which o...
Question 310: A MAJOR advantage of using key risk indicators (KRIs) is tha...
Question 311: Which of the following is the PRIMARY reason to adopt key co...
Question 312: Improvements in the design and implementation of a control w...
Question 313: To reduce costs, an organization is combining the second and...
Question 314: During the internal review of an accounts payable process, a...
Question 315: During an internal IT audit, an active network account belon...
Question 316: Which of the following is the MOST appropriate key risk indi...
Question 317: Which of the following is the MOST effective way to integrat...
Question 318: Which of the following would BEST facilitate the maintenance...
Question 319: Which of the following provides the MOST helpful information...
Question 320: The PRIMARY reason for communicating risk assessment results...
Question 321: Which of the following is the BEST way to protect sensitive ...
Question 322: Which of the following is MOST helpful to ensure effective s...
Question 323: When an organization's disaster recovery plan (DRP) has a re...
Question 324: Which of the following is the BEST way to ensure ongoing con...
Question 325: Which of the following would MOST effectively reduce risk as...
Question 326: Due to a change in business processes, an identified risk sc...
Question 327: Which of the following would be MOST important for a risk pr...
Question 328: Which of the following trends would cause the GREATEST conce...
Question 329: The PRIMARY benefit of using a maturity model is that it hel...
Question 330: Which of the following facilitates a completely independent ...
Question 331: The PRIMARY reason to have risk owners assigned to entries i...
Question 332: Which of the following is the PRIMARY benefit of identifying...
Question 333: Which of the following is MOST important to include in a ris...
Question 334: The cost of maintaining a control has grown to exceed the po...
Question 335: Which of the following should a risk practitioner review FIR...
Question 336: Which of the following scenarios presents the GREATEST risk ...
Question 337: When presenting risk, the BEST method to ensure that the ris...
Question 338: Which of the following s MOST likely to deter an employee fr...
Question 339: IT risk assessments can BEST be used by management:...
Question 340: The BEST key performance indicator (KPI) to measure the effe...
Question 341: An organization has outsourced its backup and recovery proce...
Question 342: Which of the following is the PRIMARY responsibility of a co...
Question 343: Which of the following is the MOST important key performance...
Question 344: An organization has detected unauthorized logins to its clie...
Question 345: The BEST key performance indicator (KPI) for monitoring adhe...
Question 346: Which of the following should be done FIRST when developing ...
Question 347: Which of the following is MOST important for successful inci...
Question 348: Which of the following practices would be MOST effective in ...
Question 349: Which of the following should be used as the PRIMARY basis f...
Question 350: A risk practitioner notes control design changes when compar...
Question 351: A PRIMARY advantage of involving business management in eval...
Question 352: Which of the following is the BEST key performance indicator...
Question 353: Which of the following is MOST useful for measuring the exis...
Question 354: Which of the following BEST enables the integration of IT ri...
Question 355: The PRIMARY goal of conducting a business impact analysis (B...
Question 356: An organization's recovery team is attempting to recover cri...
Question 357: Which of the following BEST enables the identification of tr...
Question 358: Of the following, who is BEST suited to assist a risk practi...
Question 359: Which of the following is the MOST relevant information to i...
Question 360: An organization wants to transfer risk by purchasing cyber i...
Question 361: Which of the following is the FIRST step when conducting a b...
Question 362: When testing the security of an IT system, il is MOST import...
Question 363: Which of the following BEST indicates the effectiveness of a...
Question 364: An organization automatically approves exceptions to securit...
Question 365: What is the BEST approach for determining the inherent risk ...
Question 366: Which of the following is the PRIMARY reason for an organiza...
Question 367: An organization's Internet-facing server was successfully at...
Question 368: Which of the following is the MOST important driver of an ef...
Question 369: An engineer has been assigned to conduct data restoration af...
Question 370: A risk practitioner is utilizing a risk heat map during a ri...
Question 371: Which of the following BEST provides an early warning that n...
Question 372: Which of the following should be considered FIRST when creat...
Question 373: A new software package that could help mitigate risk in an o...
