Which of the following would be MOST helpful when estimating the likelihood of negative events?
Which of the following will BEST quantify the risk associated with malicious users in an organization?
Which of the following risk management practices BEST facilitates the incorporation of IT risk scenarios into the enterprise-wide risk register?
Which of the following is MOST effective in continuous risk management process improvement?
A recent vulnerability assessment of a web-facing application revealed several weaknesses. Which of the following should be done NEXT to determine the risk exposure?
Which of the following provides the BEST protection for Internet of Things (loT) devices that are accessed within an organization?
The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of:
Which of the following observations from a third-party service provider review would be of GREATEST concern to a risk practitioner?
To define the risk management strategy which of the following MUST be set by the board of directors?
Which of the following is the BEST criterion to determine whether higher residual risk ratings in the risk register should be accepted?
Which of the following roles would provide the MOST important input when identifying IT risk scenarios?
A department has been granted an exception to bypass the existing approval process for purchase orders. The risk practitioner should verify the exception has been approved by which of the following?
A risk practitioner has been asked to evaluate a new cloud-based service to enhance an organization ' s access management capabilities. When is the BEST time for the risk practitioner to provide opinions on control strength?
Within the three lines of defense model, the accountability for the system of internal control resides with:
Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (Pll)?
Which of the following is the BEST metric to demonstrate the effectiveness of an organization ' s patch management process?
Which of the following is MOST important to include when reporting the effectiveness of risk management to senior management?
An updated report from a trusted research organization shows that attacks have increased in the organization ' s industry segment. What should be done FIRST to integrate this data into risk assessments?
Which of the following is MOST important for an organization to continuously manage after implementing a Zero Trust security model?
Which of the following is the PRIMARY objective of aggregating the impact of IT risk scenarios and reflecting the results in the enterprise risk register?
A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner ' s FIRST course of action?
An organization is unable to implement a multi-factor authentication requirement until the next fiscal year due to budget constraints. Consequently, a policy exception must be submitted. Which of the following is MOST important to include in the analysis of the exception?
Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?
A risk practitioner is organizing risk awareness training for senior management. Which of the following is the MOST important topic to cover in the training session?
When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?
Which of the following BEST prevents unauthorized access to customer personal data transmitted to third-party service providers?
A risk practitioner has been asked to propose a risk acceptance framework for an organization. Which of the following is the MOST important consideration for the risk practitioner to address in the framework?
An organization has experienced a cyber-attack that exposed customer personally identifiable information (Pll) and caused extended outages of network services. Which of the following stakeholders are MOST important to include in the cyber response team to determine response actions?
Which of the following should be the PRIMARY recipient of reports showing the
progress of a current IT risk mitigation project?
A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
Which of the following should be the PRIMARY basis for deciding whether to disclose information related to risk events that impact external stakeholders?
In addition to the risk register, what should a risk practitioner review to develop an understanding of the organization ' s risk profile?
Which of the following is the PRIMARY purpose of creating and documenting control procedures?
Which of the following changes would be reflected in an organization ' s risk profile after the failure of a critical patch implementation?
Which of the following is the BEST recommendation of a risk practitioner for an organization that recently changed its organizational structure?
Which of the following would BEST enable a risk-based decision when considering the use of an emerging technology for data processing?
An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization ' s risk appetite and tolerance, which of the following is the risk practitioner ' s BEST recommendation?
Which of the following should be the PRIMARY focus of an independent review of a risk management process?
During a risk assessment of a financial institution, a risk practitioner discovers that tellers can initiate and approve transactions of significant value. This team is also responsible for ensuring transactions are recorded and balances are reconciled by the end of the day. Which of the following is the risk practitioner ' s BEST recommendation to mitigate the associated risk?
Which of the following is the MOST important reason to restrict access to the risk register on a need-to-know basis?
An organization has built up its cash reserves and has now become financially able to support additional risk while meeting its objectives. What is this change MOST likely to impact?
Which of the following is MOST useful when performing a quantitative risk assessment?
Which of the following would be MOST helpful to an information security management team when allocating resources to mitigate exposures?
A risk practitioner wants to identify potential risk events that affect the continuity of a critical business process. Which of the following should the risk practitioner do FIRST?
What is the MOST effective approach to promote ethical decision-making in a global organization?
When assigning control ownership, it is MOST important to verify that the owner has accountability for:
A risk practitioner ' s BEST guidance to help an organization develop relevant risk scenarios is to ensure the scenarios are:
What is the PRIMARY role of the application owner when changes are being introduced into an existing environment?
An organization ' s risk practitioner learns a new third-party system on the corporate network has introduced vulnerabilities that could compromise corporate IT systems. What should the risk practitioner do FIRST?
To minimize the risk of a potential acquisition being exposed externally, an organization has selected a few key employees to be engaged in the due diligence process. A member of the due diligence team realizes a close acquaintance is a high-ranking IT professional at a subsidiary of the company about to be acquired. What is the BEST course of action for this team member?
TESTED 30 May 2026