Which of the following is MOST helpful to review when assessing the risk exposure associated with ransomware?
-
A
Potentially impacted business processes
-
B
Recent changes in the environment
-
C
Key performance indicators (KPIs)
-
D
Suspected phishing events
Reveal answer details
Close answer details
Correct answerA
ExplanationRansomware exposure depends heavily on which business processes could be disrupted and the resulting operational impact. Reviewing potentially impacted business processes identifies critical dependencies and consequences, providing the basis for evaluating the severity of the risk rather than only isolated events or indicators.
Which of the following is the MOST effective way to help ensure accountability for managing risk?
-
A
Assign process owners to key risk areas.
-
B
Obtain independent risk assessments.
-
C
Assign incident response action plan responsibilities.
-
D
Create accurate process narratives.
Reveal answer details
Close answer details
Correct answerA
ExplanationAssigning process owners to key risk areas places accountability with individuals who have authority over the activities where risk is created and managed. They can make treatment decisions, ensure controls operate, and track remaining exposure. Independent assessments provide assurance, while action-plan assignments and process narratives document narrower tasks without establishing continuing ownership of the risk area.
Which of the following would present the GREATEST challenge when assigning accountability for control ownership?
-
A
Weak governance structures
-
B
Senior management scrutiny
-
C
Complex regulatory environment
-
D
Unclear reporting relationships
Reveal answer details
Close answer details
Correct answerD
ExplanationControl ownership requires a clear line of authority so one party can be held responsible for design, operation, monitoring, and remediation. Unclear reporting relationships make it difficult to determine who has decision rights, creating overlapping responsibility or unowned gaps. That ambiguity directly obstructs accountability even when controls and requirements are known.
Which strategy employed by risk management would BEST help to prevent internal fraud?
-
A
Require control owners to conduct an annual control certification.
-
B
Conduct regular internal and external audits on the systems supporting financial reporting.
-
C
Ensure segregation of duties are implemented within key systems or processes.
-
D
Require the information security officer to review unresolved incidents.
Reveal answer details
Close answer details
Correct answerC
ExplanationSegregation of duties divides authorization, execution, recording, and review so one person cannot complete and conceal a fraudulent transaction alone. Implementing this separation within key systems or processes therefore prevents internal fraud by requiring participation or oversight from another party. Audits and incident reviews primarily detect issues after activity occurs.
Which of the following is a PRIMARY reason for considering existing controls during initial risk assessment?
-
A
To determine the inherent risk level
-
B
To determine the acceptable risk level
-
C
To determine the current risk level
-
D
To determine the desired risk level
Reveal answer details
Close answer details
Correct answerC
ExplanationExisting controls have already changed the organization's exposure, so considering their effectiveness is necessary to determine the current risk level. Inherent risk is assessed before controls, while acceptable and desired levels are management targets rather than measurements of present exposure. The initial assessment needs the current level to support comparison and response decisions.
An organization has implemented a new operating system on all desktops and laptops that enables only necessary services to minimize business risk. Which of the following documents would address this implementation?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA standard defines mandatory, repeatable technical requirements for systems, such as allowing only necessary operating system services. Applying the requirement to all desktops and laptops creates a consistent configuration expectation. A policy provides higher-level intent, while a procedure would describe the steps used to implement or verify the setting.
The PRIMARY benefit of using a maturity model is that it helps to evaluate the:
-
A
capability to implement new processes
-
B
evolution of process improvements
-
C
degree of compliance with policies and procedures
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationA maturity model defines progressive levels of process capability and discipline. Comparing current practices with those levels allows an organization to evaluate how its processes evolve as improvements are introduced and institutionalized. Compliance checks whether rules are followed, while maturity focuses on the development and sustainability of process performance.
Which of the following should be of GREATEST concern to a risk practitioner reviewing an organization's disaster recovery plan (DRP)?
-
A
Risk scenarios used for the plan were last tested two years ago.
-
B
The IT steering committee determined the application recovery priorities.
-
C
The disaster recovery plan (DRP) does not identify a hot site.
-
D
The call list in the plan was last updated a year ago.
Reveal answer details
Close answer details
Correct answerA
ExplanationRisk scenarios are foundational assumptions for the disaster recovery plan, and testing determines whether planned responses work under those conditions. If the scenarios have not been tested for two years, changes in systems, dependencies, or operations may leave recovery arrangements unvalidated. A particular site type is not required when another suitable recovery strategy meets business needs.
A deficient control has been identified which could result in great harm to an organization should a low frequency threat event occur. When communicating the associated risk to senior management the risk practitioner should explain:
-
A
mitigation plans for threat events should be prepared in the current planning period.
-
B
this risk scenario is equivalent to more frequent but lower impact risk scenarios.
-
C
the current level of risk is within tolerance.
-
D
an increase in threat events could cause a loss sooner than anticipated.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe control deficiency leaves the organization exposed to severe consequences even though the threat event currently has low frequency. If threat events become more frequent, the expected interval before one exploits the weakness decreases, so a major loss can occur sooner than planned. This communicates how a change in likelihood affects the timing of the high-impact exposure without minimizing its potential harm.
Question 10
Single choice
Which of the following is a risk practitioner's MOST important course of action after learning that an organization's industry peers have experienced an increase in ransomware attacks?
-
A
Recommend additional preventive controls to reduce residual risk.
-
B
Document this scenario as a risk event for further risk analysis.
-
C
Propose risk acceptance until the organization is directly affected.
-
D
Raise a security incident to proactively prevent similar attacks.
Reveal answer details
Close answer details
Correct answerB
ExplanationIncreased ransomware activity among industry peers is a change in the external threat environment, not an incident within the organization. The organization should document the scenario as a risk event and analyze its relevance, likelihood, impact, and current controls. Preventive controls or acceptance should be considered only after that analysis establishes the exposure.
Question 11
Single choice
After a risk has been identified, who is in the BEST position to select the appropriate risk treatment option?
-
A
-
B
The business process owner
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe risk owner is accountable for the exposure and its potential effect on business objectives. That accountability places the owner in the best position to choose whether to accept, avoid, transfer, or mitigate the risk within authorized limits. A risk practitioner can analyze and advise, while a control owner is responsible for particular controls.
Question 12
Single choice
Which of the following statements in an organization's current risk profile report is cause for further action by senior management?
-
A
Key performance indicator (KPI) trend data is incomplete.
-
B
New key risk indicators (KRIs) have been established.
-
C
Key performance indicators (KPIs) are outside of targets.
-
D
Key risk indicators (KRIs) are lagging.
Reveal answer details
Close answer details
Correct answerC
ExplanationKPIs outside their targets indicate that business processes or outcomes are not performing at the expected level. Because sustained performance failure can affect objectives and alter the risk profile, senior management should investigate and direct corrective action. Establishing new KRIs is normal monitoring activity, while incomplete or lagging information describes measurement limitations rather than a confirmed target breach.
Question 13
Single choice
Which of the following is MOST helpful to understand the consequences of an IT risk event?