Question 374: The PRIMARY benefit associated with key risk indicators (KRl...
Question 375: An organization allows programmers to change production syst...
Question 376: Which of the following methods would BEST contribute to iden...
Question 377: An organization has implemented a system capable of comprehe...
Question 378: Which of the following is the BEST way to determine the pote...
Question 379: Which of the following would be considered a vulnerability?...
Question 380: Which of the following is the MOST important consideration w...
Question 381: Which of the following situations would BEST justify escalat...
Question 382: Which of the following is the MOST important reason to valid...
Question 383: Which of the following is MOST helpful to understand the con...
Question 384: Which of the following should be the FIRST consideration whe...
Question 385: A risk heat map is MOST commonly used as part of an IT risk ...
Question 386: Which of the following BEST enforces access control for an o...
Question 387: Which of the following is the MOST effective way for a large...
Question 388: When confirming whether implemented controls are operating e...
Question 389: Which of the following is MOST important for maintaining the...
Question 390: Which type of cloud computing deployment provides the consum...
Question 391: Read" rights to application files in a controlled server env...
Question 392: Which of the following should be the PRIMARY basis for estab...
Question 393: Which of the following should be considered FIRST when asses...
Question 394: The BEST way to demonstrate alignment of the risk profile wi...
Question 395: Which of the following is MOST likely to introduce risk for ...
Question 396: When updating the risk register after a risk assessment, whi...
Question 397: Which of the following is the MAIN benefit of involving stak...
Question 398: Employees are repeatedly seen holding the door open for othe...
Question 399: A risk practitioner is involved in a comprehensive overhaul ...
Question 400: Which of the following should be of MOST concern to a risk p...
Question 401: The BEST indication that risk management is effective is whe...
Question 402: Which of the following is the GREATEST benefit of centralizi...
Question 403: The GREATEST benefit of including low-probability, high-impa...
Question 404: Which of the following is MOST important to review when an o...
Question 405: An organization has decided to use an external auditor to re...
Question 406: When of the following 15 MOST important when developing a bu...
Question 407: Who is accountable for the process when an IT stakeholder op...
Question 408: An organization has procured a managed hosting service and j...
Question 409: Which of the following is the MOST useful information for pr...
Question 410: Which of the following should be done FIRST upon learning th...
Question 411: Which of the following will BEST help to ensure that informa...
Question 412: An IT department has provided a shared drive for personnel t...
Question 413: Which of the following is the BEST Key control indicator KCO...
Question 414: The implementation of a risk treatment plan will exceed the ...
Question 415: Which of the following is the MOST effective key performance...
Question 416: Which of the following is the BEST indicator of an effective...
Question 417: Which of the following would BEST help secure online financi...
Question 418: Which of the following is the MOST effective control to main...
Question 419: A new policy has been published to forbid copying of data on...
Question 420: Which of the following is a specific concern related to mach...
Question 421: When of the following provides the MOST tenable evidence tha...
Question 422: A control process has been implemented in response to a new ...
Question 423: Which of the following is the FIRST step when developing a b...
Question 424: Which of the following BEST indicates the condition of a ris...
Question 425: While evaluating control costs, management discovers that th...
Question 426: After undertaking a risk assessment of a production system, ...
Question 427: Which of the following is the BEST way to quantify the likel...
Question 428: An organization has updated its acceptable use policy to mit...
Question 429: Which of the following BEST helps to ensure disaster recover...
Question 430: Which of the following is the PRIMARY responsibility of the ...
Question 431: An organization has outsourced its customer management datab...
Question 432: Implementing which of the following will BEST help ensure th...
Question 433: The PRIMARY objective of collecting information and reviewin...
Question 434: A monthly payment report is generated from the enterprise re...
Question 435: Which of the following is the GREATEST concern when using ar...
Question 436: Which of We following is the MOST effective control to addre...
Question 437: When establishing leading indicators for the information sec...
Question 438: Participants in a risk workshop have become focused on the f...
Question 439: Which of the following would BEST indicate to senior managem...
Question 440: Which of the following BEST promotes commitment to controls?...
