Which of the following is the PRIMARY role of the first line of defense with respect to information security policies?
A risk practitioner is organizing risk awareness training for senior management. Which of the following is the MOST important topic to cover in the training session?
Which of the following will BEST help to ensure that information system controls are effective?
During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?
Which of the following is MOST helpful to facilitate the decision of recovery priorities in a disaster situation?
Which of the following is MOST important for management to consider when deciding whether to invest in an IT initiative that exceeds management ' s risk appetite?
Which of the following should be the PRIMARY goal of developing information security metrics?
What should be the PRIMARY objective of updating a risk awareness program in response to a steady rise in cybersecurity threats across the industry?
Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?
Which of the following has the GREATEST impact on backup policies for a system supporting a critical process?
Which of the following BEST supports the management of identified risk scenarios?
Which of the following is MOST important to compare against the corporate risk profile?
Mitigating technology risk to acceptable levels should be based PRIMARILY upon:
A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner ' s GREATEST concern?
Which of the following is the MOST important information to be communicated during security awareness training?
Winch of the following key control indicators (KCIs) BEST indicates whether security requirements are identified and managed throughout a project He cycle?
Which of the following, who should be PRIMARILY responsible for performing user entitlement reviews?
An IT license audit has revealed that there are several unlicensed copies of co be to:
A risk practitioner has reviewed new international regulations and realizes the new regulations will affect the organization. Which of the following should be the risk practitioner ' s NEXT course of
action?
Which of the following is the BEST way to promote adherence to the risk tolerance level set by management?
Which of the following is the BEST indicator of the effectiveness of IT risk management processes?
A risk practitioner learns that the organization s industry is experiencing a trend of rising security incidents. Which of the following is the BEST course of action?
Which of the following BEST enables a risk practitioner to plan a vulnerability assessment that aligns to detailed organizational requirements?
Which of the following is the PRIMARY advantage of having a single integrated business continuity plan (BCP) rather than each business unit developing its own BCP?
Which of the following will BEST help to improve an organization ' s risk culture?
Prior to selecting key performance indicators (KPIs), itis MOST important to ensure:
After a risk has been identified, who is in the BEST position to select the appropriate risk treatment option?
Which of the following BEST indicates the effectiveness of anti-malware software?
Which of the following is the PRIMARY reason to perform periodic vendor risk assessments?
Which of the following is MOST important to the effectiveness of a senior oversight committee for risk monitoring?
Which of the following BEST enables effective risk reporting to the board of directors?
Which of the following should a risk practitioner recommend FIRST when a risk assessment identifies the exposure of a significant number of personal customer records in a database?
Which of the following indicators measures the performance of IT configuration management?
Which of the following is MOST important for an organization to update following a change in legislation requiring notification to individuals impacted by data breaches?
Which of the following BEST enables detection of ethical violations committed by employees?
When of the following is the BEST key control indicator (KCI) to determine the effectiveness of en intrusion prevention system (IPS)?
Which of the following is the MOST effective way to help ensure future risk levels do not exceed the organization ' s risk appetite?
The MOST important objective of information security controls is to:
Which of the following is the BEST recommendation to address recent IT risk trends that indicate social engineering attempts are increasing in the organization?
A risk practitioner has been notified that an employee sent an email in error containing customers ' personally identifiable information (Pll). Which of the following is the risk practitioner ' s BEST course of action?
Which of the following BEST indicates that a control has been implemented successfully?
An organization is participating in an industry benchmarking study that involves providing customer transaction records for analysis Which of the following is the MOST important control to ensure the privacy of customer information?
Which of the following is MOST helpful in identifying loss magnitude during risk analysis of a new system?
After the implementation of a blockchain solution, a risk practitioner discovers noncompliance with new industry regulations. Which of the following is the MOST important course of actionpriorto informing senior management?
Which of the following is the PRIMARY reason for managing emerging risk?
The PRIMARY objective of the board of directors periodically reviewing the risk profile is to help ensure:
Which of the following would provide the MOST reliable evidence of the effectiveness of security controls implemented for a web application?
An organization has implemented a policy requiring staff members to take a minimum of five consecutive days ' leave per year to mitigate the risk of malicious insider activities. Which of the following is the BEST key performance indicator (KPI) of the effectiveness of this policy?
Which of the following is MOST important for a risk practitioner to consider when analyzing the risk associated with migrating to a new cloud service provider?
Which of the following is the BEST key control indicator (KCI) for measuring the security of a blockchain network?
TESTED 25 Sep 2026