-
A
-
B
Historical trend analysis
-
C
-
D
Business impact analysis (BIA)
Reveal answer details
Close answer details
Correct answerD
ExplanationConsequences are measured in terms of disruption and harm to business activities, not merely the technical sequence that caused an event. A business impact analysis identifies affected processes, dependencies, and the effects of interruption over time. Fault tree and root cause analysis examine causes, while historical trends describe prior patterns rather than complete business impact.
Question 14
Single choice
A risk practitioner has discovered a deficiency in a critical system that cannot be patched. Which of the following should be the risk practitioner's FIRST course of action?
-
A
Report the issue to internal audit.
-
B
Submit a request to change management.
-
C
Conduct a risk assessment.
-
D
Review the business impact assessment.
Reveal answer details
Close answer details
Correct answerC
ExplanationBecause the critical system cannot be patched, the practitioner must first assess the resulting risk by considering exposure, likelihood, impact, and existing or compensating controls. That assessment determines the significance of the deficiency and provides the basis for selecting an appropriate response. Escalation or change activity before this evaluation would occur without a measured understanding of the risk.
Question 15
Single choice
While reviewing the risk register, a risk practitioner notices that different business units have significant variances in inherent risk for the same risk scenario. Which of the following is the BEST course of action?
-
A
Update the risk register with the average of residual risk for both business units.
-
B
Review the assumptions of both risk scenarios to determine whether the variance is reasonable.
-
C
Update the risk register to ensure both risk scenarios have the highest residual risk.
-
D
Request that both business units conduct another review of the risk.
Reveal answer details
Close answer details
Correct answerB
ExplanationDifferent inherent risk ratings for the same scenario can be valid if the business units used different operating assumptions or exposure conditions. Reviewing both sets of assumptions determines whether the variance reflects real differences or inconsistent analysis. Averaging or forcing a common rating would conceal the issue, while requesting another review without first locating the cause adds little value.
Question 16
Single choice
Which of the following BEST represents a critical threshold value for a key control indicator (KCI)?
-
A
The value at which control effectiveness would fail
-
B
Thresholds benchmarked to peer organizations
-
C
A typical operational value
-
D
A value that represents the intended control state
Reveal answer details
Close answer details
Correct answerA
ExplanationA critical KCI threshold marks the boundary at which a control can no longer be considered effective. Reaching that value signals control failure or an unacceptable loss of performance and therefore calls for action. A typical operating value or intended state describes normal or desired performance, while a peer benchmark may not reflect the organization's own control requirements.
Question 17
Single choice
Which of the following BEST enforces access control for an organization that uses multiple cloud technologies?
-
A
Senior management support of cloud adoption strategies
-
B
Creation of a cloud access risk management policy
-
C
Adoption of a cloud access security broker (CASB) solution
-
D
Expansion of security information and event management (SIEM) to cloud services
Reveal answer details
Close answer details
Correct answerC
ExplanationA cloud access security broker provides a control point through which cloud usage and access policies can be applied across multiple cloud technologies. This directly supports consistent access enforcement, whereas a policy defines expectations and SIEM expansion primarily collects and analyzes security events.
Question 18
Single choice
When creating a program to manage data privacy risk, which of the following is MOST important to ensure that the program is successful?
-
A
Compliance with industry frameworks
-
B
Alignment with applicable legal and regulatory requirements
-
C
Approval of mitigating and compensating controls
-
D
Adoption of mission and vision statements
Reveal answer details
Close answer details
Correct answerB
ExplanationA privacy program must address the legal and regulatory obligations that apply to the organization's data, locations, and processing activities. Alignment with those requirements establishes mandatory privacy outcomes and provides the basis for policies and controls. Industry frameworks can guide implementation, but they do not replace binding obligations applicable to the organization.
Question 19
Single choice
Which of the following is the MOST important consideration when selecting digital signature software?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationA digital signature should bind a signer to signed content in a manner that supports nonrepudiation. This allows recipients to establish who signed and prevents the signer from credibly denying the act later. Availability, accuracy, and completeness are useful general information qualities, but they do not express the distinctive assurance a digital signature is selected to provide.
Question 20
Single choice
Which of the following would MOST effectively protect financial records from ransomware attacks?
-
A
Enforcement of encryption at rest for backups
-
B
Multi-factor authentication (MFA) on storage points
-
C
Classifying and encrypting data on backups
-
D
Immutable storage and backups
Reveal answer details
Close answer details
Correct answerD
ExplanationImmutable storage and backups prevent protected recovery copies from being altered or deleted during their retention period. Because ransomware commonly attempts to encrypt or destroy accessible records and backups, immutability preserves a trustworthy restoration point. Encryption protects confidentiality but does not by itself prevent ransomware from corrupting encrypted files.
Question 21
Single choice
Which of the following is the PRIMARY purpose of periodically reviewing an organization's risk profile?
-
A
Align business objectives with risk appetite.
-
B
Enable risk-based decision making.
-
C
Design and implement risk response action plans.
-
D
Update risk responses in the risk register
Reveal answer details
Close answer details
Correct answerB
ExplanationA risk profile changes as threats, business conditions, controls, and exposures change. Periodic review provides decision-makers with a current view of risk, enabling risk-based choices about priorities and resources. Updating individual responses may follow, but the broader purpose is informed decision making.
Question 22
Single choice
Which of the following is MOST important to review when determining whether a potential IT service provider's control environment is effective?
-
A
-
B
-
C
Key performance indicators (KPIs)
-
D
Service level agreements (SLAs)
Reveal answer details
Close answer details
Correct answerA
ExplanationAn independent audit report provides objective evaluation of whether the service provider's controls are suitably designed and operating as assessed during the covered period. Independence makes it more reliable for evaluating the provider's control environment than the provider's own self-assessment. KPIs and SLAs describe performance commitments or results, not the overall effectiveness of relevant controls.
Question 23
Single choice
An organization wants to assess the maturity of its internal control environment. The FIRST step should be to:
-
A
validate control process execution.
-
B
determine if controls are effective.
-
C
identify key process owners.
-
D
conduct a baseline assessment.
Reveal answer details
Close answer details
Correct answerD
ExplanationA baseline assessment establishes the current maturity level of the internal control environment against which later improvements can be measured. Without that starting point, the organization cannot reliably identify maturity gaps or demonstrate progress. Validation of execution and testing of effectiveness provide evidence about controls, but they should be organized within an initial view of the present state.
Question 24
Single choice
Which of the following is accountable for the management of IT risk within an organization?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationSenior management is accountable for managing IT risk because it directs organizational priorities, allocates resources, and ensures that risk remains aligned with business objectives. Business process owners manage risks within their areas, while oversight and assurance functions monitor or evaluate risk practices. Those supporting roles do not replace management's organization-wide accountability.
Question 25
Single choice
Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA mature enterprise architecture aligns business processes, information, applications, and technology through coherent designs and standards. This reduces unnecessary duplication and complexity, improves interoperability, and enables more efficient operations across the enterprise. Policy consistency, audit readiness, and compliance may improve as secondary effects, but operational efficiency is the broadest direct benefit.
Question 26
Single choice
In an organization dependent on data analytics to drive decision-making, which of the following would BEST help to minimize the risk associated with inaccurate data?