Question 441: Which of the following is MOST helpful in developing key ris...
Question 442: An IT license audit has revealed that there are several unli...
Question 443: Which of the following BEST facilitates the identification o...
Question 444: Which of the following is the PRIMARY reason for a risk prac...
Question 445: A business impact analysis (BIA) enables an organization to ...
Question 446: Which type of indicators should be developed to measure the ...
Question 447: Which of the following is the MOST important key risk indica...
Question 448: Which of the following will BEST help in communicating strat...
Question 449: Which of the following is MOST helpful in providing a high-l...
Question 450: Who is MOST important lo include in the assessment of existi...
Question 451: Which of the following is the MOST important requirement for...
Question 452: Which of the following should be the risk practitioner's FIR...
Question 453: Which of the following is BEST used to aggregate data from m...
Question 454: Business management is seeking assurance from the CIO that I...
Question 455: A peer review of a risk assessment finds that a relevant thr...
Question 456: An information security audit identified a risk resulting fr...
Question 457: Which of the following BEST protects an organization against...
Question 458: Which of the following is the MOST important course of actio...
Question 459: Which of the following is MOST important for a risk practiti...
Question 460: What is senior management's role in the RACI model when task...
Question 461: The purpose of requiring source code escrow in a contractual...
Question 462: Which of the following would prompt changes in key risk indi...
Question 463: Which of the following BEST represents a critical threshold ...
Question 464: An organization needs to send files to a business partner to...
Question 465: A systems interruption has been traced to a personal USB dev...
Question 466: An organization's financial analysis department uses an in-h...
Question 467: What is the PRIMARY reason to periodically review key perfor...
Question 468: Which of the following is MOST critical to the design of rel...
Question 469: The MAIN reason for creating and maintaining a risk register...
Question 470: Which of the following methods is an example of risk mitigat...
Question 471: A business impact analysis (BIA) has documented the duration...
Question 472: In response to the threat of ransomware, an organization has...
Question 473: In the three lines of defense model, a PRIMARY objective of ...
Question 474: During a recent security framework review, it was discovered...
Question 475: Which of the following is the MOST important characteristic ...
Question 476: Which of the following BEST indicates that risk management i...
Question 477: After a risk has been identified, who is in the BEST positio...
Question 478: Which of the following is the BEST measure of the effectiven...
Question 479: Which of the following is the MOST important objective of re...
Question 480: An organization uses one centralized single sign-on (SSO) co...
Question 481: For no apparent reason, the time required to complete daily ...
Question 482: An incentive program is MOST likely implemented to manage th...
Question 483: Which of the following is the PRIMARY accountability for a c...
Question 484: A business unit has implemented robotic process automation (...
Question 485: Which of the following would BEST ensure that identified ris...
Question 486: What is the GREATEST concern with maintaining decentralized ...
Question 487: Which of the following should be the PRIMARY goal of develop...
Question 488: Which of the following is the BEST method to maintain a comm...
Question 489: A risk practitioner is collaborating with key stakeholders t...
Question 490: The MAIN purpose of reviewing a control after implementation...
Question 491: A risk practitioner has received an updated enterprise risk ...
Question 492: Which of the following is the MOST important characteristic ...
Question 493: An organization's risk practitioner learns a new third-party...
Question 494: An organization is implementing Zero Trust architecture to i...
Question 495: When reviewing a report on the performance of control proces...
Question 496: Which of the following is the BEST way to promote adherence ...
Question 497: Which of the following is a risk practitioner's BEST course ...
Question 498: Which of the following is the MOST useful indicator to measu...
Question 499: Which of the following provides the MOST up-to-date informat...
Question 500: Which of the following would be MOST effective in monitoring...
Question 501: A key risk indicator (KRI) indicates a reduction in the perc...
Question 502: Which of the following is the MAIN reason to continuously mo...
Question 503: Within the three lines of defense model, the responsibility ...
Question 504: The software version of an enterprise's critical business ap...
Question 505: The MOST important reason to monitor key risk indicators (KR...
