Skip to main content

IT-RISK-FUNDAMENTALS Real Exam Questions

IT Risk Fundamentals Certificate

118 questions available · Page 1 of 12

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

The PRIMARY goal of a business continuity plan (BCP) is to enable the enterprise to provide:

  1. A

    a detailed list of hardware and software requirements to enable business functionality after an interruption.

  2. B

    an immediate return of all business functionality after an interruption.

  3. C

    a sufficient level of business functionality immediately after an interruption.

Show answer and explanation

Correct answer: C

Question 2 Single choice

Which of the following is important to ensure when validating the results of a frequency analysis?

  1. A

    Estimates used during the analysis were based on reliable and historical data.

  2. B

    The analysis was conducted by an independent third party.

  3. C

    The analysis method has been fully documented and explained.

Show answer and explanation

Correct answer: A

Question 3 Single choice

Which of the following is the BEST way to interpret enterprise standards?

  1. A

    A means of implementing policy

  2. B

    An approved code of practice

  3. C

    Documented high-level principles

Show answer and explanation

Correct answer: A

Question 4 Single choice

Which of the following is the objective of a frequency analysis?

  1. A

    To determine how often risk mitigation strategies should be evaluated and updated within a specific timeframe

  2. B

    To determine how many risk scenarios will impact business objectives over a given period of time

  3. C

    To determine how often a particular risk scenario might be expected to occur during a specified period of time

Show answer and explanation

Correct answer: C

Question 5 Single choice

When evaluating the current state of controls, which of the following will provide the MOST comprehensive analysis of enterprise processes, incidents, logs, and the threat environment?

  1. A

    Enterprise architecture (EA) assessment

  2. B

    IT operations and management evaluation

  3. C

    Third-party assurance review

Show answer and explanation

Correct answer: B

Question 6 Single choice

Which types of controls are designed to avoid undesirable events, errors, and other adverse occurrences?

  1. A

    Corrective controls

  2. B

    Detective controls

  3. C

    Preventive controls

Show answer and explanation

Correct answer: C

Question 7 Single choice

What is the basis for determining the sensitivity of an IT asset?

  1. A

    Potential damage to the business due to unauthorized disclosure

  2. B

    Cost to replace the asset if lost, damaged, or deemed obsolete

  3. C

    Importance of the asset to the business

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which of the following is considered an exploit event?

  1. A

    An attacker takes advantage of a vulnerability

  2. B

    Any event that is verified as a security breach

  3. C

    The actual occurrence of an adverse event

Show answer and explanation

Correct answer: A

Question 9 Single choice

Risk monitoring is MOST effective when it is conducted:

  1. A

    following changes to the business's environment.

  2. B

    before and after completing the risk treatment plan.

  3. C

    throughout the risk treatment planning process.

Show answer and explanation

Correct answer: C

Question 10 Single choice

When analyzing l&T-related risk, an enterprise defines likelihood and impact on a scale from 1 to 5, and the scale of impact also defines a range expressed in monetary terms.

Which of the following risk analysis approaches has been adopted?

  1. A

    Qualitative approach

  2. B

    Quantitative approach

  3. C

    Hybrid approach

Show answer and explanation

Correct answer: C