When analyzing l&T-related risk, an enterprise defines likelihood and impact on a scale from 1 to 5, and the scale of impact also defines a range expressed in monetary terms. Which of the following risk analysis approaches has been adopted?
Which of the following is the BEST indication of a good risk culture?
Why is risk identification important to an organization?
Which of the following is important to ensure when validating the results of a frequency analysis?
Which of the following is MOST important to include when developing a business case for a specific risk response?
Which of the following is the BEST way to minimize potential attack vectors on the enterprise network?
Which of the following is considered an exploit event?
Which of the following is MOST important to ensure when developing key risk indicators (KRIs)?
Which of the following MUST be consistent with the defined criteria when establishing the risk management context as it relates to calculation of risk?
When selecting a key risk indicator (KRI), it is MOST important that the KRI:
When evaluating the current state of controls, which of the following will provide the MOST comprehensive analysis of enterprise processes, incidents, logs, and the threat environment?
Which of the following is the PRIMARY objective of vulnerability assessments?
As part of the control monitoring process, frequent control exceptions are MOST likely to indicate:
What is the PRIMARY purpose of providing timely and accurate risk information to key stakeholders?
Which of the following is a KEY contributing component for determining risk rankings to direct risk response?
Which of the following is the MOST important factor to consider when developing effective risk scenarios?
Which of the following is MOST important for a risk practitioner to ensure when preparing a risk report?
Which of the following BEST supports a risk-aware culture within an enterprise?
Which of the following is the PRIMARY reason to conduct a cost-benefit analysis as part of a risk response business case?
Which of the following is the MOST important information for determining the critical path of a project?
To address concerns of increased online skimming attacks, an enterprise is training the software development team on secure software development practices. This is an example of which of the following risk response strategies?
Which of the following occurs earliest in the risk response process?
Which of the following is an example of an inductive method to gather information?
An enterprise has initiated a project to implement a risk-mitigating control. Which of the following would provide senior management with the MOST useful information on the project's status?
Which of the following is the BEST reason for an enterprise to avoid an absolute prohibition on risk?
Which of the following risk analysis methods gathers different types of potential risk ideas to be validated and ranked by an individual or small groups during interviews?
What is the PRIMARY benefit of using generic technology terms in IT risk assessment reports to management?
Which of the following is a potential risk associated with IT hardware or devices?
Applying statistical analysis methods to I&T risk scenarios is MOST appropriate when:
Which of the following presents the GREATEST risk for the continued existence of an enterprise?
Which risk response option has been adopted when an enterprise outsources disaster recovery activities to leverage the skills and expertise of a third-party provider?
Which of the following would be considered a cyber-risk?
Which of the following statements on an organization's cybersecurity profile is BEST suited for presentation to management?
Which of the following is the MOST likely reason to perform a qualitative risk analysis?
An enterprise is currently experiencing an unacceptable 8% processing error rate and desires to manage risk by establishing a policy that error rates cannot exceed 5%. In addition, management wants to be alerted when error rates meet or exceed 4%. The enterprise should set a key performance indicator (KPI) metric at which of the following levels?