Question 506: Recent penetration testing of an organization's software has...
Question 507: Which of the following is the MOST important consideration w...
Question 508: Which of the following is the MOST comprehensive resource fo...
Question 509: To enable effective integration of IT risk scenarios and ERM...
Question 510: A department allows multiple users to perform maintenance on...
Question 511: Key risk indicators (KRIs) are MOST useful during which of t...
Question 512: Risk mitigation procedures should include:...
Question 513: It is MOST important that security controls for a new system...
Question 514: Which of the following BEST enables effective risk-based dec...
Question 515: Which of the following is the MOST critical consideration wh...
Question 516: Which of the following is a risk practitioner's MOST importa...
Question 517: Which of the following is the PRIMARY risk management respon...
Question 518: Which of the following is the MOST important component in a ...
Question 519: If preventive controls cannot be Implemented due to technolo...
Question 520: Which of the following would be MOST useful when measuring t...
Question 521: Which of the following is the BEST way to validate privilege...
Question 522: Which of the following is MOST important when conducting a p...
Question 523: Which of the following is the GREATEST risk associated with ...
Question 524: The risk associated with an asset after controls are applied...
Question 525: A vendor's planned maintenance schedule will cause a critica...
Question 526: Which of me following is MOST helpful to mitigate the risk a...
Question 527: A penetration test reveals several vulnerabilities in a web-...
Question 528: The PRIMARY advantage of implementing an IT risk management ...
Question 529: Which of the following BEST assists in justifying an investm...
Question 530: An IT control gap has been identified in a key process. Who ...
Question 531: The PRIMARY purpose of using a framework for risk analysis i...
Question 532: Which of the following BEST prevents control gaps in the Zer...
Question 533: During the risk assessment of an organization that processes...
Question 534: Which of the following would be MOST useful to senior manage...
Question 535: An organization is considering outsourcing user administrati...
Question 536: A risk practitioner has determined that a key control does n...
Question 537: Which of the following scenarios is MOST likely to cause a r...
Question 538: Which of the following is the MOST important benefit of repo...
Question 539: An organization recently implemented new technologies that e...
Question 540: Upon learning that the number of failed back-up attempts con...
Question 541: A robotic process automation (RPA) project has implemented n...
Question 542: A risk owner should be the person accountable for:...
Question 543: Which of the following should be the PRIMARY objective of pr...
Question 544: Which of the following IT key risk indicators (KRIs) provide...
Question 545: Which of the following should be done FIRST when developing ...
Question 546: Which of the following is the PRIMARY reason for a risk prac...
Question 547: Performing a background check on a new employee candidate be...
Question 548: Which of the following BEST indicates that security requirem...
Question 549: From a risk management perspective, which of the following i...
Question 550: Which of the following is MOST important for senior manageme...
Question 551: A risk practitioner has been asked to assess the risk associ...
Question 552: An organization has decided to commit to a business activity...
Question 553: Which of the following changes would be reflected in an orga...
Question 554: Which of the following provides the MOST important informati...
Question 555: As pan of business continuity planning, which of the followi...
Question 556: Of the following, who should be responsible for determining ...
Question 557: Which of the following should be the PRIMARY concern when ch...
Question 558: When reporting to senior management on changes in trends rel...
Question 559: Which of the following BEST indicates whether security aware...
Question 560: A risk practitioner shares the results of a vulnerability as...
Question 561: Following a significant change to a business process, a risk...
Question 562: Which of the following is the BEST way to validate the resul...
Question 563: An organization is reviewing a contract for a Software as a ...
Question 564: A risk practitioner has discovered a deficiency in a critica...
Question 565: Which of the following will be MOST effective in uniquely id...
Question 566: In the three lines of defense model, a PRIMARY objective of ...
Question 567: During an organization's simulated phishing email campaign, ...
Question 568: Which of the following statements BEST describes risk appeti...
Question 569: Which of the following is the MOST important consideration w...
Question 570: A risk practitioner is reviewing accountability assignments ...
Question 571: An organization is considering allowing users to access comp...
Question 572: Which of the following key risk indicators (KRIs) provides t...
