CRISC · domain
scenario questions
Practise Certified in Risk and Information Systems Control CRISC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (983)
Click any question to see the full explanation, or start a practice session above.
A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?
Medium2A board member asks for a summary of the top five risks. The risk practitioner has 10 risks with current residual risk levels. Which approach BEST supports board-level reporting?
Hard3Arrange the steps for performing a risk assessment in the correct order.
Medium4A manufacturing company uses Internet of Things (IoT) sensors to monitor equipment temperature and vibration on the production floor. The sensor data is automatically sent to a central system, but there is a manual log maintained by operators that records their visual inspections. Recently, there have been instances where the sensor data indicated abnormal readings, but the operator logs showed normal conditions, leading to delayed maintenance actions and two equipment breakdowns. The risk manager investigates and finds that operators sometimes forget to update logs or misinterpret sensor alerts. The company wants to improve the reliability of the monitoring process. What should be the primary action?
Medium5A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?
Medium6An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?
Easy7A small online retailer with 15 employees sells handmade crafts through its e-commerce website. The company processes payments via a third-party gateway. The owner manually reviews transaction logs once a week for fraud indicators, but recently discovered three chargebacks due to unauthorized transactions. The retailer has limited IT budget and no dedicated security staff. The owner wants to improve detection of fraudulent transactions without significant investment. The current manual process takes about two hours per week and often results in delayed detection. The payment gateway offers basic fraud detection features such as IP geolocation and velocity checks, but these are not enabled. What is the most practical first step?
Easy8During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?
Medium9A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?
Medium10Based on the exhibit, which of the following risks is MOST indicated by the policy configuration?
Medium11A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?
Medium12An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?
Hard13An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?
Hard14During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?
Medium15A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?
Medium16Which of the following is a detective control?
Easy17Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?
Easy18In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?
Medium19Which THREE of the following are effective techniques for identifying IT risks?
Medium20A financial institution is identifying IT risks associated with a new mobile banking application. Which TWO threat modeling techniques are best suited for this scenario? (Select two.)
Medium21An organization is implementing a data classification scheme. Which of the following classification categories would be MOST effective for identifying risks related to intellectual property theft?
Hard22Which THREE of the following are common challenges when implementing a risk monitoring dashboard? (Select exactly three.)
Hard23An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?
Easy24A financial institution has implemented a continuous monitoring solution for its core banking application. The monitoring team receives an alert indicating that the average response time for a critical transaction has exceeded the threshold for the past 15 minutes. The transaction volume during this period is within normal range. What should be the FIRST step in the incident response process?
Medium25Which of the following is the PRIMARY benefit of using a risk register for monitoring?
Easy26A healthcare organization operates a legacy electronic health record (EHR) system that is manually monitored for access anomalies by a small IT team. The organization is planning to migrate to a new cloud-based EHR with integrated logging and monitoring. However, due to budget constraints, the migration will take two years. In the interim, the risk manager wants to improve monitoring for unauthorized access to patient data. The current manual process involves weekly log reviews, but recent audits have identified instances of delayed detection (up to two weeks) and missed incidents. The IT team can dedicate only 10 additional hours per week for monitoring. What is the best approach to enhance monitoring during the transition period?
Medium27In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?
Medium28Which TWO of the following are valid risk scenarios that should be documented during IT risk identification?
Medium29A financial services company uses a legacy mainframe system for core banking transactions. The risk assessment identifies that the system does not support modern encryption standards, and data is transmitted in clear text over internal networks. The IT department has proposed implementing network segmentation and encryption at the application layer using a middleware solution. However, the cost is high and the project would take 18 months. Meanwhile, the company is planning to migrate to a new core system in two years. The risk appetite for data confidentiality is low. As the risk practitioner, what is the MOST appropriate risk response?
Medium30Which threat modeling technique is specifically designed to be integrated into Agile and DevSecOps processes, providing a visual and simple approach?
Easy31An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?
Medium32A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?
Medium33An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?
Hard34An organization is planning to deploy an IoT solution in a manufacturing plant. The risk manager is asked to identify risks associated with the integration of IoT devices into the plant network. Which of the following techniques would be MOST effective for identifying both technical and operational risks?
Medium35An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?
Easy36When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?
Medium37A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?
Easy38Which TWO of the following are primary purposes of risk and control monitoring? (Choose two.)
Medium39A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?
Medium40An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?
Medium41Match each risk assessment method to its characteristic.
Medium42During a quarterly risk review, it is discovered that a previously accepted risk has materialized due to a change in the external environment. What is the MOST appropriate response?
Hard43A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?
Easy44An organization is designing a vendor risk management program. Which TWO of the following are essential components of ongoing vendor monitoring? (Select TWO)
Medium45During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?
Medium46An organization assesses a risk of intellectual property theft through email exfiltration. They decide to enforce DLP controls, purchase a cyber liability policy, and officially accept the residual risk after controls. Which THREE risk response options are demonstrated?
Hard47Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?
Medium48After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?
Medium49Which TWO of the following are examples of inherent risk?
Easy50Which TWO of the following are key risk identification techniques used to identify threats and vulnerabilities in IT systems? (Select exactly 2.)
Medium51A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?
Hard52An organization is assessing risks related to a third-party cloud provider. Which of the following is the BEST source of threat intelligence for identifying threats targeting the cloud infrastructure?
Medium53A financial services firm is migrating critical applications to a public cloud. The architecture review board (ARB) is evaluating the solution architecture. Which THREE risks should the ARB prioritize for review?
Hard54Which of the following is the BEST practice for determining the frequency of control monitoring activities?
Easy55A company calculates the annualized loss expectancy (ALE) for a server failure as $150,000. After implementing a backup solution costing $20,000 per year, the ALE drops to $30,000. What is the annualized benefit of the control?
Hard56Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?
Easy57A risk manager notices that a key risk indicator (KRI) for failed login attempts has exceeded the threshold for three consecutive weeks. Which of the following should be the FIRST action?
Easy58An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?
Medium59A retail company uses a manual control to verify that all credit card transactions are processed by authorized payment terminals. The control requires a store manager to compare a daily transaction log against a list of approved terminal IDs. The company processes an average of 10,000 transactions per day across 200 stores. During a recent internal audit, it was found that 15% of stores had not completed the reconciliation for the past month. The audit also revealed that several unauthorized terminals had been used to process transactions, resulting in a data breach of customer payment information. The company's risk appetite for payment card data security is very low. The current monitoring approach includes a quarterly review of control performance by the internal audit team. The risk manager needs to recommend improvements to the monitoring of this control. Which of the following is the BEST recommendation?
Medium60An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?
Medium61An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?
Medium62An organization uses a qualitative risk assessment methodology. During a recent assessment, several risks were rated as 'high' due to vague definitions. What is the BEST way to improve the accuracy of the assessment?
Medium63Which TWO of the following are examples of continuous monitoring techniques?
Easy64A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?
Hard65An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:
Medium66A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:
Medium67In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?
Hard68An organization has identified a high-risk IT process that, if continued, could result in significant regulatory fines. The risk owner recommends implementing additional controls. However, the cost of controls exceeds the potential financial loss. Which risk treatment option is MOST appropriate?
Hard69A financial services firm is assessing vulnerabilities in its web application. The team wants to identify application-level vulnerabilities that could be exploited. Which TWO vulnerability identification techniques should be prioritized for this purpose?
Medium70A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?
Hard71A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?
Hard72A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?
Hard73During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:
Medium74A company's internal audit function reports that a detective control (manual review of transactions) is operating effectively based on a sample of 50 transactions showing no issues. However, the continuous monitoring system shows that 100 suspicious transactions were not reviewed during the same period. The control owner argues the control is effective. What is the BEST conclusion?
Hard75A multinational corporation is implementing continuous monitoring of its compliance with data privacy regulations across multiple jurisdictions. Which TWO of the following are significant challenges to this approach?
Hard76A risk assessment that assigns monetary values to assets and calculates expected loss is called:
Easy77A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?
Medium78An organization uses a third-party SaaS provider for payroll processing. Which of the following is the BEST technique to identify risks associated with this vendor?
Easy79Which of the following is a key component of an IT risk management programme design?
Easy80A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?
Medium81Based on the exhibit, which aspect of risk monitoring is MOST concerning?
Medium82A company uses a risk control self-assessment (RCSA) process that is conducted annually. During a quarterly review, management discovers that several high-risk controls are no longer effective due to changes in the business environment. Which of the following is the BEST way to enhance the monitoring of these controls?
Hard83Refer to the exhibit. During a risk identification review, the risk manager sees this IDS alert. What risk does this alert MOST directly indicate?
Easy84Which THREE of the following are common elements of a periodic control effectiveness testing program? (Select THREE)
Medium85During a quarterly control effectiveness test, internal audit discovers that a key automated control failed 15% of the time due to a software bug. The risk owner decides to accept the risk because the cost to fix the bug is high. What should the risk manager do next?
Hard86A medium-sized e-commerce company has a risk monitoring program that tracks key risk indicators (KRIs) monthly. One KRI is the percentage of orders with failed payment transactions. The threshold is 2%, but for the past three months, the KRI has been 2.5%, 3.1%, and 2.8%. The risk owner says this is due to a seasonal increase in fraudulent transactions and expects it to return to normal next month. The company has a compensating control that manually reviews flagged transactions. The internal audit team recently tested the compensating control and found it to be 100% effective. The risk committee wants to know if the KRI breach requires action. What should the risk practitioner recommend?
Medium87A risk manager is developing a risk scenario for a potential data breach involving a third-party cloud provider. According to the ISACA risk scenario template, which THREE elements must be included? (Select three.)
Hard88An organization has a risk register that includes risks related to regulatory compliance, such as GDPR and SOX. The risk practitioner is now categorizing these risks. Which risk category would BEST fit these compliance-related risks?
Medium89In IT risk reporting, which level of management typically receives operational risk reporting on a weekly or monthly basis?
Medium90An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)
Hard91An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?
