Which of the following is the BEST control for mitigating risk when a critical customer-facing application has been vulnerable to recent credential-stuffing attacks?
ABlock IP addresses from foreign countries.
BIncrease monitoring of account usage.
CImplement multi-factor authentication.
DIncrease password complexity requirements.
Which of the following offers the MOST useful input for developing IT risk scenarios?
ARecent external IT audit findings
BInternal security events and incidents
CHistory of IT risk policy noncompliance
DInternal and external risk factors
Which of the following is the PRIMARY input for designing IT controls?
AInternal and external risk reports
BOutcome of control self-assessments
CBenchmark of industry standards
DRecommendations from IT risk experts
Which of the following provides the BEST evidence of an effective internal control environment?
AIndependent audit results
BRegular stakeholder briefings
CAdherence to governing policies
DRisk assessment results
QuestionQ6
Risk Response and Reporting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Risk Assessment
QuestionQ8
Risk Response and Reporting
QuestionQ9
Risk Assessment
QuestionQ10
Risk Assessment
QuestionQ11
Risk Assessment
QuestionQ12
Governance
QuestionQ13
Governance
QuestionQ14
Technology and Security
QuestionQ15
Governance
QuestionQ16
Risk Assessment
QuestionQ17
Risk Assessment
QuestionQ18
Risk Response and Reporting
QuestionQ19
Risk Response and Reporting
QuestionQ20
Risk Response and Reporting
QuestionQ21
Risk Assessment
QuestionQ22
Governance
QuestionQ23
Risk Response and Reporting
QuestionQ24
Risk Assessment
QuestionQ25
Governance
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
An audit finds that several terminated employee accounts still retain access. Which of the following should be the FIRST step to mitigate the risk?
APerform a risk assessment
BDisable user access
CPerform root cause analysis
DDevelop an access control policy
The PRIMARY reason for prioritizing risk scenarios is to:
Afacilitate risk response decisions.
Bsupport risk response tracking.
Cassign risk ownership.
Dprovide an enterprise-wide view of risk.
A control process was implemented in response to a new regulatory requirement, but it has significantly reduced productivity. Which of the following is the BEST way to address this concern?
AAbsorb the loss in productivity.
BEscalate the issue to senior management.
CRequest a waiver to the requirements.
DRemove the control to accommodate business objectives.
Because of budget limitations, an organization cannot implement encryption for all databases. Which of the following provides the MOST useful information for identifying high-risk databases where encryption should be applied?
ABusiness impact assessment (BIA)
BUnsupported database list
CPenetration test results
DData classification scheme
Which of the following is the BEST method for identifying high-impact risk types?
AQualitative risk analysis
BDelphi technique
CFailure modes and effects analysis
DQuantitative risk analysis
Which of the following provides the MOST comprehensive input to the risk-assessment process for the effects of system downtime?
ABusiness continuity plan (BCP) testing results
BRecovery point objective (RPO)
CBusiness impact analysis (BIA) results
DRecovery time objective (RTO)
You are the project manager for the GHT project. You want to conduct a post-project review. What is the BEST time for you and the project development team to perform this review to assess the project’s effectiveness?
AProject is completed and the system has been in production for a sufficient time period
BDuring the project
CImmediately after the completion of the project
DProject is about to complete
You are working with a vendor on your project. A stakeholder has requested a project change that will add value to the project deliverables. The vendor you are working with on the project will be affected by this change. What system can help you introduce and execute the stakeholder’s change request with the vendor?
AContract change control system
BScope change control system
CCost change control system
DSchedule change control system
Which of the following should be the PRIMARY consideration when implementing controls to monitor user activity logs?
ABuilding correlations between logs collected from different sources
BEnsuring the control is proportional to the risk
CImplementing log analysis tools to automate controls
DEnsuring availability of resources for log analysis
Which activity would BEST allow a risk manager to verify stakeholders’ scopes of responsibility in IT risk scenarios?
ATabletop exercise
BRisk assessment
CVulnerability assessment
DInterviews with IT staff
Which of the following fall within the phases of risk identification and evaluation?
Each correct answer represents a complete solution.
Choose three
AMaintain a risk profile
BCollecting data
CAnalyzing risk
DApplying controls
Which of the following is MOST important for a risk practitioner to review when conducting an IT risk assessment?
AInformation system control weaknesses and audit findings
BInformation system assets and associated threats
CThe organization's historical threats and monetary loss
DPublished records of loss from peer organizations
Among several risk responses, which response is used for negative risk events?
AShare
BEnhance
CExploit
DAccept
Which of the following provides the BEST indication that a business continuity program is effective?
ABusiness continuity tests are performed successfully and issues are addressed.
BBusiness continuity and disaster recovery plans are regularly updated.
CBusiness impact analyses (BIAs) are reviewed and updated in a timely manner.
DBusiness units are familiar with the business continuity plans (BCPs) and process.
When reporting IT-risk trend changes to senior management, which of the following is MOST important?
AMaturity
BMateriality
CConfidentiality
DTransparency
Suppose you work at Techmart Inc., which sells various products through its website. Because of recent losses, you are trying to identify the most important risks to the Website. Based on feedback from several experts, you have developed a list. You now want to prioritize these risks. In which category would you place the risk involving modification of the Website by unauthorized parties?
APing Flooding Attack
BWeb defacing
CDenial of service attack
DFTP Bounce Attack
Reviewing which of the following provides the BEST indication of an organization's risk tolerance?
ARisk sharing strategy
BRisk assessments
CRisk transfer agreements
DRisk policies
The cost to maintain a control has increased beyond the potential loss. Which option BEST describes this circumstance?
AEffective risk management
BOptimized control management
COver-controlled environment
DInsufficient risk tolerance
Which of the following may be inferred from one data point on a risk heat map?
ARisk appetite
BRisk magnitude
CRisk response
DRisk tolerance
Which of the following is the BEST indicator of an effective risk management program?
ARisk action plans are approved by senior management
BMitigating controls are designed and implemented
CResidual risk is within the organizational risk appetite
DRisk is recorded and tracked in the risk register
Community Discussion