IT-Risk-Fundamentals IT Risk Fundamentals Certificate Exam Questions and Answers
The PRIMARY goal of a business continuity plan (BCP) is to enable the enterprise to provide:
Applying statistical analysis methods to I&T risk scenarios is MOST appropriate when:
Which of the following is MOST important for the determination of I&T-related risk?
A risk practitioner has been asked to prepare a risk report by the end of the day that includes an analysis of the most significant risk events facing the organization. Which of the following would BEST enable the risk practitioner to meet the report deadline?
As part of the control monitoring process, frequent control exceptions are MOST likely to indicate:
Which of the following is an example of an inductive method to gather information?
An enterprise recently implemented multi-factor authentication. During the most recent risk assessment, it was determined that cybersecurity risk is within the organization's risk appetite threshold. What is the MOST appropriate action for the organization to take regarding the remaining cybersecurity residual risk?
Which of the following is MOST important to ensure when developing key risk indicators (KRIs)?
Which of the following is the PRIMARY reason to conduct a cost-benefit analysis as part of a risk response business case?
Which of the following presents the GREATEST risk for the continued existence of an enterprise?
In the context of enterprise risk management (ERM), what is the overall role of l&T risk management stakeholders?
Which of the following is combined with risk impact to determine the level of risk?
Which of the following is MOST likely to expose an organization to adverse threats?
Which of the following is the MOST likely reason to perform a qualitative risk analysis?
Which of the following is the BEST reason for an enterprise to avoid an absolute prohibition on risk?
Which of the following is a KEY contributing component for determining risk rankings to direct risk response?
Publishing l&T risk-related policies and procedures BEST enables an enterprise to:
Which of the following MUST be established in order to manage l&T-related risk throughout the enterprise?
What is the PRIMARY benefit of using generic technology terms in IT risk assessment reports to management?
Which of the following statements on an organization's cybersecurity profile is BEST suited for presentation to management?
An enterprise has performed a risk assessment for the risk associated with the theft of sales team laptops while in transit. The results of the assessment concluded that the cost of mitigating the risk is higher than the potential loss. Which of the following is the BEST risk response strategy?
Which of the following is MOST important for a risk practitioner to ensure when preparing a risk report?
Risk maps can help to develop common profiles in order to identify which of the following?
Which of the following risk analysis methods gathers different types of potential risk ideas to be validated and ranked by an individual or small groups during interviews?
Of the following, which stakeholder group is MOST often responsible for risk governance?