Easy92A multinational financial services company has implemented a continuous monitoring program for its trading systems. The program uses automated scripts to check system configurations against a baseline every hour. Recently, the company experienced a significant security incident where a malicious actor exploited a misconfigured firewall rule to exfiltrate sensitive customer data. Post-incident analysis revealed that the misconfiguration had been present for 72 hours before detection. The monitoring scripts did not detect the change because the baseline had been updated two weeks prior to include the misconfiguration as part of a planned change that was later reversed without updating the baseline. The company's change management process requires that all configuration changes be approved and documented, but the reversal of the change was not documented. The incident response team was only alerted when a customer reported suspicious activity. The risk practitioner is tasked with recommending improvements to prevent recurrence. Which of the following is the BEST course of action?
Hard93When assessing IT risks, which of the following is the PRIMARY purpose of developing risk scenarios?
Easy94Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?
Easy95Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy96In assessing control effectiveness, an IS auditor evaluates both design adequacy and operating effectiveness. Which of the following indicates that a control is operating effectively?
Medium97A risk manager is using a 5×5 likelihood-impact matrix to assess a set of identified risks. What is the PRIMARY advantage of using this qualitative method?
Easy98A company is migrating its legacy on-premises applications to a public cloud environment. Which risk identification technique is most appropriate for this scenario?
Medium99A financial institution is migrating its core banking system from an on-premises data center to a public cloud infrastructure. The migration is planned in phases over 18 months. The IT risk manager is tasked with identifying risks during the transition. During the first phase, the team moves non-critical applications to the cloud. A vulnerability assessment of the cloud environment reveals that several virtual machines have default administrative credentials enabled. Additionally, the cloud security group configuration for the application tier allows inbound SSH from the entire internet (0.0.0.0/0). The risk manager also learns that the cloud provider's shared responsibility model is not fully understood by the operations team, who believe the provider is responsible for all security controls. The institution's risk appetite statement allows for moderate risk tolerance but prohibits any exposure that could lead to unauthorized access to customer financial data. Which of the following risk scenarios should the risk manager identify as the MOST critical to address immediately?
Hard100An IT manager is identifying risks for a new cloud application. Which of the following is the BEST source for identifying specific threats relevant to cloud services?
Easy101A financial institution monitors the number of unauthorized access attempts to its core banking system. The risk owner recommends increasing the monitoring frequency from daily to hourly because a recent attack exploited a delayed detection. Which of the following is the PRIMARY benefit of this change?
Easy102A security analyst notices that the number of failed login attempts has significantly increased over the past week. The SIEM alerts are not being triggered because the threshold was set too high. What is the MOST effective immediate action to improve monitoring?
Medium103A multinational corporation is assessing the risk of a new cloud-based customer relationship management (CRM) system. The risk manager conducts a qualitative risk assessment using a risk matrix that plots likelihood vs. impact. Which of the following is the PRIMARY benefit of using a qualitative approach over a quantitative approach in this context?
Easy104A risk owner wants to implement continuous monitoring for a set of critical controls. Which of the following is the PRIMARY benefit of continuous monitoring over periodic testing?
Easy105Match each key risk indicator (KRI) to its description.
Medium106A bank's risk committee reviews a monthly risk report that includes KRIs. One KRI shows that the number of failed transactions due to system errors is trending upward. The control owner states that the trend is within the risk appetite. However, the report also shows that the number of customer complaints is stable. What should the risk manager do FIRST?
Hard107During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?
Easy108A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:
Easy109A risk assessment of a critical financial application identifies a high inherent risk due to outdated software. The risk manager is considering mitigation options. Which TWO of the following would be considered preventive controls?
Medium110A risk practitioner is designing a risk dashboard for the executive team. The organization has a high risk appetite for revenue-generating activities but a low risk appetite for regulatory compliance. Which combination of metrics should be prominently displayed?
Medium111A university is implementing a new online learning management system (LMS) that will store student records, grades, and personal information. During the risk assessment, the IT team identifies that the LMS vendor's default configuration allows students to see each other's email addresses in the class roster. This could lead to privacy violations under FERPA regulations. The vendor states that this feature can be disabled in the settings but doing so will require manual configuration for each course. The university has a moderate risk appetite and wants to launch the system within two weeks. Which of the following is the MOST appropriate risk response?
Medium112A retail company has a risk monitoring program that tracks key risk indicators (KRIs) for its e-commerce platform. One KRI measures the number of failed payment transactions as a percentage of total transactions. The threshold is set at 2%. Over the past quarter, the KRI has been fluctuating between 1.8% and 2.5%, breaching the threshold several times. Each time the KRI exceeded the threshold, the risk owner performed a manual investigation and found that the failures were due to transient network issues that resolved on their own. The risk owner has now requested that the threshold be raised to 3% to avoid unnecessary investigations. The risk practitioner is evaluating this request. What should the risk practitioner do?
Medium113An IT risk report to the board of directors should primarily focus on which of the following?
Easy114A risk assessment team is prioritizing IT risks for treatment. Which THREE factors should be considered when prioritizing risks? (Select THREE)
Hard115Which TWO of the following are best practices for risk reporting to senior management?
Easy116Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?
Easy117A financial services firm uses SAST and DAST tools in its application security testing. However, they are struggling to prioritize vulnerabilities from the large number of findings. Which additional technique would BEST help identify the most critical vulnerabilities in the context of business risk?
Hard118An organization has a risk appetite that is risk-averse. Which risk treatment option would be most aligned with this appetite?
Easy119A company is evaluating control types for a new system. The security team proposes implementing an intrusion detection system (IDS) and a backup restoration process. Which TWO control types do these represent, respectively?
Medium120Which TWO of the following are essential components of an effective control monitoring program?
Medium121During an IT risk assessment, the risk owner identifies a high inherent risk for a legacy system. After implementing a firewall and intrusion detection system, the residual risk is calculated. Which of the following best describes residual risk?
Medium122A large financial institution has implemented a risk monitoring framework that includes KRIs for operational risk. Recently, a critical KRI related to trade settlement errors has been showing an upward trend, but it remains within the approved threshold. The risk manager is concerned because the trend indicates potential control degradation. The control owner argues that since the KRI is still within threshold, no action is needed. The risk manager wants to determine the best course of action to address the trend before it breaches the threshold. The organization's risk policy requires proactive monitoring. What should the risk manager do?
Hard123An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?
Medium124An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?
Hard125An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?
Medium126A company is assessing a new vendor that will have access to its customer database. The vendor's security questionnaire reveals they lack SOC 2 certification. According to risk tiering, the vendor is classified as critical. What should the company do?
Medium127Refer to the exhibit. A risk manager reviews the vulnerability scan output. According to the policy, what is the required risk response?
Medium128During a risk assessment, a risk manager is evaluating the effectiveness of a firewall rule set. The manager notes that the firewall logs show a high number of dropped packets from a specific IP range, but no policy changes have been made. The manager suspects the firewall rule set may be misconfigured. Which of the following should the manager do FIRST?
Hard129During a threat modeling exercise using the STRIDE methodology, a security analyst identifies a threat where an attacker can modify data in transit between a web server and database. Which STRIDE category does this threat belong to?
Hard130A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?
Hard131An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
Hard132A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?
Medium133A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?
Medium134Which type of control testing is typically performed on a continuous basis using automated tools?
Easy135Based on the exhibit, what risk does this database error MOST directly indicate?
Easy136Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?
Hard137An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?
Hard138An organization is adopting machine learning for credit scoring decisions. Which of the following risks is MOST critical from a regulatory compliance perspective?
Medium139A risk manager is identifying risks for a new mobile payment application. The application will use end-to-end encryption. Which of the following is the BEST source of risk information for identifying potential threats?
Easy140Based on the exhibit, what is the MOST appropriate immediate risk response?
Medium141Refer to the exhibit. A SIEM correlation rule 'Brute_Force_SSH' has fired excessively due to traffic from internal monitoring servers. What is the BEST course of action?
Easy142Based on the exhibit, which vulnerability poses the HIGHEST risk to the organization?
Medium143Which THREE of the following are typical exclusions in a cyber insurance policy?
Medium144Refer to the exhibit. The control test failed because unauthorized access attempts were detected. The remediation plan suggests additional logging. Is this remediation appropriate?
Hard145Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?
Medium146An organization has received a critical vulnerability alert for a web application firewall. The risk owner is on leave. What should the risk manager do?
Medium147A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?
Hard148Refer to the exhibit. A security analyst reviews firewall logs and sees repeated authentication failures for VPN tunnel attempts between two IP addresses. What is the MOST appropriate action?
Medium149A healthcare organization is migrating its electronic health records (EHR) system to a public cloud. The risk manager identifies several risks. Which TWO of the following are the MOST significant risks related to data privacy and regulatory compliance?
Medium150A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?
Medium151A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?
Easy152Which TWO of the following are recognized techniques for identifying IT risks? (Select exactly 2.)
Medium153During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?
Easy154A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?
Hard155Refer to the exhibit. What is the PRIMARY risk identified from this policy?
Hard156During a quarterly control effectiveness test, an internal auditor discovers that a key preventive control has a 10% exception rate. The control is designed to prevent unauthorized transactions. Which Key Control Indicator (KCI) is being measured?
Medium157Which type of control is designed to reduce the likelihood of a risk event occurring?
Easy158Which of the following is an example of a corrective control?
Easy159A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?
Medium160A multinational corporation is evaluating a new vendor for cloud services. The vendor's data centers are located in a country with weak data protection laws. The corporation's data includes personal information of EU citizens subject to GDPR. What is the MOST appropriate risk response?
Hard161During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?
Medium162An organization has implemented a continuous monitoring solution for its critical applications. The IT team reports that the monitoring tool generates a high volume of false positives. What is the BEST course of action?
Medium163Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?
Easy164You are the IT risk manager for a multinational corporation with a hybrid cloud environment. The company uses AWS for its primary infrastructure and maintains an on-premises data center for legacy applications. Recently, the security team detected that a contractor's credentials were used to access an S3 bucket containing personally identifiable information (PII) of European customers. The contractor had been granted access to this bucket six months ago for a data migration project that has since been completed. The access was not revoked. The security team has implemented an automated process to review and revoke access for contractors after project completion, but this process has not been applied retroactively. The company is subject to GDPR. Which of the following is the BEST course of action to address the immediate risk?
Hard165Based on the exhibit, which risk should be treated first according to the risk rating?