-
A
Establishing an intellectual property agreement
-
B
Evaluating each of the data sources for vulnerabilities
-
C
Periodically reviewing big data strategies
-
D
Benchmarking to industry best practice
Reveal answer details
Close answer details
Correct answerB
ExplanationAnalytical decisions inherit integrity risk from the data supplied to them. Evaluating each data source for vulnerabilities identifies weaknesses that could permit inaccurate, incomplete, or improperly altered data to enter the analysis. Strategy reviews and benchmarking operate at a broader level, while an intellectual property agreement addresses ownership rights rather than the accuracy of decision data.
Question 27
Single choice
Which of the following is the BEST way to detect zero-day malware on an end user's workstation?
-
A
-
B
Database activity monitoring
-
C
-
D
File integrity monitoring
Reveal answer details
Close answer details
Correct answerD
ExplanationZero-day malware may not match signatures already known to an antivirus program. File integrity monitoring instead detects unauthorized or unexpected changes to files, so suspicious activity can be identified from its effect on the workstation without relying solely on a known signature. Database monitoring and firewall logs observe different layers and may not reveal local file modification.
Question 28
Single choice
Which of the following is the MOST effective way to minimize the impact associated with the loss of key employees?
-
A
Maintain and publish a RACI chart.
-
B
Promote incentive programs.
-
C
Perform succession planning.
-
D
Develop a robust onboarding program.
Reveal answer details
Close answer details
Correct answerC
ExplanationSuccession planning identifies potential replacements for key roles and prepares them to assume essential responsibilities. This preserves leadership, knowledge, and operational continuity when a key employee departs. A RACI chart documents responsibilities, while incentives and onboarding do not ensure that a qualified successor is ready for a critical position.
Question 29
Single choice
Which of the following is the MOST important consideration when sharing risk management updates with executive management?
-
A
Including trend analysis of risk metrics
-
B
Using an aggregated view of organizational risk
-
C
Relying on key risk indicator (KRI) data
-
D
Ensuring relevance to organizational goals
Reveal answer details
Close answer details
Correct answerD
ExplanationExecutive management uses risk updates to make decisions about organizational direction and resources. Ensuring the information is relevant to organizational goals connects risk exposure and treatment to the outcomes executives are accountable for. Aggregation, trends, and KRI data can improve presentation, but they add value only when they explain consequences for those goals.
Question 30
Single choice
Performing a background check on a new employee candidate before hiring is an example of what type of control?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA background check occurs before employment access and responsibilities are granted. Its purpose is to identify concerns early and prevent an unsuitable candidate from creating avoidable exposure, making it a preventive control. A detective control would identify an event after it occurred, while a corrective control would restore conditions after a problem was found.
Question 31
Single choice
An organization's stakeholders are unable to agree on appropriate risk responses. Which of the following would be the BEST course of action?
-
A
Escalate to senior management.
-
B
Identify a risk transfer option.
-
C
-
D
Benchmark with similar industries.
Reveal answer details
Close answer details
Correct answerA
ExplanationWhen stakeholders cannot agree on a risk response, the decision should be escalated to senior management, which has the authority to balance business objectives, risk appetite, and resource commitments. Reassessment is useful only if the underlying analysis needs revision. Benchmarking does not resolve internal accountability, and selecting risk transfer would impose one treatment without authorized agreement.
Question 32
Single choice
A global organization has implemented an application that does not address all privacy requirements across multiple jurisdictions. Which of the following risk responses has the organization adopted with regard to privacy requirements?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe organization proceeded with the application even though some privacy requirements remain unmet across its jurisdictions. By retaining that known exposure rather than avoiding, transferring, or fully mitigating it, the organization has adopted risk acceptance. Implementation of the application demonstrates that the residual privacy risk remains with the organization.
Question 33
Single choice
When reporting on the performance of an organization's control environment including which of the following would BEST inform stakeholders risk decision-making?
-
A
The audit plan for the upcoming period
-
B
Spend to date on mitigating control implementation
-
C
A report of deficiencies noted during controls testing
-
D
A status report of control deployment
Reveal answer details
Close answer details
Correct answerC
ExplanationDeficiencies found during controls testing reveal where controls failed, were absent, or did not operate as intended. This directly informs stakeholders about remaining exposure and supports decisions on remediation, acceptance, or further analysis. Spending and deployment status report inputs or progress, while an upcoming audit plan does not show current control performance.
Question 34
Single choice
Which of the following should be determined FIRST when a new security vulnerability is made public?
-
A
Whether the affected technology is used within the organization
-
B
Whether the affected technology is Internet-facing
-
C
What mitigating controls are currently in place
-
D
How pervasive the vulnerability is within the organization
Reveal answer details
Close answer details
Correct answerA
ExplanationThe first step is to determine whether the affected technology is used within the organization. If it is not present, the published vulnerability does not create direct exposure there. Once presence is confirmed, the organization can determine whether it is Internet-facing, how broadly it is deployed, and which mitigating controls apply.
Question 35
Single choice
Which of the following would MOST likely cause a risk practitioner to reassess risk scenarios?
-
A
A change in the risk management policy
-
B
A major security incident
-
C
A change in the regulatory environment
-
D
An increase in intrusion attempts
Reveal answer details
Close answer details
Correct answerB
ExplanationA major security incident is direct evidence that a significant threat scenario has occurred and that prior assumptions about threats, vulnerabilities, impacts, or controls may no longer hold. Because it can materially change the organization's actual exposure, the affected scenarios should be reassessed to reflect the demonstrated event and its consequences.
Question 36
Single choice
The BEST indication that risk management is effective is when risk has been reduced to meet:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationRisk appetite expresses the amount and type of risk the organization is willing to pursue or retain in support of its objectives. Risk management is effective when treatment reduces exposure to a level consistent with that appetite. Capacity is the maximum risk the organization can bear, so merely staying below capacity does not demonstrate alignment with its chosen risk position.
Question 37
Single choice
Which of the following would present the GREATEST challenge for a risk practitioner during a merger of two organizations?
-
A
Variances between organizational risk appetites
-
B
Different taxonomies to categorize risk scenarios
-
C
Disparate platforms for governance, risk, and compliance (GRC) systems
-
D
Dissimilar organizational risk acceptance protocols
Reveal answer details
Close answer details
Correct answerA
ExplanationRisk appetite guides how much and what type of risk each organization is willing to accept while pursuing objectives. Material differences between the merging organizations affect strategy, investment, control priorities, and acceptance decisions across the combined enterprise. Taxonomies, systems, and protocols can be harmonized operationally, but conflicting appetites require fundamental leadership alignment.
Question 38
Single choice
Which of the following would MOST likely result in agreement on accountability for risk scenarios?
-
A
Using a facilitated risk management workshop
-
B
Relying on generic risk scenarios
-
C
Relying on external IT risk professionals
-
D
Distributing predefined scenarios for review
Reveal answer details
Close answer details
Correct answerA
ExplanationA facilitated risk management workshop brings relevant stakeholders together to discuss scenarios, business impacts, authority, and responsibility. The facilitator can resolve differing interpretations and guide the group toward explicit agreement on accountability. Distributing generic or predefined scenarios does not provide the same interactive resolution of ownership issues.
Question 39
Single choice
Which of the following is the PRIMARY objective of maintaining an information asset inventory?
