Which types of controls are designed to avoid undesirable events, errors, and other adverse occurrences?
The PRIMARY goal of a business continuity plan (BCP) is to enable the enterprise to provide:
A key risk indicator (KRI) is PRIMARILY used for which of the following purposes?
Which of the following represents a vulnerability associated with legacy systems using older technology?
The PRIMARY reason for the implementation of additional security controls is to:
The use of risk scenarios to guide senior management through a rapidly changing market environment is considered a key risk management
Which of the following is an example of an inductive method to gather information?
A risk practitioner has been tasked with analyzing new risk events added to the risk register. Which of the following analysis methods would BEST enable the risk practitioner to minimize ambiguity and subjectivity?
Key risk indicators (KRIs) are used for which of the following purposes when developing a project plan?
Which of the following is MOST likely to expose an organization to adverse threats?
Of the following, who is BEST suited to be responsible for continuous monitoring of risk?
An enterprise that uses a two-factor authentication login method for accessing sensitive data has implemented which type of control?
An enterprise has performed a risk assessment for the risk associated with the theft of sales team laptops while in transit. The results of the assessment concluded that the cost of mitigating the risk is higher than the potential loss. Which of the following is the BEST risk response strategy?
Which of the following is the MAIN reason to include previously overlooked risk in a risk report?
As part of the control monitoring process, frequent control exceptions are MOST likely to indicate:
The MOST important reason for developing and monitoring key risk indicators (KRIs) is that they provide:
An enterprise has initiated a project to implement a risk-mitigating control. Which of the following would provide senior management with the MOST useful information on the project's status?
Which of the following is a KEY contributing component for determining risk rankings to direct risk response?