Hard166An organization has implemented a new control that requires manual approval for all high-value transactions. The control owner is responsible for ensuring approvals are obtained. Which control ownership aspect is demonstrated?
Medium167After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?
Hard168A risk manager is identifying risks for an organization that uses a hybrid cloud environment. The organization stores sensitive data on-premises and in the cloud. Which of the following is the MOST effective method for identifying risks related to data residency and compliance?
Medium169A company outsourced its payroll processing to a third-party vendor. During the risk assessment, it was found that the vendor's data centers are in a country with weak data protection laws. What is the BEST way to treat this risk?
Medium170Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)
Medium171A multinational organization uses multiple risk management systems that do not integrate with each other. The risk team manually consolidates data into a spreadsheet for reporting. This process is error-prone and time-consuming. Which of the following is the BEST long-term solution to improve risk monitoring and reporting?
Hard172During a qualitative risk assessment, the risk owner rates the likelihood of a threat as 'high' and the impact as 'medium'. According to standard risk matrices, what is the resulting risk level?
Medium173A financial institution uses a quantitative risk assessment for a core banking system. The annual loss expectancy (ALE) is calculated as $500,000 with a single loss expectancy (SLE) of $2,500,000. What is the annualized rate of occurrence (ARO)?
Hard174When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?
Hard175Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?
Medium176Which of the following best describes the purpose of tactical risk reporting?
Medium177An IT risk report for the board of directors should primarily focus on:
Medium178A risk assessment identifies that a critical application has a vulnerability with a high likelihood of exploitation. The risk owner proposes to implement a web application firewall (WAF) as a mitigating control. Which TWO of the following are likely benefits of this control?
Medium179Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)
Medium180Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you discover that the target company uses a legacy ERP system that is no longer supported by the vendor. They have no disaster recovery plan for this system, and it contains financial data critical to the merged entity. The integration timeline is aggressive, and replacing the system would delay the merger by 18 months. The executive team is reluctant to delay. What is the BEST risk treatment option?
Hard181An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:
Hard182A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?
Medium183A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?
Medium184A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)
Medium185Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)
Hard186A company is evaluating the risk of a data breach using the FAIR framework. The threat event frequency is estimated at 10 per year, and the vulnerability is 0.2. The primary loss per event is $50,000 and secondary loss is $20,000. What is the annualized loss expectancy (ALE)?
Medium187A company has a low risk appetite but high risk tolerance. Which of the following scenarios is consistent with this situation?
Hard188An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?
Hard189A risk practitioner discovers that a critical control deficiency has been open for six months beyond the agreed remediation date. What is the MOST appropriate reporting action?
Easy190A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?
Easy191A risk manager notices that a key risk indicator (KRI) for system downtime has exceeded the threshold for two consecutive months. What is the MOST appropriate immediate action?
Easy192A company implements a new automated control to monitor user access rights. The control sends a daily report of any users with excessive privileges. What is the PRIMARY benefit of this control?
Easy193Which of the following is the BEST indicator that an organization's IT risk assessment process is effective?
Easy194An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?
Hard195A healthcare organization is implementing a new electronic health records (EHR) system. During the risk assessment, the risk practitioner discovers that the system's access control mechanism allows any authenticated user to view patient records without additional authorization checks. This violates the principle of least privilege and could lead to unauthorized disclosure of protected health information (PHI). The IT team proposes implementing role-based access control (RBAC), but it will require significant changes to the system configuration and user training. The project manager is concerned about delays to the go-live date. The organization has a moderate risk appetite but must comply with HIPAA regulations. Which of the following actions should the risk practitioner recommend FIRST?
Medium196A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?
Hard197An organization uses AI/ML for credit scoring decisions. The risk manager is concerned about regulatory compliance if the model cannot explain its decisions. Which AI risk is most directly addressed by requiring explainability?
Hard198An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:
Medium199An organization is implementing a new identity and access management (IAM) system. The risk manager is tasked with identifying risks associated with the migration from legacy authentication to single sign-on (SSO). Which of the following is the GREATEST risk during this migration?
Easy200An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?
Medium201Which THREE of the following are typical components of a risk scenario?
Hard202An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?
Medium203Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?
Medium204A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?
Hard205An organization is assessing the risk of a ransomware attack. The threat actor capability is high, but vulnerability is low due to strong patching. However, the business impact is severe. According to FAIR, which factor most directly influences Loss Event Frequency (LEF)?
Hard206During a risk assessment, an organization identifies that its remote workforce uses personal devices for work. The risk manager is concerned about data leakage. The organization has a risk appetite that is 'moderate' and wants to treat the risk. Which of the following is the MOST effective risk treatment option?
Hard207Which TWO of the following are key elements that should be included in an IT risk assessment report?
Easy208A large healthcare organization is implementing a new electronic health record (EHR) system. During the risk identification process, the risk team discovers that the EHR vendor has a history of minor security incidents but has always resolved them quickly. The vendor’s data center is located in a region prone to earthquakes. Additionally, the EHR system will integrate with several legacy systems that have known vulnerabilities. The project sponsor is keen to proceed and believes the vendor is reputable. The risk team needs to ensure all relevant risks are identified and documented. Which of the following should be the PRIORITY for the risk team?
Medium209A financial institution uses a third-party cloud service for data analytics. The service has access to non-public personal information (NPI). During a risk assessment, the risk manager discovers that the cloud provider uses subprocessors without notifying the institution. The contract does not require notification of subprocessor changes. What should the risk manager do FIRST?
Medium210A financial institution is integrating a new cloud-based analytics platform that will process sensitive customer data. The project team is conducting risk identification. Which technique would be MOST effective for identifying risks related to the integration of this platform with existing on-premises systems?
Hard211During a risk assessment for a cloud migration project, the IT risk manager identifies that the organization lacks visibility into the cloud provider's security controls. Which approach should the risk manager recommend to address this risk?
Medium212In qualitative risk analysis, a risk with a likelihood rating of 'High' and an impact rating of 'High' on a 5×5 heat map would typically be classified as:
Medium213During a control self-assessment, an operational manager reports that a manual review control is performed quarterly instead of monthly as documented. What should the risk practitioner do?
Easy214A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?
Easy215A risk manager is assessing the risks of an IT/OT convergence project in a chemical plant. Which TWO of the following are the most significant security risks? (Select two.)
Medium216An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?
Medium217A company uses a dashboard to monitor KRIs. One KRI shows a warning level, but the data is two months old. What is the primary concern?
Hard218Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?
Easy219Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?
Easy220A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?
Hard221Refer to the exhibit. What risk is introduced by this IAM policy?
Hard222After a security incident, a company implements a new control and begins monitoring its effectiveness. Which of the following metrics would BEST indicate that the control is achieving its objective?
Medium223A bank's fraud detection system generates an alert for a transaction, but subsequent investigation finds it false. What should be done?
Medium224An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?
Medium225Refer to the exhibit. A risk practitioner is reviewing the access control list for a critical server. The ACL is applied inbound on the interface connecting to the internet. Which of the following is the MOST significant risk?
Easy226During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?
Medium227After implementing a new access control system, the IT risk manager needs to measure its effectiveness. Which THREE of the following are Key Control Indicators (KCIs) that would be appropriate?
Medium228A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?
Medium229Refer to the exhibit. An organization uses this firewall access list. What is the MOST significant risk associated with this configuration?
Medium230A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?
Medium231Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?
Medium232An organization is selecting a control to prevent unauthorized access to a critical database. Which control type is most appropriate?
Easy233A risk manager uses a 5x5 heat map to plot the likelihood and impact of identified risks. This approach is an example of which type of risk analysis?
Easy234A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?
Hard235A company operates a legacy system for which the vendor no longer provides security patches. What is the most critical risk to identify regarding this system?
Medium236A risk practitioner is identifying vulnerabilities in an organization's IT environment. Which TWO of the following are examples of 'operational vulnerability identification'? (Choose two.)
Medium237A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?
Medium238An organization is implementing a new control to address a high-risk finding. The project manager has scheduled a user training session and updated the relevant policies. Which implementation phase is being addressed?
Hard239Based on the exhibit, which of the following is the MOST likely risk scenario?
Easy240A company is evaluating control effectiveness for a critical system. The control fails 10% of the time when tested. The inherent risk level is 'high'. What is the effect on residual risk?
Hard241Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?
Easy242A company has a control that automatically rejects transactions over $10,000. During a review, it is found that 2% of transactions over $10,000 were approved due to a system glitch. The control owner says the glitch has been fixed. What should the risk practitioner do next?
Hard243A risk manager is reviewing the control monitoring reports and finds that a key control's effectiveness rating has dropped from 'effective' to 'partially effective' due to increased errors in manual data entry. Which of the following is the BEST course of action?
Hard244Which of the following is the BEST example of a key risk indicator (KRI) for the risk of unauthorized access to sensitive data?
Easy245An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?
Medium246During a quantitative risk analysis, the risk team calculates the loss event frequency (LEF) using the FAIR framework. If the threat event frequency (TEF) is 10 per year and the vulnerability (V) is 0.3, what is the LEF?
Hard247A manufacturing company's board of directors receives a monthly risk report. Which key performance indicator (KPI) is MOST relevant for the board to assess the effectiveness of internal controls?
Easy248An IT risk manager is facilitating a brainstorming session to identify threats. Which technique is BEST suited for identifying a wide range of potential threats?
Easy249During a risk assessment, the risk team identifies that a legacy system has multiple known vulnerabilities that cannot be patched. The system is critical for operations. Which of the following risk treatment options is MOST appropriate?
Hard250An organization has an inherent risk score of 20 for a process. After controls, the residual risk score is 8. If the control design is assessed as adequate but operating effectiveness is only 60%, what is the control effectiveness adjustment?
Hard251An organization is conducting a risk assessment of its remote access infrastructure. Which THREE of the following are typical components of a risk assessment report? (Select THREE.)
Medium252A financial institution uses threat intelligence from an Information Sharing and Analysis Center (ISAC). This is an example of which type of threat intelligence source?
Medium253A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?
Hard254A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?
Medium255A change to a critical application is being implemented without updating the associated security controls. This is most likely a failure in which process?