Question 573: A risk practitioner learns that the organization s industry ...
Question 574: The BEST way for an organization to ensure that servers are ...
Question 575: Which of the following is the MOST important success factor ...
Question 576: A key risk indicator (KRI) that incorporates data from exter...
Question 577: An organization mandates the escalation of a service ticket ...
Question 578: Which of the following is the PRIMARY purpose for ensuring s...
Question 579: Who is accountable for authorizing application access in a c...
Question 580: Which of the following is the MOST important benefit of key ...
Question 581: Which of the following is performed after a risk assessment ...
Question 582: Which of the following is the BEST way to determine the ongo...
Question 583: Which of the following activities is a responsibility of the...
Question 584: When of the following is the MOST significant exposure when ...
Question 585: Which of the following is the MOST important consideration w...
Question 586: Which of the following is MOST helpful to review when identi...
Question 587: Key risk indicators (KRIs) BEST support risk treatment when ...
Question 588: A global organization is planning to collect customer behavi...
Question 589: A risk practitioner is organizing a training session lo comm...
Question 590: Which of the following is the PRIMARY purpose of a risk regi...
Question 591: Implementing which of the following controls would BEST redu...
Question 592: An organization's risk tolerance should be defined and appro...
Question 593: The BEST way to test the operational effectiveness of a data...
Question 594: Which of the following is the PRIMARY objective for automati...
Question 595: Before implementing instant messaging within an organization...
Question 596: A risk practitioner has identified that the agreed recovery ...
Question 597: Which of the following is the BEST indicator of executive ma...
Question 598: Who is PRIMARILY accountable for risk treatment decisions?...
Question 599: A company has located its computer center on a moderate eart...
Question 600: A multinational organization is considering implementing sta...
Question 601: Mitigating technology risk to acceptable levels should be ba...
Question 602: Which of the following is a KEY outcome of risk ownership?...
Question 603: Continuous monitoring of key risk indicators (KRIs) will:...
Question 604: Which of the following management action will MOST likely ch...
Question 605: A risk practitioner has reviewed new international regulatio...
Question 606: Which of the following is the MOST important consideration f...
Question 607: Which of the following is the MOST important consideration f...
Question 608: Which of the following is the PRIMARY reason to use key cont...
Question 609: The BEST reason to classify IT assets during a risk assessme...
Question 610: Which of the following is MOST important when developing key...
Question 611: Which of the following practices MOST effectively safeguards...
Question 612: A risk practitioner is reporting on an increasing trend of r...
Question 613: The PRIMARY focus of an ongoing risk awareness program shoul...
Question 614: An organizations chief technology officer (CTO) has decided ...
Question 615: Which of the following deficiencies identified during a revi...
Question 616: The risk appetite for an organization could be derived from ...
Question 617: Which of the following is the ULTIMATE objective of utilizin...
Question 618: Controls should be defined during the design phase of system...
Question 619: Which of the following is MOST important to consider when de...
Question 620: Which of the following is the PRIMARY reason to update a ris...
Question 621: A recent risk workshop has identified risk owners and respon...
Question 622: Which of the following is the MOST important factor affectin...
Question 623: Which of the following is the BEST approach when a risk prac...
Question 624: Which of the following is MOST helpful in preventing risk ev...
Question 625: An organization uses a web application hosted by a cloud ser...
Question 626: An organization has initiated a project to launch an IT-base...
Question 627: A risk practitioner notices a trend of noncompliance with an...
Question 628: An organization maintains independent departmental risk regi...
Question 629: Which of the following is MOST important to consider when de...
Question 630: What is the PRIMARY benefit of risk monitoring?...
Question 631: An organization recently configured a new business division ...
Question 632: Which of the following is the MOST important outcome of a bu...
Question 633: A risk practitioner identifies an increasing trend of employ...
Question 634: Which of the following is the BEST method to identify unnece...
Question 635: A risk practitioner is performing a risk assessment of recen...
Question 636: Recovery the objectives (RTOs) should be based on...
Question 637: Which of the following is the BEST response when a potential...