-
A
To provide input to business impact analyses (BIAs)
-
B
To protect information assets
-
C
To facilitate risk assessments
-
D
To manage information asset licensing
Reveal answer details
Close answer details
Correct answerB
ExplanationAn organization cannot consistently protect information assets unless it knows which assets exist and can associate them with appropriate handling and safeguarding requirements. Maintaining the inventory supplies that visibility and supports ownership, classification, and protection activities. It can also inform a BIA or risk assessment, but those are supporting uses toward the broader objective of protecting the assets.
Question 40
Single choice
Which organization is implementing a project to automate the purchasing process, including the modification of approval controls. Which of the following tasks is lie responsibility of the risk practitioner*?
-
A
Verify that existing controls continue to properly mitigate defined risk
-
B
Test approval process controls once the project is completed
-
C
Update the existing controls for changes in approval processes from this project
-
D
Perform a gap analysis of the impacted control processes
Reveal answer details
Close answer details
Correct answerD
ExplanationAutomating purchasing and modifying approvals can create differences between required controls and the controls present in the redesigned process. The risk practitioner's role is to perform a gap analysis of the impacted control processes so those differences and their risk implications are identified. Updating or testing controls belongs to the functions responsible for implementation or assurance.
Question 41
Single choice
Who should be responsible for strategic decisions on risk management?
-
A
Chief information officer (CIO)
-
B
Executive management team
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationStrategic risk decisions determine enterprise priorities, appetite, resource commitments, and the balance between risk and business objectives. These matters span organizational functions and therefore belong to the executive management team. A CIO or process owner has a narrower operational domain, while an audit committee provides oversight rather than directing risk management strategy.
Question 42
Single choice
A risk practitioner is concerned with potential data loss in the event of a breach at a hosted third-party provider. Which of the following is the BEST way to mitigate this risk?
-
A
Include an indemnification clause in the provider's contract.
-
B
Monitor provider performance against service level agreements (SLAs).
-
C
Purchase cyber insurance to protect against data breaches.
-
D
Ensure appropriate security controls are in place through independent audits.
Reveal answer details
Close answer details
Correct answerD
ExplanationIndependent audits can verify that appropriate security controls at the hosted provider are present and operating, directly reducing the likelihood of a breach and resulting data loss. SLA monitoring focuses on agreed service performance. Indemnification and cyber insurance may transfer financial consequences, but they do not prevent or limit the underlying security event.
Question 43
Single choice
An organization has raised the risk appetite for technology risk. The MOST likely result would be:
-
A
-
B
higher risk management cost
-
C
-
D
lower risk management cost.
Reveal answer details
Close answer details
Correct answerD
ExplanationRaising risk appetite means management is willing to accept a greater level of technology risk. The organization may therefore need fewer or less intensive risk treatments, leading to lower risk management cost. Appetite does not itself change inherent risk, and reducing controls would not be expected to decrease residual risk.
Question 44
Single choice
What should a risk practitioner do FIRST upon learning a risk treatment owner has implemented a different control than what was specified in the IT risk action plan?
-
A
Seek approval from the control owner.
-
B
Update the action plan in the risk register.
-
C
Reassess the risk level associated with the new control.
-
D
Validate that the control has an established testing method.
Reveal answer details
Close answer details
Correct answerC
ExplanationA different control may reduce the risk by a different amount than the measure specified in the action plan. Reassessing the risk level associated with the new control determines its effect on likelihood, impact, and residual exposure before records or approvals are updated. A testing method supports later assurance, but the immediate issue is whether the substituted treatment achieves an acceptable risk outcome.
Question 45
Single choice
Which of the following is MOST important to ensure when continuously monitoring the performance of a client-facing application?
-
A
Objectives are confirmed with the business owner.
-
B
Control owners approve control changes.
-
C
End-user acceptance testing has been conducted.
-
D
Performance information in the log is encrypted.
Reveal answer details
Close answer details
Correct answerA
ExplanationContinuous monitoring is useful only when measured performance is tied to the application's intended business outcomes. Confirming objectives with the business owner establishes the relevant targets, thresholds, and service expectations against which results should be evaluated. Testing and change approvals concern implementation, while log encryption does not determine what performance should be monitored.
Question 46
Single choice
A recent audit identified high-risk issues in a business unit though a previous control self-assessment (CSA) had good results. Which of the following is the MOST likely reason for the difference?
-
A
The audit had a broader scope than the CSA.
-
B
The CSA was not sample-based.
-
C
The CSA did not test control effectiveness.
-
D
The CSA was compliance-based, while the audit was risk-based.
Reveal answer details
Close answer details
Correct answerC
ExplanationA control self-assessment can produce favorable results without establishing that controls actually operate as intended. Testing control effectiveness examines whether controls are functioning in practice and achieving their objectives. If the CSA omitted that testing, ineffective controls could remain undetected until the audit performed more substantive evaluation and identified the high-risk issues.
Question 47
Single choice
An organization is developing a risk universe to create a holistic view of its overall risk profile. Which of the following is the GREATEST barrier to achieving the initiative's objectives?
-
A
Lack of cross-functional risk assessment workshops within the organization
-
B
Lack of common understanding of the organization's risk culture
-
C
Lack of quantitative methods to aggregate the total risk exposure
-
D
Lack of an integrated risk management system to aggregate risk scenarios
Reveal answer details
Close answer details
Correct answerB
ExplanationA risk universe depends on risks being understood and interpreted consistently across functions. Without a common understanding of the organization's risk culture, units may classify, evaluate, communicate, and escalate similar exposures differently, preventing a holistic profile. Workshops, quantitative methods, and integrated systems can support aggregation, but they cannot correct fundamentally inconsistent risk perspectives.
Question 48
Single choice
Which of the following is the GREATEST benefit of centralizing IT systems?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationCentralized IT systems consolidate information and processing, making risk data easier to collect and present through a common reporting structure. This supports consistent enterprise-level reporting and reduces fragmented views from separate systems. Classification, monitoring, and identification remain necessary activities, but the clearest broad benefit of centralization is producing unified risk information for decision-makers.
Question 49
Single choice
An organization's IT department wants to complete a proof of concept (POC) for a security tool. The project lead has asked for approval to use the production data for testing purposes as it will yield the best results. Which of the following is the risk practitioner's BEST recommendation?
-
A
Accept the risk of using the production data to ensure accurate results.
-
B
Assess the risk of using production data for testing before making a decision.
-
C
Benchmark against what peer organizations are doing with POC testing environments.
-
D
Deny the request, as production data should not be used for testing purposes.
Reveal answer details
Close answer details
Correct answerB
ExplanationProduction data may improve test realism, but its sensitivity and exposure within a proof of concept must be evaluated before use. Assessing likelihood, impact, handling conditions, and available controls provides the basis for an informed decision. Immediate acceptance or denial bypasses that assessment, and peer benchmarking does not determine the organization's own production-data risk.
Question 50
Single choice
An organization is subject to a new regulation that requires nearly real-time recovery of its services following a disruption. Which of the following is the BEST way to manage the risk in this situation?
-
A
Move redundant IT infrastructure to a closer location.
-
B
Obtain insurance and ensure sufficient funds are available for disaster recovery.