Hard256A multinational corporation is expanding its cloud infrastructure to include a new SaaS application that stores sensitive customer data. The vendor claims compliance with SOC 2 Type II and ISO 27001. The risk manager must determine if the remaining residual risk after vendor controls is within the company's risk appetite. Which of the following is the MOST critical next step?
Hard257A risk analyst is reviewing control monitoring results and notices that a detective control has a high false positive rate. What is the BEST action to improve the control's efficiency?
Easy258A company is conducting a risk assessment of a critical third-party service provider. Which of the following is the BEST source of information to identify risks associated with the provider's sub-processors?
Medium259Refer to the exhibit. A risk manager is reviewing IAM policies for an S3 bucket used for sensitive data. This policy allows which of the following?
Hard260Which TWO controls are most effective for reducing the risk of data leakage from endpoints in a remote work environment?
Medium261A risk practitioner is designing a monitoring dashboard for operational risk. Which of the following is the most important consideration?
Medium262During an IT risk assessment for a new cloud-based customer relationship management (CRM) system, the risk practitioner identifies that the vendor's data center is located in a country with different data protection regulations. Which of the following is the MOST appropriate next step?
Medium263An organization uses a risk register that includes inherent risk, control effectiveness, and residual risk. During a quarterly review, the risk owner updates control effectiveness from 'partially effective' to 'effective'. What effect does this have on the residual risk rating?
Hard264A control owner reports that a preventive control is operating as designed, but the risk owner is concerned that residual risk remains high. What should the risk practitioner do NEXT?
Easy265Which TWO of the following are leading indicators that could be used as KRIs for information security risk? (Select TWO.)
Medium266When performing asset-based vulnerability identification, a security analyst uses the Common Vulnerabilities and Exposures (CVE) database along with the National Vulnerability Database (NVD). Which of the following BEST describes the relationship between CVE and NVD?
Hard267Which of the following best describes residual risk?
Easy268An international bank is expanding its operations into a new country with strict data localization laws. The IT department plans to use a cloud service provider that stores data in neighboring countries but promises compliance. The risk team has identified several potential risks: regulatory fines for non-compliance, data interception during cross-border transmission, and difficulty in auditing the cloud provider. The legal team advises that the contract includes data protection clauses, but these have not been tested. The risk manager must now prioritize risk identification efforts. What is the MOST important risk identification step the risk team should undertake?
Hard269An organization uses automated SIEM rules to continuously monitor for unauthorized access attempts. This is an example of which type of monitoring?
Easy270Which risk identification technique relies on analyzing past incidents to predict future risks?
Easy271An organization is considering moving from periodic control testing to continuous monitoring for its critical financial controls. What is the PRIMARY benefit of this transition?
Hard272A vendor risk tier is assigned based on data access and service criticality. A vendor that processes sensitive customer data and is critical to operations should be classified as which tier?
Medium273An organization is performing a business impact analysis (BIA) for its critical applications. Which TWO of the following are primary objectives of a BIA?
Easy274Which risk treatment option involves eliminating the activity that creates the risk?
Easy275Refer to the exhibit. What is the most appropriate immediate action for the control failure?
Medium276A risk assessment identifies a high-likelihood, high-impact risk associated with a legacy system. The business owner decides to decommission the system to eliminate the risk. Which risk treatment option is being applied?
Medium277Refer to the exhibit. What action should the risk practitioner recommend FIRST?
Easy278In a risk report presented to the board of directors, which of the following elements is most appropriate to include?
Medium279A security operations center (SOC) uses a Security Information and Event Management (SIEM) system to continuously monitor for suspicious activities. Which type of monitoring is being performed?
Medium280A business continuity manager wants to identify risks that could disrupt critical business processes. Which source of information would be MOST valuable for identifying such risks?
Medium281A software development company uses a DevOps pipeline with automated code deployment. Recently, a developer accidentally pushed a configuration file containing database credentials to a public repository. The credentials were changed within an hour, but the file remained public for a few hours. The risk team is now identifying risks in the CI/CD process. The security team has proposed adding static code analysis to detect secrets in code. The development team objects, citing false positives. The risk manager must identify the most significant risk that could lead to a data breach. Which risk should be prioritized?
Hard282A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
Easy283A risk assessment reveals that a legacy system has a high vulnerability score but low business criticality. The cost to remediate is high. What is the MOST appropriate risk response?
Medium284An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?
Medium285A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?
Hard286What is the most significant risk identified by this configuration?
Hard287A financial institution is assessing the risk of a new real-time payment system. The risk manager calculates that the annualized loss expectancy (ALE) for a potential fraud scenario is $500,000. The cost to implement a fraud detection solution is $200,000 initially with $50,000 annual maintenance. The solution is expected to reduce the ALE by 80%. What is the net benefit of implementing the solution over three years?
Hard288Which type of control is designed to operate before an event to prevent an undesirable outcome?
Easy289Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?
Medium290A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?
Medium291A risk practitioner is reviewing the results of a control self-assessment (CSA) and finds that the control owner rated a control as 'effective' but an independent audit found control weaknesses. What is the BEST explanation for this discrepancy?
Hard292In the FAIR model, 'Loss Event Frequency' is calculated as:
Hard293An organization uses the FAIR framework to assess the risk of a data breach. The risk analyst estimates that the Threat Event Frequency (TEF) is 10 per year, the Vulnerability (V) is 0.2, the Primary Loss per event is $50,000, and the Secondary Loss per event is $30,000. What is the Annualized Loss Expectancy (ALE)?
Hard294Which TWO of the following are examples of continuous monitoring techniques for IT controls? (Select TWO)
Easy295A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?
Hard296An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?
Hard297Refer to the exhibit. Which risk is MOST directly identified?
Easy298An organization uses a risk appetite statement that limits operational losses to $2 million per quarter. A new risk reporting dashboard shows that current operational losses are $1.8 million with two weeks remaining in the quarter. The head of risk management wants to ensure that losses remain within appetite. Which of the following control monitoring reports would be MOST useful for proactive decision-making?
Hard299Match each risk management process step to its activity.
Medium300Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?
Easy301A large organization is implementing a continuous monitoring program for its critical systems. Which of the following is the MOST important factor for the program's success?
Hard302A financial institution is implementing a new real-time payment system that will process high-value transactions. To identify emerging risks, which method would be MOST effective during the development phase?
Hard303During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?
Easy304An organization uses the FAIR framework to calculate annualized loss expectancy (ALE) for a specific risk. Given that the single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2, what is the ALE?
Medium305Which TWO of the following are considered direct costs in the financial impact assessment of a risk event?
Hard306Which TWO of the following are examples of risk mitigation controls?
Easy307Which TWO of the following are valid reasons to accept a risk rather than mitigate it?
Hard308Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)
Easy309Which of the following is an example of a leading indicator?
Easy310During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control is expected to reduce the ALE by 80% and will cost $150,000 per year. What is the net benefit of implementing the control?
Medium311An organization is implementing a new cloud-based customer relationship management (CRM) system. The risk practitioner is designing the control monitoring plan. Which approach BEST ensures continuous monitoring of controls across both the application and infrastructure layers?
Hard312An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?
Hard313A risk manager is using a 5x5 heat map to assess IT risks. Which of the following best describes the primary limitation of this qualitative risk analysis approach?
Easy314Which THREE of the following are effective risk treatment strategies?
Hard315Which of the following best describes the primary limitation of qualitative risk analysis?
Medium316A quantitative risk analysis using FAIR requires estimating which THREE primary factors?
Hard317A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?
Hard318Which TWO of the following are examples of control monitoring activities?
Easy319When prioritizing risk treatment actions, which of the following should be the primary consideration?
Medium320An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:
Hard321A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)
Easy322Which TWO of the following are examples of operational vulnerabilities that a risk practitioner might identify?
Easy323An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?
Hard324A risk analyst is assessing the impact of a potential ransomware attack. Which THREE categories of business impact should be considered?
Medium325You are the risk manager for a multinational corporation that relies heavily on a cloud-based ERP system. The system is critical for financial reporting and supply chain management. Recently, the company experienced a significant increase in the number of failed user authentication attempts, which were traced to a misconfiguration in the identity management module. The misconfiguration was detected by the security operations center (SOC) through log analysis, but it took three days to identify and resolve. The root cause was a change made by a cloud administrator without following the change management process. The incident resulted in a temporary denial of service for external users. The company's risk appetite for system availability is low, with a tolerance for downtime of no more than one hour per month. The current monitoring controls include quarterly access reviews and SOC monitoring of logs with a 24-hour review cycle. The board has requested a report on the incident and recommendations to prevent recurrence. What is the MOST effective recommendation to improve monitoring and reduce the likelihood of similar incidents?
Hard326Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)
Hard327Which of the following is an example of a detective control in IT risk management?
Easy328A financial institution has a control that manually reviews all wire transfers over $10,000. During an audit, it was found that the review is completed within 24 hours for 95% of transactions, but the target is 99%. The process owner wants to improve the control's effectiveness. Which of the following would be the MOST effective remediation?
Hard329Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?
Hard330A risk manager notices that a key risk indicator (KRI) for network downtime has been steadily increasing over the past three months. The current value is 15% above the risk tolerance threshold. Which of the following is the BEST immediate action?
Easy331An IT risk manager is facilitating a workshop to identify risks for a new mobile banking application. Which technique is MOST appropriate for generating a comprehensive list of risks?
Easy332A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?
Hard333A retail company uses a legacy inventory system that is no longer supported by the vendor. The IT department is planning to migrate to a modern cloud-based system. During risk identification, which of the following should be considered a PRIMARY risk?
Easy334An IT risk manager is performing a risk assessment for a new cloud service. Which TWO of the following are key inputs to the risk identification process? (Select TWO.)
Medium335An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)
Hard336A risk practitioner is identifying risks related to a new API gateway implementation. Which TWO of the following are MOST likely to be significant risks?
Easy337Which TWO of the following are examples of detective controls?
Medium338An organization has a risk indicator that shows the number of failed login attempts per day. The threshold is 100. Last week, the number spiked to 200 on two days. What does this indicate?
Easy339You are the IT risk manager for a financial institution. During a routine vulnerability scan, you discover that a critical web application has a high-severity vulnerability that could allow remote code execution. The development team states that a patch is not yet available from the vendor, and the application is business-critical with no acceptable downtime. The risk owner wants to accept the risk. However, the organization's risk appetite is very low for security vulnerabilities. You have been asked to recommend a course of action. Which of the following should you recommend?