Question 638: Which of the following should an organization perform to for...
Question 639: Which of the following is MOST helpful in identifying new ri...
Question 640: A risk practitioner has identified that the agreed recovery ...
Question 641: An organization has decided to implement a new Internet of T...
Question 642: Which of the following describes the relationship between Ke...
Question 643: Which of the following MOST effectively limits the impact of...
Question 644: Who is ULTIMATELY accountable for the confidentiality of dat...
Question 645: Which of the following is the PRIMARY reason to perform peri...
Question 646: Which of the following is the MOST cost-effective way to tes...
Question 647: When determining which control deficiencies are most signifi...
Question 648: An organization discovers significant vulnerabilities in a r...
Question 649: Which of the following criteria associated with key risk ind...
Question 650: Which of the following is MOST important to consider when as...
Question 651: The MAIN purpose of selecting a risk response is to....
Question 652: An organization operates in an environment where reduced tim...
Question 653: Which of the following is the PRIMARY reason for an organiza...
Question 654: A recent internal risk review reveals the majority of core I...
Question 655: Which of the following is the MOST efficient method for moni...
Question 656: A control for mitigating risk in a key business area cannot ...
Question 657: During a review of the asset life cycle process, a risk prac...
Question 658: An organization plans to implement a new Software as a Servi...
Question 659: Which of the following provides the MOST useful input to the...
Question 660: A financial institution has identified high risk of fraud in...
Question 661: Which of the following would BEST mitigate the ongoing risk ...
Question 662: The BEST way to validate that a risk treatment plan has been...
Question 663: Which of the following is the MOST important consideration w...
Question 664: An organization is considering the adoption of an aggressive...
Question 665: During the creation of an organization's IT risk management ...
Question 666: A risk practitioner is defining metrics for security threats...
Question 667: Which of the following BEST indicates that additional or imp...
Question 668: A trusted third-party service provider has determined that t...
Question 669: Which of the following should be the PRIMARY driver for the ...
Question 670: Which of the following is the BEST control to detect an adva...
Question 671: Which of the following is the GREATEST benefit of using IT r...
Question 672: A risk practitioner is reviewing a vendor contract and finds...
Question 673: To mitigate the risk of using a spreadsheet to analyze finan...
Question 674: From a business perspective, which of the following is the M...
Question 675: A risk practitioner's BEST guidance to help an organization ...
Question 676: A vulnerability assessment of a vendor-supplied solution has...
Question 677: Which of the following should be a risk practitioner's NEXT ...
Question 678: Which of the following controls are BEST strengthened by a c...
Question 679: Which of the following is MOST important for a risk practiti...
Question 680: A risk practitioner has been notified of a social engineerin...
Question 681: Which of the following BEST enables a risk practitioner to f...
Question 682: Which of the following BEST indicates the effective implemen...
Question 683: Which of the following would MOST likely cause management to...
Question 684: Which strategy employed by risk management would BEST help t...
Question 685: Which of the following is the MOST important responsibility ...
Question 686: Which of the following statements BEST illustrates the relat...
Question 687: The PRIMARY basis for selecting a security control is:...
Question 688: The MOST important reason to aggregate results from multiple...
Question 689: An organization uses a vendor to destroy hard drives. Which ...
Question 690: Which of the following issues should be of GREATEST concern ...
Question 691: Winch of the following can be concluded by analyzing the lat...
Question 692: A risk assessment indicates the residual risk associated wit...
Question 693: Which of the following provides the MOST useful information ...
Question 694: Which of the following should be management's PRIMARY consid...
Question 695: Which of the following should be the PRIMARY recipient of re...
Question 696: Which of the following is the MOST important consideration w...
Question 697: An IT risk practitioner has been tasked to engage key stakeh...
Question 698: Which of the following should be the PRIMARY consideration f...
Question 699: A risk assessment has identified increased losses associated...
Question 700: A risk practitioner recently discovered that sensitive data ...
Question 701: An organization has decided to postpone the assessment and t...
Question 702: Which stakeholders are PRIMARILY responsible for determining...