-
C
Review the business continuity plan (BCP) and align it with the new business needs.
-
D
Outsource disaster recovery services to a third-party IT service provider.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe new regulation changes the required recovery outcome, so the business continuity plan must be reviewed and aligned with the nearly real-time business need. This establishes updated recovery objectives, responsibilities, and coordinated continuity requirements before selecting a solution. Relocation, insurance, or outsourcing addresses only a particular method and may not satisfy the revised requirement.
Question 51
Single choice
Which of the following is the MOST important consideration for the board and senior leadership regarding the organization's approach to risk management for emerging technologies?
-
A
Ensuring the organization follows risk management industry best practices
-
B
Ensuring IT risk scenarios are updated and include emerging technologies
-
C
Ensuring the risk framework and policies are suitable for emerging technologies
-
D
Ensuring threat intelligence services are used to gather data about emerging technologies
Reveal answer details
Close answer details
Correct answerC
ExplanationThe board and senior leadership must ensure the organization's governance foundation can address the different uncertainties introduced by emerging technologies. Suitable risk frameworks and policies define how those risks are identified, owned, assessed, treated, and reported. Updating individual scenarios and gathering threat data are useful activities, but they depend on an adequate governing structure.
Question 52
Single choice
An internal risk assessment revealed multiple critical security findings for a newly commissioned testing environment. Which of the following should the risk practitioner do FIRST?
-
A
-
B
Update the IT risk register.
-
C
-
D
Set dates for the next review.
Reveal answer details
Close answer details
Correct answerC
ExplanationMultiple critical findings require prompt communication to IT management because management must understand the exposure and authorize or coordinate an appropriate response. Defining mitigation steps before this notification could bypass decision authority, while register updates and future review dates can follow the initial escalation.
Question 53
Single choice
Which of the following would BEST help to address the risk associated with malicious outsiders modifying application data?
-
A
Multi-factor authentication
-
B
Role-based access controls
-
C
Activation of control audits
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe scenario concerns malicious outsiders, so the first protective boundary is establishing that a person seeking access is genuinely authorized. Multi-factor authentication requires more than one authentication factor, reducing the ability of an outsider using compromised credentials to reach and modify application data. Role-based controls govern permitted actions after authentication but do not by themselves prevent outsider impersonation.
Question 54
Single choice
Implementing which of the following will BEST help ensure that systems comply with an established baseline before deployment?
-
A
-
B
Continuous monitoring and alerting
-
C
-
D
Access controls and active logging
Reveal answer details
Close answer details
Correct answerC
ExplanationConfiguration management defines approved settings, controls changes, and verifies that system configurations conform to the established baseline before release. This makes baseline compliance part of deployment control. Vulnerability scans identify weaknesses, while monitoring, logging, and access controls primarily operate as detective or protective measures after configurations exist.
Question 55
Single choice
Following a significant change to a business process, a risk practitioner believes the associated risk has been reduced. The risk practitioner should advise the risk owner to FIRST
-
A
review the key risk indicators.
-
B
-
C
-
D
reallocate risk response resources.
Reveal answer details
Close answer details
Correct answerB
ExplanationA belief that risk has decreased must be supported by analysis after the significant process change. Conducting a risk analysis evaluates the revised likelihood, impact, and control conditions before any formal record or resource decision is changed. Updating the register or reallocating response resources first would treat an unconfirmed reduction as established.
Question 56
Single choice
Which of the following is MOST important information to review when developing plans for using emerging technologies?
-
A
-
B
-
C
-
D
Organizational strategic plan
Reveal answer details
Close answer details
Correct answerD
ExplanationPlans for emerging technologies should begin with the organizational strategic plan because technology adoption must advance business direction and intended outcomes. This alignment determines which opportunities deserve investment and which risks are relevant. The IT environment, IT plan, and risk register then provide supporting constraints and implementation information.
Question 57
Single choice
An organization is considering the adoption of an aggressive business strategy to achieve desired growth From a risk management perspective what should the risk practitioner do NEXT?
-
A
Identify new threats resorting from the new business strategy
-
B
Update risk awareness training to reflect current levels of risk appetite and tolerance
-
C
Inform the board of potential risk scenarios associated with aggressive business strategies
-
D
Increase the scale for measuring impact due to threat materialization
Reveal answer details
Close answer details
Correct answerA
ExplanationAn aggressive business strategy may introduce activities, dependencies, or exposures that were not part of the prior risk landscape. The next risk management step is to identify new threats resulting from that strategy so relevant scenarios can be assessed. Reporting, training, or changing impact scales before identifying those threats would not establish what new risk must be managed.
Question 58
Single choice
Which of the following should be the MOST important consideration when determining controls necessary for a highly critical information system?
-
A
The number of threats to the system
-
B
The organization's available budget
-
C
The number of vulnerabilities to the system
-
D
The level of acceptable risk to the organization
Reveal answer details
Close answer details
Correct answerD
ExplanationControl requirements should be driven by the amount of residual risk the organization is prepared to accept. The acceptable risk level provides the target against which control strength and coverage can be judged for the critical system. Counts of threats and vulnerabilities inform exposure analysis, while budget constrains implementation, but none of those establishes the required risk reduction outcome.
Question 59
Single choice
Which of the following is the BEST approach for selecting controls to minimize risk?
-
A
Industry best practice review
-
B
-
C
-
D
Control-effectiveness evaluation
Reveal answer details
Close answer details
Correct answerC
ExplanationControl selection should balance the expected reduction in risk against the resources required to obtain and operate the control. Cost-benefit analysis provides that decision basis by comparing the value of reduced exposure with implementation and operating cost. Risk assessment identifies the exposure, and effectiveness evaluation measures a control, but neither alone establishes whether a particular control is economically justified.
Question 60
Single choice
Which of the following is the PRIMARY reason to compare the business impact analysis (BIA) against the organization ' s business continuity plan (BCP)?
-
A
The results of the BIA quantify the BCP objectives and supporting technology for each operational area.
-
B
The BCP provides detailed information on alternative facilities to use in case of business interruptions.
-
C
The results of the BIA quantify the cost of the technology environment needed to restart each operational area.
-
D
The BCP provides the backup and restoration procedures to follow in case of business interruptions.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe BIA identifies critical operations, measures disruption impacts, and establishes recovery requirements. Comparing it with the BCP confirms that the plan's objectives and supporting technology for each operational area match those quantified business needs. Facility and restoration details are plan components, but they must first be driven by BIA results.
Question 61
Single choice
After several security incidents resulting in significant financial losses, IT management has decided to outsource the security function to a third party that provides 24/7 security operation services. Which risk response option has management implemented?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationOutsourcing 24/7 security operations introduces an additional capability intended to reduce the likelihood or impact of further security incidents. That is risk mitigation: management is applying a service as a control while the organization remains accountable for the underlying business risk. Transfer would require shifting specified financial consequences or liability, not merely assigning security activities to a provider.
Question 62
Single choice
Which of the following criteria associated with key risk indicators (KRIs) BEST enables effective risk monitoring?