Medium340During a risk assessment for a cloud migration project, the risk team identifies that the new SaaS application has not been tested for interoperability with existing identity management systems. The project manager argues that the integration will be straightforward and asks to remove this from the risk register. Which of the following is the BEST response from the risk practitioner?
Medium341During a third-party risk management review, the organization is tiering its vendors based on risk. Which TWO of the following criteria are most relevant for determining vendor risk tier?
Medium342An IT risk manager is preparing a quarterly risk report for the CISO. Which type of reporting structure does this represent?
Medium343During a risk assessment, a risk owner is unsure about the likelihood rating for a specific threat. Which of the following is the BEST source of information to determine the likelihood?
Easy344A company is implementing a new cloud-based customer relationship management (CRM) system. The IT risk manager needs to assess the risk of data exfiltration by a malicious insider at the cloud provider. Which risk assessment approach is most appropriate for this scenario?
Medium345A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?
Hard346A control owner reports that a control is operating effectively, but the internal audit found a deficiency. What should the risk manager do?
Medium347Which of the following is the BEST indicator that a control is effective in mitigating a risk?
Easy348A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?
Hard349An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)
Hard350An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?
Hard351An organization is evaluating threat intelligence feeds to improve IT risk identification. Which of the following criteria should be given the HIGHEST priority when selecting a feed?
Hard352Order the steps for implementing a risk treatment plan.
Medium353An organization is developing an IT risk universe. Which of the following is the PRIMARY purpose of creating a comprehensive IT risk universe?
Medium354A company has identified a risk of data exfiltration through an outdated encryption protocol. The risk assessment team determines that the likelihood is low, but the impact is very high. The company decides to update the encryption protocol. This risk response is an example of:
Medium355An organization is performing a risk assessment for its new customer relationship management (CRM) system. Which of the following is the BEST way to identify threats to the CRM?
Easy356A vulnerability scan of the internal network reveals a critical vulnerability in a legacy application that cannot be patched immediately. What is the FIRST step the risk practitioner should take?
Easy357Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA) during the IT risk assessment process?
Easy358Which TWO of the following are examples of risk avoidance?
Medium359Which TWO of the following are characteristics of an effective key risk indicator (KRI)?
Medium360A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?
Medium361A risk practitioner is facilitating a workshop to identify IT risks for a new product launch. Which technique BEST encourages participants to think about risks from different perspectives?
Easy362You are the risk manager at a financial institution that processes online transactions. The organization relies on a legacy system for transaction authorization, which is monitored via manual log reviews performed weekly by a junior analyst. Recently, the internal audit team identified that several unauthorized transactions were not detected for over two weeks. The logs showed that the authorization control failed intermittently due to a known software bug, but the bug had been documented in the risk register with a low residual risk rating. The CRO asks you to recommend the most effective improvement to the control monitoring process. Which of the following would be the BEST course of action?
Easy363In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?
Easy364During a risk assessment, an organization identifies that its primary data center is located in a flood-prone area. Which risk treatment option would best address this risk?
Medium365During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)
Medium366In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy367A multinational e-commerce company has experienced multiple security incidents involving unauthorized access to customer payment data. The incidents originated from different regional offices and exploited misconfigured firewall rules. The risk manager needs to identify the root cause of these risks. Which approach would BEST help in identifying the root cause of the IT risk?
Medium368According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?
Easy369An organization is updating its IT risk universe to include emerging threats. The CISO wants to ensure the risk register captures realistic risk scenarios. Which THREE components are essential for constructing a complete risk scenario according to ISACA's risk scenario template?
Hard370Which THREE of the following should be included in a board-level risk report to effectively communicate the organization's risk profile?
Hard371During a risk assessment, a financial institution identifies that its online banking application uses an outdated encryption protocol. The likelihood of exploitation is high, and the impact is moderate. What should the risk owner do FIRST?
Medium372A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?
Medium373Based on the firewall log exhibit, which of the following conclusions is MOST appropriate for risk identification?
Hard374Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?
Easy375Which of the following is a key element of promoting a risk-aware culture within an IT department?
Medium376Which THREE of the following are characteristics of leading key risk indicators (KRIs)?
Medium377During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?
Medium378A new web application is being developed using several open-source libraries. Which risk identification method is most effective for identifying vulnerabilities in these libraries?
Medium379A SIEM generates alerts for the following events. Which TWO events should be considered potential emerging risks? (Select exactly 2.)
Easy380Based on the exhibit, which of the following poses the HIGHEST risk to the environment?
Hard381A risk manager is designing monthly risk reports for senior management. Which THREE of the following should be included in an effective risk report? (Choose three.)
Easy382In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?
Medium383A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?
Hard384A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?
Easy385A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?
Hard386A company is implementing a new continuous monitoring tool for its network security controls. Which of the following is the MOST important step to ensure the tool provides meaningful risk information?
Medium387During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?
Hard388A risk practitioner is reviewing the monitoring reports for a critical business process. The report shows that a key control has a 95% effectiveness rate, but the risk appetite for the associated risk is 98%. What should the practitioner do?
Medium389An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?
Medium390A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of the following risk identification techniques should the risk manager use to understand the full extent of the risk?
Hard391Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?
Easy392A risk assessment for a financial trading platform has identified a high-risk vulnerability in the order matching engine. The risk owner has recommended implementing compensating controls rather than fixing the underlying code. Which TWO of the following are valid compensating controls? (Choose two.)
Medium393A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?
Hard394Which TWO of the following are primary sources of risk identification for IT projects? (Select exactly 2.)
Easy395During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?
Hard396Based on the exhibit, what is the primary risk to the organization?
Medium397Which THREE of the following are best practices for reporting risk and control monitoring results to stakeholders?
Hard398A government agency is migrating its critical applications to a public cloud infrastructure. The risk assessment reveals that the cloud provider uses shared tenancy, and the agency's sensitive data will be stored alongside other customers' data. The agency has a very low risk appetite for data leakage and must comply with strict data sovereignty laws. The cloud provider offers data encryption at rest and in transit, as well as dedicated hardware security modules (HSMs) for key management. However, the provider's physical datacenters are located in another country with different legal frameworks. As the risk practitioner, which of the following should be the PRIMARY risk response?
Hard399When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:
Hard400An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?
Medium401A retail company uses a third-party vendor for payment processing. The vendor's service level agreement (SLA) requires 99.9% uptime. Recently, there were two incidents of downtime totaling 0.2% in a month, still within the SLA. However, the company's internal risk monitoring detected a pattern of increasing minor incidents. The vendor insists the SLA is met. The risk manager must decide on monitoring and reporting. The company's board wants to understand the risk. What is the best course of action?
Medium402A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?
Easy403During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?
Medium404An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?
Easy405Which TWO of the following are valid techniques for identifying risk in IT risk assessment?
Hard406When implementing a new control, which of the following is the most important factor in ensuring its long-term effectiveness?
Easy407A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?
Medium408An organization's risk register contains a scenario: 'A nation-state actor exploits an unpatched vulnerability in a public-facing web application, leading to data exfiltration of customer PII.' According to ISACA's risk scenario template, which element is MISSING from this description?
Hard409An organization is reviewing its IT risk management program and identifies that the risk register is not being updated after project changes. Which TWO components of the risk management program are most likely deficient?
Medium410An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?
Medium411During an IT risk assessment, the risk team calculates the Annualized Loss Expectancy (ALE) for a critical application. Which quantitative risk analysis framework is most commonly used for this calculation?
Medium412Which of the following is the PRIMARY purpose of a risk register?
Easy413A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?
Hard414An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)
Hard415Order the steps for change management in an IT environment.
Medium416A financial services company is implementing a new control to mitigate the risk of unauthorized access to customer data. Which TWO of the following are key factors to consider during the control design phase?
Medium417The exhibit shows a control monitoring configuration in JSON format. Which of the following is the MOST critical gap in this monitoring setup?
Medium418Which TWO of the following are appropriate actions when a control deficiency is identified during monitoring? (Select exactly two.)
Medium419An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?
Medium420During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?
Hard421An organization maintains a risk register. Which of the following updates should be made on an ongoing basis?
Medium422A risk analyst is performing a quantitative risk analysis using the FAIR framework. Which TWO factors are multiplied to calculate Loss Event Frequency (LEF)?
Medium423A retail company recently deployed a point-of-sale (POS) system that processes credit card transactions. The system is connected to the corporate network and transmits transaction data to a payment processor over the internet. During a risk assessment, the IT risk manager identifies that the POS system is vulnerable to malware injection via unvalidated input from barcode scanners. Which of the following is the MOST appropriate risk mitigation strategy?
Medium424Match each control type to its example.
Medium425Which TWO of the following are primary techniques for identifying IT risks in an organization? (Choose two.)
Medium426In the FAIR framework, which of the following correctly represents the calculation of Loss Event Frequency (LEF)?
Hard427Which type of control is designed to stop an undesirable event from occurring?
Easy428In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?
Hard429Based on the exhibit, which risk response should be prioritized?
Medium430A risk practitioner is evaluating the effectiveness of existing risk mitigation controls for a critical financial application. Which THREE of the following are key indicators that controls are operating effectively?
Hard431A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?
Medium432A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?
Medium433A company's control monitoring shows that a detective control has been 100% effective for the past year. However, a recent incident revealed that a data breach went undetected for three months. What is the MOST likely cause?
Hard434Which TWO of the following are characteristics of quantitative risk analysis compared to qualitative risk analysis? (Select 2)
Hard435An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?
Hard436When performing a risk assessment, which TWO of the following are components of inherent risk?
Easy437During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?
Medium438During a risk identification workshop, a risk owner proposes a scenario: 'A disgruntled employee with privileged access exfiltrates customer data to a competitor.' In the context of the ISACA risk scenario template, which element is missing if the scenario only includes the actor, threat type, event, and asset?
Hard439A manufacturing company uses an industrial control system (ICS) that is connected to the corporate network for monitoring. The risk manager is identifying risks related to this connectivity. Which of the following is the MOST significant risk?
Easy440A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?
