Which of the following would have the MOST impact on the accuracy and appropriateness of plans associated with business continuity and disaster recovery?
An enterprise has performed a risk assessment for the risk associated with the theft of sales team laptops while in transit. The results of the assessment concluded that the cost of mitigating the risk is higher than the potential loss. Which of the following is the BEST risk response strategy?
Which of the following MUST be established in order to manage l&T-related risk throughout the enterprise?
What is the PRIMARY benefit of using generic technology terms in IT risk assessment reports to management?
Which of the following is the MOST important factor to consider when developing effective risk scenarios?
The PRIMARY goal of a business continuity plan (BCP) is to enable the enterprise to provide:
Of the following, who is BEST suited to be responsible for continuous monitoring of risk?
A key risk indicator (KRI) is PRIMARILY used for which of the following purposes?
Of the following, which stakeholder group is MOST often responsible for risk governance?
Which of the following is a benefit of using a top-down approach when developing risk scenarios?
As part of the control monitoring process, frequent control exceptions are MOST likely to indicate:
The PRIMARY reason for the implementation of additional security controls is to:
Risk maps can help to develop common profiles in order to identify which of the following?
Which of the following is the MOST useful information to include in a risk report to indicate control effectiveness?
Which of the following are KEY considerations when selecting the best risk response for a given situation?
Which of the following is the BEST reason for an enterprise to avoid an absolute prohibition on risk?
Which of the following statements on an organization's cybersecurity profile is BEST suited for presentation to management?
Detailed risk management reports should be targeted to a specific audience based on:
Which of the following is MOST likely to promote ethical and open communication of risk management activities at the executive level?
A risk practitioner has been tasked with analyzing new risk events added to the risk register. Which of the following analysis methods would BEST enable the risk practitioner to minimize ambiguity and subjectivity?
Which of the following is the PRIMARY reason to conduct a cost-benefit analysis as part of a risk response business case?
The use of risk scenarios to guide senior management through a rapidly changing market environment is considered a key risk management