-
A
Approval by senior management
-
B
Low cost of development and maintenance
-
C
Sensitivity to changes in risk levels
-
D
Use of industry risk data sources
Reveal answer details
Close answer details
Correct answerC
ExplanationAn effective KRI must respond when the underlying exposure moves. Sensitivity to changes in risk levels allows the indicator to provide an early and meaningful signal instead of remaining static while risk increases or decreases. Management approval, low maintenance cost, and industry data may support use of the indicator but do not ensure it tracks changing risk.
Question 63
Single choice
Which of the following is a business asset for an organization that runs only in a Software as a Service (SaaS) cloud computing environment?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationIn a Software as a Service environment, the organization's hosted data remains a business asset because it has value and supports business activities even though the service provider operates the application environment. Platforms and containers belong to underlying service layers, while security logs are operational records rather than the primary business asset listed.
Question 64
Single choice
Who should be responsible for approving the cost of controls to be implemented for mitigating risk?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe risk owner is accountable for the risk and for deciding whether its treatment and resulting residual exposure are acceptable. Approving the cost of mitigating controls is part of that business decision because expenditure must be weighed against expected risk reduction. Practitioners advise, while control owners and implementers operate or deploy the controls.
Question 65
Single choice
What is a risk practitioner's BEST approach to monitor and measure how quickly an exposure to a specific risk can affect the organization?
-
A
Create an asset valuation report.
-
B
Create key performance indicators (KPls).
-
C
Create key risk indicators (KRIs).
-
D
Create a risk volatility report.
Reveal answer details
Close answer details
Correct answerC
ExplanationKRIs monitor changes in conditions associated with a specific risk and can be measured frequently enough to reveal how rapidly exposure is developing. Tracking time-sensitive KRIs against defined thresholds shows the movement from normal conditions toward material impact. This provides actionable monitoring of risk velocity rather than a static asset value or general performance measure.
Question 66
Single choice
Which of the following is the MOST useful indicator to measure the efficiency of an identity and access management process?
-
A
Number of tickets for provisioning new accounts
-
B
Average time to provision user accounts
-
C
Password reset volume per month
-
D
Average account lockout time
Reveal answer details
Close answer details
Correct answerB
ExplanationEfficiency concerns the resources or time used to produce an output. Average time to provision user accounts directly measures how quickly the identity and access management process completes a core service. Ticket counts and password-reset volume measure workload, while account lockout time addresses a narrower access-support condition.
Question 67
Single choice
Which of the following activities is PRIMARILY the responsibility of senior management?
-
A
Bottom-up identification of emerging risks
-
B
Categorization of risk scenarios against a standard taxonomy
-
C
Prioritization of risk scenarios based on severity
-
D
Review of external loss data
Reveal answer details
Close answer details
Correct answerC
ExplanationSenior management is responsible for enterprise direction and allocation of attention and resources. Prioritization of risk scenarios based on severity determines which exposures require the greatest management focus and treatment priority, making it a management decision. Identification, taxonomy mapping, and external-data review are supporting analysis activities.
Question 68
Single choice
A risk practitioner notices a risk scenario associated with data loss at the organization's cloud provider is assigned to the provider who should the risk scenario be reassigned to.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA provider can perform services and operate controls, but it does not own the organization's business consequences from losing the data. The data owner is accountable for the data's value, required protection, and related risk decisions, so the scenario belongs with that role. Vendor management and risk executives provide oversight, but oversight is not ownership of this specific data risk.
Question 69
Single choice
The PRIMARY goal of a risk management program is to:
-
A
facilitate resource availability.
-
B
help ensure objectives are met.
-
C
safeguard corporate assets.
-
D
help prevent operational losses.
Reveal answer details
Close answer details
Correct answerB
ExplanationRisk management supports organizational success by identifying uncertainty and keeping exposure within acceptable limits while objectives are pursued. Its primary goal is therefore to help ensure those objectives are met. Protecting assets, preventing losses, and supporting resources are important contributions, but each is narrower than successful achievement of business objectives.
Question 70
Single choice
An organization has decided to postpone the assessment and treatment of several risk scenarios because stakeholders are unavailable. As a result of this decision, the risk associated with these new entries has been;
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationPostponing assessment and treatment leaves the organization exposed to the risk without reducing it or shifting it to another party. By knowingly allowing that exposure to continue during the delay, the organization has accepted it for that period. Calling the activity deferred describes the timing of the work, not the risk response that results from leaving the exposure untreated.
Question 71
Single choice
Which of the following is the PRIMARY reason to aggregate risk assessment results from different business units?
-
A
To improve communication of risk to senior management
-
B
To compare risk profiles across the business units
-
C
To allocate budget for risk management resources
-
D
To determine overall impact to the organization
Reveal answer details
Close answer details
Correct answerD
ExplanationIndividual business-unit assessments describe local exposure, but aggregation reveals how those exposures combine at enterprise level. It captures cumulative impact, concentration, and cross-unit dependencies that cannot be understood from isolated results. Comparing units and communicating results can be useful, but the primary purpose is to determine the overall impact to the organization.
Question 72
Single choice
Of the following, who is accountable for ensuing the effectiveness of a control to mitigate risk?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe control owner is accountable for ensuring that a control is appropriately designed, maintained, monitored, and effective in mitigating the intended risk. A control operator may perform daily activities but does not hold overall accountability. Risk management and treatment roles address broader risk decisions rather than ownership of the individual control.
Question 73
Single choice
Which of the following is the MOST important for an organization to have in place to ensure IT asset protection?
-
A
Procedures for risk assessments on IT assets
-
B
An IT asset management checklist
-
C
An IT asset inventory populated by an automated scanning tool
-
D
A plan that includes processes for the recovery of IT assets
Reveal answer details
Close answer details
Correct answerA
ExplanationProtecting IT assets requires a repeatable process for identifying each asset's threats, vulnerabilities, value, and potential business impact. Risk assessment procedures provide that foundation and allow safeguards to be selected according to exposure. An inventory, checklist, or recovery plan supports particular activities, but none alone establishes the risk-based decisions needed across the asset life cycle.
Question 74
Single choice
The MOST significant benefit of using a consistent risk ranking methodology across an organization is that it enables:
-
A
allocation of available resources
-
B
clear understanding of risk levels
-
C
assignment of risk to the appropriate owners
-
D
risk to be expressed in quantifiable terms
Reveal answer details
Close answer details
Correct answerA
ExplanationA consistent ranking methodology places risks from different business areas on a comparable priority scale. This allows decision-makers to direct limited people, funding, and treatment capacity toward the highest-ranked exposures across the organization. Shared understanding is useful, but the most consequential organizational benefit is that comparable rankings support defensible allocation of available resources.
Question 75
Single choice
When a risk practitioner is building a key risk indicator (KRI) from aggregated data, it is CRITICAL that the data is derived from:
-
A
-
B
representative data sets.
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationA KRI built from aggregated data must use representative data sets so the resulting measure reflects the full population or conditions being monitored. If the data is skewed, the indicator may conceal exposure or generate misleading threshold signals. Data ownership, industry comparisons, and automation can support collection, but none ensures that the underlying observations are representative.
Question 76
Single choice
An external data source has released an advisory about a critical vulnerability affecting a widely used software application. Which of the following should the risk practitioner do FIRST?