Medium441An organization has implemented a new key risk indicator (KRI) for vendor management that measures the percentage of vendors without a signed contract. The current value is 15%, exceeding the risk appetite threshold of 10%. The risk owner wants to know the most appropriate action to take based on this KRI. What should the risk practitioner recommend?
Medium442Refer to the exhibit. Based on the risk register, which risk response is applied to the risk with the highest inherent risk?
Medium443Match each risk response strategy to its definition.
Medium444During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)
Hard445A risk officer is evaluating the effectiveness of a control that prevents unauthorized changes to configuration files. The control has not detected any unauthorized changes in the past year. What does this indicate?
Medium446A risk practitioner is analyzing the results of a phishing simulation. The simulation had a 15% click rate on a test email targeting finance department staff. Which of the following conclusions is MOST valid regarding IT risk identification?
Hard447Which THREE of the following are effective risk identification techniques for a cloud migration project? (Select exactly THREE.)
Hard448An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?
Easy449A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?
Medium450An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?
Medium451Which TWO methods are commonly used for continuous monitoring of IT controls?
Medium452A medium-sized e-commerce company recently experienced a denial-of-service (DoS) attack that took down its website for two hours. The incident response team quickly mitigated the attack by blocking the source IPs. In the aftermath, the risk manager is tasked with identifying risks to prevent recurrence. The company relies heavily on a single internet service provider (ISP) and has no DDoS protection service. The IT director suggests purchasing additional server capacity to absorb future attacks. The CEO is concerned about the cost. The risk team has identified that the likelihood of a similar attack is high based on recent industry trends, and the impact includes lost revenue and customer trust. What is the MOST effective risk identification action the risk team should take next?
Easy453An organization uses control self-assessments (CSAs) as part of its monitoring program. The results from the latest CSA show that the majority of controls are rated as effective, but an internal audit reveals several control failures in those same areas. What is the MOST likely reason for this discrepancy?
Easy454A company is updating its risk register. Which of the following is the primary purpose of a risk register?
Medium455An IAM policy grants an external auditor user permission to read objects from a sensitive data bucket, with no location restrictions. What risk does this indicate?
Hard456A company's risk management team is evaluating the effectiveness of its control monitoring program. They find that many controls are tested at the same time each year, leading to a resource bottleneck. Which of the following approaches would BEST address this issue?
Hard457During a quantitative risk analysis, the risk practitioner determines that the single loss expectancy (SLE) for a ransomware attack is $500,000 and the annualized rate of occurrence (ARO) is 0.4. The organization has a risk appetite that accepts annual losses up to $150,000. What is the recommended action?
Hard458After a risk assessment, the risk owner decides to mitigate a high-risk finding by implementing additional access controls. What should the risk manager do NEXT?
Medium459A company's risk assessment identifies that a threat actor has high capability and motivation to exploit a vulnerability. Which factor does this relate to?
Medium460A multinational corporation is conducting a risk assessment for its new online payment platform. The platform processes transactions in multiple currencies and stores sensitive customer financial data. The risk team has identified that the encryption algorithm used for data at rest is outdated and could be vulnerable to advanced attacks. The company's risk appetite is low for data breaches. The security team recommends upgrading the encryption to a modern standard, but the upgrade will require a 48-hour downtime impacting all global transactions. The business unit is concerned about revenue loss during the downtime. As the risk practitioner, what is the BEST course of action to balance security and business continuity?
Easy461Refer to the exhibit. Based on the KRI data for the current week, what action should the risk manager take FIRST?
Easy462Refer to the exhibit. Given the organization's risk appetite is Low, which risk response is most appropriate?
Hard463During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Medium464Order the steps for incident response handling.
Medium465An organization is designing a control monitoring program. Which THREE of the following are types of control monitoring activities that should be included?
Hard466An IT risk assessment team is using a 5×5 risk matrix with likelihood and impact ratings. A risk scenario is rated as likelihood = 4 (likely) and impact = 5 (catastrophic). According to the typical heat map, what would be the risk rating?
Easy467After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
Medium468Which TWO of the following are key outputs of a risk assessment process?
Medium469Which of the following is a detective control for an information system?
Easy470Which TWO of the following are characteristics of an effective key risk indicator (KRI)?
Medium471An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?
Medium472An organization uses a risk and control monitoring system that generates weekly reports. The reports show a key control as 'effective' for the past three months. However, during a recent audit, a significant control failure was discovered. Which TWO of the following are MOST likely root causes for this discrepancy? (Choose two.)
Hard473An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?
Hard474A risk manager is evaluating the risk associated with a new third-party vendor that will have access to customer data. The vendor has been in business for 10 years and holds ISO 27001 certification. Which factor should be given the MOST weight when determining the vendor's risk level?
Medium475An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?
Medium476Which risk assessment method uses a matrix to plot likelihood and impact to determine risk level?
Easy477An organization uses a third-party vendor for payment processing. The vendor's latest SOC 2 report shows a significant control exception in logical access. What is the BEST way to monitor the effectiveness of the compensating controls the vendor has implemented?
Medium478An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?
Medium479A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?
Hard480Which TWO of the following are appropriate criteria for selecting key risk indicators (KRIs)?
Medium481A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?
Easy482Arrange the steps for performing a vulnerability assessment.
Medium483Which risk treatment option involves eliminating the activity that creates the risk?
Easy484Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?
Easy485When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?
Medium486During a quarterly IT risk review, the risk manager presents a risk heat map. Which TWO of the following elements should be included in the report to provide a comprehensive view?
Hard487The policy requiring TLS 1.2 or higher for all data transmissions is intended to enforce what security control?
Hard488Which of the following is the PRIMARY purpose of a risk register?
Easy489A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?
Easy490Based on the exhibit, what control monitoring deficiency is evident in the DLP policy?
Hard491An organization is updating its asset inventory to improve IT risk identification. Which of the following asset attributes is MOST critical for assessing cybersecurity risk?
Easy492A software development team is adopting Agile methodology and wants to integrate risk identification into their sprints. Which approach BEST aligns with Agile principles while ensuring effective risk identification?
Hard493A bank is evaluating the impact of a potential system outage. Which of the following is an example of a direct financial cost associated with this impact?
Medium494A large enterprise uses a risk matrix with impact categories (very low, low, medium, high, very high) and likelihood (rare, unlikely, possible, likely, almost certain). A risk identified has a 'likely' likelihood and 'high' impact. According to the matrix, risks with this combination are classified as 'high' risk. The risk appetite statement requires that all high risks have a response plan within 30 days. However, the risk owner argues that due to effective compensating controls, the residual risk is only 'medium'. Which of the following is the BEST course of action?
Hard495Which of the following is the BEST indicator that a risk assessment should be performed outside the normal cycle?
Easy496A risk manager is designing a monitoring and reporting framework. Which THREE of the following are essential components of an effective risk and control monitoring program?
Easy497An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?
Medium498An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?
Medium499An organization has implemented a firewall (preventive), intrusion detection system (detective), and a backup restoration plan (corrective) to address a specific risk. The risk manager assesses the control effectiveness as follows: design adequacy is strong, but operating effectiveness is weak due to inconsistent patching. Which of the following best describes the residual risk?
Hard500During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?
Medium501A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?
Hard502Which risk treatment option involves purchasing cyber insurance?
Easy503Which threat actor is most likely motivated by political ideology and may target government systems?
Easy504A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?
Easy505An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?
Medium506Which TWO of the following are types of insider threats?
Easy507Which TWO of the following are key inputs to a risk assessment?
Easy508Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?
Easy509After implementing a set of controls, the risk owner calculates the residual risk. Which of the following is true about residual risk?
Medium510Which THREE of the following are key components of a risk assessment report?
Medium511Which TWO of the following are examples of risk avoidance? (Select TWO.)
Medium512A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?
Medium513A vendor is classified as 'critical' based on its access to sensitive data and the criticality of its service. According to best practices, what minimum security requirement should be mandated for this vendor?
Medium514A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?
Medium515A risk manager is evaluating the impact assessment for a potential data breach. Which THREE categories of impact should be considered in a comprehensive business impact analysis?
Hard516An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?
Hard517A SOC analyst observes repeated failed login attempts from an external IP address targeting a user account. What is the best next step in the IT risk identification process?
Easy518An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
Easy519An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?
Easy520An organization is designing a risk and control monitoring program for a new cloud-based application. Which of the following is the MOST important factor to consider when selecting Key Risk Indicators (KRIs)?
Medium521An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?
Medium522An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?
Medium523You are the IT risk manager for a mid-sized e-commerce company. The company processes credit card payments and stores customer data. Recently, the company experienced a security incident where an attacker exploited a SQL injection vulnerability in the web application, exfiltrating a database of customer records. The vulnerability was introduced three months ago during a feature upgrade. The development team claims they followed secure coding guidelines, but the vulnerability was missed due to insufficient testing. The company's risk appetite is moderate, and they have a risk management policy that requires risks to be treated within 30 days of identification. The CISO wants to know the most effective way to reduce the likelihood of similar incidents. You have assessed that the current risk score for web application vulnerabilities is 16 (High). The company has a bug bounty program, but it has not been effective. Which of the following courses of action would BEST address the root cause and reduce the risk?
Hard524A global financial services firm has implemented a risk monitoring system that aggregates data from 50+ systems across three regions (Americas, EMEA, APAC). The system uses a centralized data lake and provides dashboards to regional risk committees. Recently, the APAC committee reported that their dashboard shows a spike in cyber risk indicators, but the Americas and EMEA dashboards show no change. The data source for the spike is a single system in APAC that tracks failed VPN logins. The risk owner for that system believes the spike is due to a misconfiguration during a recent patch. However, the APAC risk committee is concerned that this indicates a coordinated attack. The Chief Risk Officer (CRO) wants a clear assessment. Which course of action is most appropriate?
Hard525A multinational corporation is migrating critical applications to a public cloud provider. The IT risk manager needs to design a risk assessment approach that addresses shared responsibility. Which of the following is the MOST appropriate approach?
Hard526Which TWO outcomes indicate that a risk assessment process is effective?
Easy527Which control type is primarily focused on identifying that a risk event has occurred?
