Question 101

Which of the following should be the risk practitioner's PRIMARY focus when determining whether controls are adequate to mitigate risk?
  • Question 102

    The following is the snapshot of a recently approved IT risk register maintained by an organization's information security department.

    After implementing countermeasures listed in ''Risk Response Descriptions'' for each of the Risk IDs, which of the following component of the register MUST change?
  • Question 103

    Which of the following is MOST important to review when determining whether a potential IT service provider s control environment is effective?
  • Question 104

    Senior management is deciding whether to share confidential data with the organization's business partners.
    The BEST course of action for a risk practitioner would be to submit a report to senior management containing the:
  • Question 105

    Which of the following provides the BEST evidence that a selected risk treatment plan is effective?