-
A
Advise application owners to patch affected software
-
B
Determine organizational exposure
-
C
Notify senior management of the critical vulnerability
-
D
Review the incident response plan
Reveal answer details
Close answer details
Correct answerB
ExplanationA widely used application's vulnerability matters only where the organization uses an affected version or depends on an exposed service. Determining organizational exposure first establishes affected assets and business relevance. That scope is needed before directing patches, escalating the issue, or activating response activities.
Question 77
Single choice
Which of the following BEST indicates the efficiency of a process for granting access privileges?
-
A
Average time to grant access privileges
-
B
Number of changes in access granted to users
-
C
Average number of access privilege exceptions
-
D
Number and type of locked obsolete accounts
Reveal answer details
Close answer details
Correct answerA
ExplanationEfficiency concerns the resources or time consumed to produce an output. Average time to grant access privileges directly measures how quickly the provisioning process completes its work and can reveal delays or bottlenecks. Exceptions, obsolete accounts, and changes to existing access are more closely related to control quality, compliance, or account administration.
Question 78
Single choice
An IT operations team implements disaster recovery controls based on decisions from application owners regarding the level of resiliency needed. Who is the risk owner in this scenario?
-
A
Business resilience manager
-
B
Disaster recovery team lead
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe application owner determines the resiliency needed and is accountable for the business consequences if that level is inadequate. The IT operations team implements disaster recovery controls according to that decision, so it manages the control rather than owning the underlying risk. Risk ownership follows authority over the application and its required resilience.
Question 79
Single choice
When developing a business continuity plan (BCP), it is MOST important to:
-
A
identify an alternative location to host operations.
-
B
identify a geographically dispersed disaster recovery site.
-
C
prioritize critical services to be restored.
-
D
develop a multi-channel communication plan.
Reveal answer details
Close answer details
Correct answerC
ExplanationA business continuity plan must first ensure that the services most important to the organization are restored in the required order. Prioritizing critical services directs limited people, facilities, and technology toward the greatest business need during disruption. Sites and communication channels are supporting arrangements selected after recovery priorities are established.
Question 80
Single choice
When developing IT risk scenarios associated with a new line of business, which of the following would be MOST helpful to review?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationOrganizational threats identify events and actors that could affect the objectives, assets, processes, and dependencies of the new line of business. Reviewing them helps construct relevant IT risk scenarios and connect plausible events to business impact. Resource and financial analyses support planning but do not define the threat conditions themselves.
Question 81
Single choice
Senior management is deciding whether to share confidential data with the organization's business partners. The BEST course of action for a risk practitioner would be to submit a report to senior management containing the:
-
A
possible risk and suggested mitigation plans.
-
B
design of controls to encrypt the data to be shared.
-
C
project plan for classification of the data.
-
D
summary of data protection and privacy legislation.
Reveal answer details
Close answer details
Correct answerA
ExplanationSenior management needs decision-oriented information that connects the proposed data sharing to possible risk and practical mitigation plans. This enables leaders to weigh exposure, business value, and treatment choices before deciding. A single control design, a classification project plan, or a legislative summary covers only part of that decision context.
Question 82
Single choice
Which of the following BEST enables an organization to increase the likelihood of identifying risk associated with unethical employee behavior?
-
A
Require a signed agreement by employees to comply with ethics policies
-
B
Conduct background checks for new employees
-
C
Establish a channel to anonymously report unethical behavior
-
D
Implement mandatory ethics training for employees
Reveal answer details
Close answer details
Correct answerC
ExplanationAn anonymous reporting channel gives employees and other observers a practical way to disclose unethical behavior without attaching their identity to the report. Reducing fear of retaliation increases the likelihood that concealed conduct and its associated risk will be identified. Agreements and training communicate expectations, while background checks address hiring risk rather than detection of ongoing behavior.
Question 83
Single choice
Which of the following is the BEST indication that an organization's risk management program has not reached the desired maturity level?
-
A
Significant increases in risk mitigation budgets
-
B
Large fluctuations in risk ratings between assessments
-
C
A steady increase in the time to recover from incidents
-
D
A large number of control exceptions
Reveal answer details
Close answer details
Correct answerB
ExplanationLarge fluctuations in risk ratings between assessments indicate that the program is not producing stable, repeatable evaluations. Such variation can reflect inconsistent criteria, data, or application of the assessment method, all of which are signs that risk practices have not reached the desired maturity. Budget changes and control exceptions can arise even in a mature program.
Question 84
Single choice
The BEST key performance indicator (KPI) for monitoring adherence to an organization's user accounts provisioning practices is the percentage of:
-
A
accounts without documented approval
-
B
user accounts with default passwords
-
C
active accounts belonging to former personnel
-
D
accounts with dormant activity.
Reveal answer details
Close answer details
Correct answerA
ExplanationProvisioning requires authorization before an account is created or access is granted. The percentage of accounts without documented approval directly measures exceptions to that requirement and therefore indicates adherence to the provisioning practice. Default passwords, former personnel accounts, and dormancy concern password, deprovisioning, or account-review controls instead.
Question 85
Single choice
Which of the following will BEST help to ensure key risk indicators (KRIs) provide value to risk owners?
-
A
-
B
-
C
Return on investment (ROI)
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationA key risk indicator has practical value only if the risk owner receives its warning early enough to evaluate the change and act before exposure becomes unacceptable. Timely notification converts indicator data into actionable information. Training may improve interpretation, but delayed communication can make even an accurate KRI ineffective for risk decisions.
Question 86
Single choice
An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on the devices?
-
A
Periodically review application on BYOD devices
-
B
Include BYOD in organizational awareness programs
-
C
Implement BYOD mobile device management (MDM) controls.
-
D
Enable a remote wee capability for BYOD devices
Reveal answer details
Close answer details
Correct answerC
ExplanationMobile device management controls provide centralized enforcement over how BYOD devices access and use enterprise applications. They can apply organizational security requirements consistently to approved devices and applications. Periodic reviews and awareness support governance, while a remote wipe capability addresses lost-device data rather than inappropriate application use as comprehensively.
Question 87
Single choice
An information system for a key business operation is being moved from an in-house application to a Software as a Service (SaaS) vendor. Which of the following will have the GREATEST impact on the ability to monitor risk?
-
A
Reduced ability to evaluate key risk indicators (KRIs)
-
B
Reduced access to internal audit reports
-
C
Dependency on the vendor's key performance indicators (KPIs)
-
D
Dependency on service level agreements (SLAs)
Reveal answer details
Close answer details
Correct answerA
ExplanationMoving the operation to a SaaS vendor reduces the organization's direct visibility into the systems and controls that generate risk information. A reduced ability to evaluate key risk indicators most directly weakens risk monitoring because those indicators signal changes in exposure. KPIs and SLAs address performance commitments, while audit reports provide periodic assurance rather than ongoing risk signals.
Question 88
Single choice
A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization's data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?
-
A
Request a policy exception from senior management.
-
B
Comply with the organizational policy.
-
C
Report the noncompliance to the local regulatory agency.
-
D
Request an exception from the local regulatory agency.