Medium528A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts from the Asia-Pacific region has dropped significantly over the past week. Upon investigation, the log source status shows that 30% of the devices in that region have not sent any logs in 48 hours. What is the MOST likely cause?
Hard529Which TWO of the following are valid triggers for initiating a risk assessment outside the regular cycle? (Select 2)
Medium530Refer to the exhibit. What is the most likely risk indicated by this error log?
Easy531During a risk assessment, the risk practitioner discovers that a critical database does not have an active failover solution. The database is used by multiple business applications. Which of the following factors should be given the HIGHEST weight when determining the inherent risk level?
Medium532An organization wants to promote a risk-aware culture. Which TWO of the following initiatives are most effective for achieving this?
Easy533Which of the following threat actors is MOST likely to be motivated by ideology rather than financial gain?
Easy534A quantitative risk analysis for a data breach yields an Annualized Loss Expectancy (ALE) of $500,000. The Single Loss Expectancy (SLE) is $100,000. What is the Annualized Rate of Occurrence (ARO)?
Medium535A multinational corporation is developing a new e-commerce platform using microservices architecture. The security team is conducting a threat modeling exercise to identify potential application-level threats. Which TWO threat modeling methodologies are most appropriate for this DevSecOps environment?
Medium536A company uses cyber insurance to cover losses from data breaches. This is an example of which risk treatment?
Hard537Which TWO risk identification techniques are most appropriate for identifying emerging risks from new technologies?
Hard538After a security incident, an organization discovers that a critical database was accessed by an unauthorized user due to weak authentication controls. As part of the IT risk assessment process, which step should have identified this vulnerability?
Medium539A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?
Medium540An organization is implementing a new data loss prevention (DLP) solution. The risk manager is identifying potential risks related to the DLP solution itself. Which of the following is a risk that should be considered?
Easy541A company uses a DevOps approach with a continuous integration/continuous deployment (CI/CD) pipeline. Which risk identification technique is best suited for detecting code vulnerabilities early in the development lifecycle?
Medium542During a risk assessment of a web application, the risk owner identifies that the application uses outdated encryption algorithms. What is the most appropriate next step?
Easy543An organization has identified a new vulnerability in its web application that could allow SQL injection attacks. Which of the following sources would MOST likely have been used to identify this vulnerability?
Medium544A risk practitioner is updating the risk register and needs to categorize risks. Which TWO of the following are standard risk categories used in IT risk management?
Medium545An organization is developing a vendor risk management program. Which THREE activities should be included in the initial onboarding assessment for a high-risk vendor?
Hard546When prioritizing risk treatment actions, which of the following should be the primary consideration?
Medium547An organization is implementing a new control to address a high-risk vulnerability. Which TWO factors are MOST important to consider during the control implementation planning phase?
Medium548An organization is implementing a quantitative risk assessment for its customer database. Which TWO elements are essential for calculating the annualized loss expectancy (ALE)?
Hard549An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?
Hard550A company is identifying risks associated with a new cloud-based CRM. Which of the following is the MOST effective method for identifying potential threats?
Easy551Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?
Medium552The exhibit shows a warning from a control monitoring system. Based on the log, which of the following is the MOST likely control deficiency?
Hard553In a quantitative risk analysis, the annualized loss expectancy (ALE) is calculated as $1 million. If the organization implements a control that reduces the ARO from 0.5 to 0.1, and the SLE remains constant at $2 million, what is the new ALE?
Hard554An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?
Medium555A risk assessment team is calculating the Annual Loss Expectancy (ALE) for a critical server. The Single Loss Expectancy (SLE) is $50,000 and the Annual Rate of Occurrence (ARO) is estimated to be 2. The team is considering implementing a new backup solution costing $40,000 per year. Which TWO of the following statements are true regarding the cost-benefit analysis? (Select TWO.)
Hard556Which TWO of the following are primary factors that determine how often a risk assessment should be performed?
Medium557A healthcare organization is subject to strict regulatory requirements regarding patient data privacy. The organization has a control that requires all access to patient records to be logged and reviewed weekly by the compliance team. The review is currently performed manually by sampling 10% of the logs. The compliance team reports that the review takes 20 hours per week and they are often unable to complete it on time. As a result, some suspicious access patterns are detected weeks after they occur. The risk manager needs to propose an improvement to the monitoring process. The organization's risk appetite for undetected unauthorized access is very low. Which of the following is the MOST effective recommendation?
Medium558A large e-commerce company uses several key risk indicators (KRIs) to monitor credit card fraud. The risk committee noticed that one KRI has been trending above the threshold for three consecutive months, yet no risk response was initiated. Which of the following is the MOST likely root cause?
Medium559A risk assessment team is evaluating the effectiveness of existing controls for a critical application. Which of the following approaches best determines whether controls are operating as intended?
Medium560An organization is evaluating the risk of a data breach using the FAIR framework. The threat event frequency is estimated at 10 per year, the vulnerability is 0.2, and the loss magnitude is $500,000 per event. What is the annualized loss expectancy (ALE)?
Medium561An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?
Hard562Which of the following best describes the purpose of a risk heat map in an IT risk report?
Easy563Sequence the steps for implementing a new control based on risk assessment findings.
Medium564Which THREE of the following are key components of an IT risk assessment report as per ISACA guidelines?
Hard565A security team is using the STRIDE threat modeling methodology for a new web application. Which threat type under STRIDE would be MOST relevant to a SQL injection vulnerability?
Medium566A company uses a third-party SaaS application for payroll processing. What is the most important activity to identify IT risks associated with this service?
Easy567A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?
Hard568Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?
Easy569A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?
Medium570After a control self-assessment (CSA) workshop, business units reported that 80% of controls are operating effectively. However, internal audit's recent testing indicates a 30% control failure rate. What is the BEST explanation for this discrepancy?
Hard571An organization uses a third-party vendor for critical data processing. The vendor has experienced two minor security incidents in the past year with no data loss. The risk manager is updating the vendor risk assessment. Which approach best aligns with ISACA's guidance?
Hard572An organization has recently suffered a ransomware attack that encrypted critical files. During the post-incident review, the risk team is identifying key risk indicators (KRIs) to improve early detection. Which of the following KRIs would be MOST effective in detecting similar attacks in the future?
Hard573Which THREE of the following are indicators of potential IT risk in an organization? (Select exactly THREE.)
Easy574A global organization is consolidating risk data from multiple business units into a single enterprise risk management (ERM) system. The risk practitioner notices that KRIs for the same risk type (e.g., cybersecurity) are calculated differently across units. What is the BEST approach to ensure consistent and reliable risk monitoring and reporting?
Hard575During a risk assessment, the risk manager identifies a vulnerability in a web application that could allow SQL injection. The development team states they will fix it in the next release, which is six months away. What should the risk manager do?
Easy576A risk assessment report includes both inherent and residual risk ratings. The inherent risk for a process is rated as 'high' based on a 5×5 heat map. After applying a set of controls, the residual risk is rated as 'medium'. What does this indicate about the control effectiveness?
Medium577A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?
Hard578An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?
Medium579Which THREE of the following are common consequences in an IT risk scenario?
Medium580A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)
Medium581An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?
Medium582A company is prioritizing risk treatment actions. Which THREE factors should be considered when prioritizing risks?
Medium583Refer to the exhibit. A risk analyst is reviewing an AWS S3 bucket policy. What is the MOST significant control monitoring gap in this policy?
Hard584When implementing a new access control system, which activity is essential during the change management process?
Easy585Which THREE of the following are key components of an effective risk reporting framework?
Hard586A critical infrastructure organization is enhancing its threat identification capabilities. The risk team wants to leverage threat intelligence sources to identify emerging threats. Which THREE sources are most relevant for obtaining actionable threat intelligence?
Hard587A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?
Medium588Which THREE of the following are valid risk response options according to the ISACA risk management framework? (Select 3)
Easy589A large e-commerce company is assessing the risk of a distributed denial-of-service (DDoS) attack on its web applications. The company has experienced three DDoS attacks in the past year, each causing significant downtime and revenue loss. The current mitigation strategy relies on an on-premise appliance that can handle up to 10 Gbps of attack traffic. Recent industry reports indicate that DDoS attacks are growing in volume and sophistication, with some exceeding 100 Gbps. The company's risk appetite for availability is moderate. The security team has proposed migrating to a cloud-based DDoS protection service that scales to 200 Gbps, but it will increase annual operational costs by 40%. The business is concerned about the cost increase. Which of the following is the BEST risk treatment decision?
Hard590Which TWO of the following are examples of detective controls?
Easy591A company has identified a risk of data breach due to weak encryption. The current controls include encryption at rest but not in transit. The risk assessment team calculates inherent risk as high and residual risk as high. What should the team recommend FIRST?
Medium592A project manager is identifying risks for a new software development project using Agile methodology. Which THREE threat modeling techniques are BEST suited for Agile/DevSecOps environments?
Hard593A risk assessor is evaluating a third-party cloud service provider. Which of the following is the MOST important factor to consider when assessing the risk of data exfiltration?
Hard594An organization recently experienced a significant security incident that was not detected by existing monitoring controls. The risk team is reviewing the effectiveness of the control monitoring framework. Which THREE of the following are key factors that should be evaluated to improve detection capabilities?
Medium595An organization is evaluating whether to accept a risk. Which TWO conditions must be met for risk acceptance to be appropriate?
Medium596Put the steps for developing an information security policy in order.
Medium597An organization is evaluating cyber insurance to cover potential losses from ransomware attacks. The insurer requires that the organization have multi-factor authentication (MFA) on all remote access systems. This requirement is an example of which factor influencing insurance premiums?
Hard598A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?
Medium599Based on the exhibit, what is the PRIMARY risk associated with this cloud storage bucket policy?
Medium600A large bank has implemented a sophisticated risk and control monitoring system with multiple dashboards and automated reporting for key risk indicators (KRIs). However, the board of directors has been receiving conflicting KRI reports from different business units (e.g., retail banking, corporate lending, and wealth management). For example, the fraud KRI shows a high risk in retail but low risk in wealth management, yet both units use the same underlying data source. The chief risk officer (CRO) is concerned that the board is losing confidence in the risk reporting. An investigation reveals that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. What is the most likely root cause and the best remediation?
Hard601Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?