Reveal answer details
Close answer details
Correct answerA
ExplanationLocal privacy regulations impose requirements that the centralized system must respect, while the conflict arises from an internal data-handling policy. Senior management has authority over that organizational policy and can approve a documented exception so the implementation can comply with local law. Following the conflicting policy would preserve the conflict, and an internal policy exception is not granted by the regulator.
Question 89
Single choice
Which of the following requirements is MOST important to include in an outsourcing contract to help ensure sensitive data stored with a service provider is secure?
-
A
A third-party assessment report of control environment effectiveness must be provided at least annually.
-
B
Incidents related to data toss must be reported to the organization immediately after they occur.
-
C
Risk assessment results must be provided to the organization at least annually.
-
D
A cyber insurance policy must be purchased to cover data loss events.
Reveal answer details
Close answer details
Correct answerA
ExplanationAn annual third-party assessment report provides independent information about whether the service provider's control environment is operating effectively. Requiring that report in the contract gives the organization recurring assurance over controls protecting its sensitive data. Risk results or insurance do not demonstrate control effectiveness, and incident reporting acts only after an event has occurred.
Question 90
Single choice
Which of the following should be accountable for ensuring that media containing financial information are adequately destroyed per an organization's data disposal policy?
-
A
-
B
-
C
-
D
Chief information officer (CIO)
Reveal answer details
Close answer details
Correct answerC
ExplanationThe data owner is accountable for the financial information throughout its life cycle, including defining protection and disposal requirements according to policy. Other roles may operate destruction processes or oversee compliance, but the owner must ensure that media containing the information are disposed of adequately. Operational delegation does not remove that information accountability.
Question 91
Single choice
Which of the following is the BEST evidence that a user account has been properly authorized?
-
A
An email from the user accepting the account
-
B
Notification from human resources that the account is active
-
C
User privileges matching the request form
-
D
Formal approval of the account by the user's manager
Reveal answer details
Close answer details
Correct answerD
ExplanationProper authorization requires evidence that a person with appropriate authority approved creation of the account. Formal approval by the user's manager demonstrates a deliberate decision tied to the user's business need and accountability. Matching privileges to a request shows accurate provisioning, but it does not prove that the request itself was authorized; user or human resources notices also lack approval authority.
Question 92
Single choice
Who should be accountable for authorizing information system access to internal users?
-
A
Information security officer
-
B
Information security manager
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe information owner is accountable for deciding who may access information and for what business purpose because that role determines its authorized use and protection requirements. A custodian implements and administers access according to those decisions. Security officers and managers establish or oversee security practices, but they do not replace the owner's authorization accountability.
Question 93
Single choice
What is the PRIMARY role of the application owner when changes are being introduced into an existing environment?
-
A
Determining possible losses due to downtime during the changes
-
B
Updating control procedures and documentation
-
C
Approving the proposed changes based on impact analysis
-
D
Notifying owners of affected systems after the changes are implemented
Reveal answer details
Close answer details
Correct answerC
ExplanationThe application owner is accountable for ensuring that proposed changes remain suitable for the application's business purpose and risk profile. Reviewing the impact analysis and approving the changes applies that accountability before implementation, when adverse effects and required safeguards can still influence the decision.
Question 94
Single choice
A risk practitioner notices that a particular key risk indicator (KRI) has remained below its established trigger point for an extended period of time. Which of the following should be done FIRST?
-
A
Recommend a re-evaluation of the current threshold of the KRI.
-
B
Notify management that KRIs are being effectively managed.
-
C
Update the risk rating associated with the KRI In the risk register.
-
D
Update the risk tolerance and risk appetite to better align to the KRI.
Reveal answer details
Close answer details
Correct answerA
ExplanationA KRI trigger should distinguish conditions that require attention from normal operating results. If the indicator remains below its trigger for an extended period, the threshold may no longer provide useful warning information. Re-evaluating the current threshold first determines whether it should be recalibrated before changing related risk records or governance limits.
Question 95
Single choice
Which of the following is the BEST way to confirm whether appropriate automated controls are in place within a recently implemented system?
-
A
Perform a post-implementation review.
-
B
Conduct user acceptance testing.
-
C
Review the key performance indicators (KPIs).
-
D
Interview process owners.
Reveal answer details
Close answer details
Correct answerA
ExplanationA post-implementation review evaluates the system after deployment against its approved requirements and intended control design. It can confirm whether automated controls were actually implemented and operate in the live environment. User acceptance testing focuses mainly on whether the system meets user and business needs.
Question 96
Single choice
Which of the following will be MOST effective in uniquely identifying the originator of electronic transactions?
-
A
-
B
-
C
-
D
Multifactor authentication
Reveal answer details
Close answer details
Correct answerA
ExplanationA digital signature is created using a signer's private key and can be verified with the corresponding public key. This binds the transaction to the holder of that signing credential and also reveals unauthorized changes to the signed content, supporting origin authentication and integrity. Encryption protects confidentiality, while edit checks and multifactor authentication do not bind a transaction itself to its originator.
Question 97
Single choice
The number of tickets to rework application code has significantly exceeded the established threshold. Which of the following would be the risk practitioner s BEST recommendation?
-
A
Perform a root cause analysis
-
B
-
C
Implement version control software.
-
D
Implement training on coding best practices
Reveal answer details
Close answer details
Correct answerA
ExplanationExceeding the rework threshold indicates a recurring problem but does not identify why it is happening. Root cause analysis determines the underlying process, design, skill, or control condition producing the rework. Only after that cause is understood can management choose an effective response, such as a targeted review, tool, or training measure.
Question 98
Single choice
Which of the following is the FIRST step in a risk assessment process?
-
A
-
B
Documenting vulnerabilities
-
C
Assessing the likelihood of threats
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA risk assessment needs an inventory of the assets that may be affected before threats, vulnerabilities, impact, or ownership can be evaluated. Identifying assets establishes what has value and defines the assessment scope. Once that foundation exists, vulnerabilities can be documented, threat likelihood assessed, and accountable risk owners assigned.
Question 99
Single choice
When assessing the maturity level of an organization's risk management framework, which of the following deficiencies should be of GREATEST concern to a risk practitioner?
-
A
Unclear organizational risk appetite
-
B
Lack of senior management participation
-
C
Use of highly customized control frameworks
-
D
Reliance on qualitative analysis methods
Reveal answer details
Close answer details
Correct answerB
ExplanationSenior management participation supplies authority, direction, accountability, and support for risk management across the organization. Without that participation, risk decisions may remain disconnected from objectives and may not receive the ownership or resources needed for implementation. Other deficiencies can limit clarity or analysis, but missing leadership undermines the framework as a whole.
Question 100
Single choice
Which of the following is a risk practitioner's BEST recommendation to help reduce IT risk associated with scheduling overruns when starting a new application development project?
-
A
Implement a tool to track the development team's deliverables.
-
B
Review the software development life cycle.
-
C
Involve the development team in planning.
-
D
Assign more developers to the project team.
Reveal answer details
Close answer details
Correct answerC
ExplanationInvolving the development team in planning brings those who understand the work, dependencies, and delivery constraints into schedule estimation. Their participation supports more realistic commitments and earlier identification of factors that could cause overruns. Tracking tools measure progress after planning, while adding staff or reviewing the life cycle does not by itself improve the schedule's underlying estimates.
|