Medium602A risk assessment identifies a vulnerability in a critical application. The threat actor is a script kiddie with low capability. Using the FAIR framework, which factor would most directly increase the Loss Event Frequency (LEF)?
Medium603An organization wants to promote a risk-aware culture. Which initiative is most effective in encouraging employees to report security incidents without fear?
Hard604A risk practitioner is connecting a risk scenario to business impact. The scenario involves a ransomware attack that encrypts critical financial systems, resulting in a two-week outage. Which of the following is the MOST appropriate business impact category?
Hard605An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?
Medium606A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?
Hard607A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:
Hard608An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?
Medium609In a quantitative risk analysis using FAIR, which of the following best represents Loss Magnitude (LM)?
Medium610Which of the following is the primary purpose of a risk and control monitoring program?
Easy611An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?
Medium612For a risk with very low likelihood and low impact, what is the typical risk response?
Easy613An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?
Medium614A company is considering outsourcing its data center operations to a cloud provider. Which risk treatment option is the company primarily exercising?
Medium615Refer to the exhibit. Based on the exhibit, what is the most appropriate action regarding the control OWF?
Hard616An organization decides to discontinue a high-risk business process that cannot be effectively mitigated. This is an example of which risk treatment option?
Easy617In the context of threat modeling for a web application, which technique is specifically designed to be integrated into Agile and DevSecOps processes, emphasizing collaboration and visualization?
Hard618A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?
Hard619During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?
Hard620Which of the following best describes risk capacity?
Easy621What is the primary purpose of a control self-assessment (CSA)?
Easy622Which of the following is a key characteristic of a well-maintained risk register?
Easy623A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?
Medium624Which of the following is a key component of the NIST Cybersecurity Framework's Identify function?
Easy625A risk analyst uses a 5x5 heat map to evaluate a set of IT risks. For a particular risk, the likelihood is rated as 4 (likely) and impact as 5 (very high). What is the resulting risk rating?
Medium626In the context of ERM integration, IT risk is typically considered a subset of which broader risk category?
Medium627During a risk assessment, a risk practitioner identifies that a legacy application uses a deprecated encryption protocol. The application is critical for business operations and cannot be patched. Which of the following is the BEST approach to assess the risk?
Medium628A retail company monitors its key risk indicator (KRI) for credit card transaction fraud. The KRI has exceeded the established threshold for three consecutive days, but the weekly control performance report shows all fraud detection controls operating effectively. What should the risk practitioner do FIRST?
Medium629A risk practitioner is using the TRIKE threat modeling methodology. Which TWO of the following are characteristics of TRIKE?
Hard630You are the IT risk manager at a multinational corporation that recently migrated its customer database to a cloud-based platform. The database contains personally identifiable information (PII) subject to GDPR. During a routine vulnerability scan, you discover that the database is accessible from the internet without encryption (port 1433 open). The cloud provider's shared responsibility model indicates that securing the database configuration is the customer's responsibility. You have identified the risk as high likelihood and high impact. The business owner argues that the database is only accessible to a limited IP range and that encryption would degrade performance. Which course of action should you recommend to treat the risk?
Medium631A vendor risk manager is tiering vendors based on the criticality of services and data access. A vendor that processes sensitive customer data for a core business application should be classified as which tier?
Medium632A financial institution is evaluating the risk of a new mobile payment application. The risk team calculates the Annual Loss Expectancy (ALE) as $500,000 based on a single loss expectancy (SLE) of $100,000 and an annual rate of occurrence (ARO) of 5. After implementing a new encryption control at a cost of $150,000 per year, the ALE is reduced to $200,000. What is the residual risk in terms of ALE after one year of control operation?
Hard633During a quarterly risk review, the CISO notes that the number of failed authentication attempts has increased by 300% over the last month. The IT team confirms no changes to authentication systems. This metric is BEST categorized as which of the following?
Hard634Which of the following is an example of a corrective control?
Easy635Which of the following is a detective control?
Easy636Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?
Easy637An organization is implementing a new access control system. Which of the following is the MOST important consideration during the implementation phase?
Medium638A company has implemented a new control to detect unauthorized access attempts. What is the PRIMARY purpose of monitoring this control?
Easy639A database error log shows repeated login failures followed by a successful authentication. Which control failure is MOST likely?
Easy640Refer to the exhibit. During a risk identification exercise for the internal network, the risk manager reviews this firewall log entry. Which of the following risks is MOST directly suggested by this log entry?
Medium641After a risk assessment, the risk owner states that the residual risk for a specific asset is within the organization's risk tolerance. Which of the following BEST describes the action that should be taken?
Easy642Which TWO are primary objectives of IT risk identification?
Easy643An organization notices a spike in failed authentication attempts over the past week. This metric is best classified as which type of risk indicator?
Hard644An organization is using the OCTAVE method for risk identification. Which activity is typically performed FIRST?
Medium645A risk manager is facilitating a risk identification workshop for a new cloud migration initiative. Which TWO techniques are most effective for identifying potential IT risks at this stage?
Medium646A multinational corporation uses a common identity management system (IdM) across all subsidiaries. During a risk assessment, it is discovered that the IdM system has a critical vulnerability that could allow privilege escalation. The patch requires a 4-hour downtime. The risk manager must decide the best course of action considering the organization's risk appetite of 'low' and the fact that the IdM system is critical for business operations. Which of the following is the BEST approach?
Hard647A risk practitioner is using a 5×5 heat map with likelihood and impact ratings. Which of the following is a key advantage of this qualitative risk analysis approach?
Easy648In a risk-aware culture, which of the following behaviors is MOST encouraged?
Easy649Which TWO of the following are effective risk mitigation strategies for reducing the likelihood of a ransomware attack?
Medium650Which of the following is the primary purpose of a risk heat map in a risk report?
Easy651A company has implemented a new cloud-based customer relationship management (CRM) system. The IT risk manager is tasked with identifying risks related to this system. Which of the following is the MOST important risk identification technique to use initially?
Easy652Which type of control is primarily designed to prevent an unwanted event from occurring?
Easy653Which THREE of the following are key indicators that a risk identification process is effective? (Choose three.)
Hard654The exhibit shows a log entry from a GRC system. Which of the following is the MOST significant concern regarding this risk score update?
Medium655A security control failed to prevent unauthorized access to a sensitive database. The risk owner has been notified. What should the risk practitioner do NEXT?
Medium656A manufacturing company uses IoT sensors on the factory floor to monitor equipment performance. The sensors transmit data to a central server via Wi-Fi. During a risk identification workshop, the operations manager reveals that some sensors are operating on outdated firmware with known vulnerabilities. The IT director proposes replacing all sensors at a high cost. The risk team notes that a breach could cause production downtime but the sensors only collect non-sensitive operational data. The company has a low tolerance for downtime. What should the risk team identify as the most critical risk?
Medium657An organization defines its risk appetite as 'no more than one major security incident per year.' During the year, a major incident occurs. The monitoring team reports this to the risk committee. What should be the NEXT step?
Easy658An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)
Hard659A mid-sized retail company operates 50 stores across three regions. Each store uses a point-of-sale (POS) system that transmits credit card transactions to a centralized payment processor. The company recently deployed a new SaaS-based inventory management application that connects to the POS system via API. The IT department has no formal process for tracking third-party connections. The risk manager suspects that unknown or unauthorized connections may exist. During a risk identification review, the risk manager discovers that the POS vendor's API documentation was shared with the inventory SaaS provider without a non-disclosure agreement (NDA). Additionally, the API keys for the POS system are stored in plain text configuration files on the inventory SaaS application server. The company's security policy requires encryption of all sensitive data in transit and at rest. Which of the following should the risk manager prioritize as the HIGHEST risk scenario to document in the risk register?
Medium660According to the FAIR model, which TWO of the following are primary components used to calculate probable financial impact of a cyber incident?
Medium661A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?
Hard662A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?
Medium663An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?
Medium664After a major system upgrade, the control testing team reports that a critical automated control failed intermittently. The control owner states it's a temporary glitch. What is the best course of action?
Hard665After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?
Medium666A third-party vendor has been tiered as 'high risk' due to access to sensitive customer data. The vendor's SOC 2 Type II report has a qualified opinion on security controls. The vendor risk appetite requires unqualified SOC 2 Type II for critical vendors. What is the MOST appropriate risk response?
Hard667An organization is migrating on-premises applications to a public cloud. Which THREE of the following should be considered as key risk identification activities?
Medium668During an IT risk assessment, a risk analyst discovers that a server contains sensitive customer data but is not included in the organization's vulnerability scanning program. What should the analyst do first?
Easy669An organization is conducting a vulnerability assessment of its IT assets. Which of the following sources is MOST authoritative for identifying known software vulnerabilities?
Easy670A retail company is planning to launch a mobile payment app. The risk team is identifying potential risks related to payment card industry (PCI) compliance. The app will process credit card numbers. The development team has implemented tokenization to replace card numbers with tokens, but the token vault is located on-premises. The network architect proposes exposing the token vault to the internet for mobile app access. The compliance officer is concerned about PCI DSS requirements. The risk manager needs to identify the highest risk related to this setup. What is the primary risk?
Easy671A key control indicator (KCI) for a critical access control shows a deficiency rate of 12% for the quarter, exceeding the target of 5%. Which of the following should be the risk practitioner's PRIMARY action?
Hard672A risk manager notices that a key risk indicator (KRI) has been consistently above the threshold for three months. What should be the first action?
Medium673An organization is conducting a business impact analysis (BIA) for its core banking system. Which of the following is the PRIMARY metric used to determine the urgency of recovery?
Easy674The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
Medium675A risk register is being created for a new ERP implementation project. Which TWO of the following risks should be included in the project's risk register? (Choose two.)
Easy676A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?
Medium677A company calculates the annualized loss expectancy (ALE) for a server outage as $75,000. The cost to implement a high-availability solution is $200,000 with a lifespan of 5 years and annual maintenance of $10,000. What is the residual risk if the solution reduces outage likelihood by 90%?
Hard678Which THREE of the following are examples of risk mitigation controls? (Select THREE.)
Easy679An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?
Hard680Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)
Medium681You are the risk manager for a healthcare provider. A risk assessment identified that patient data is transmitted over unencrypted connections between clinics and the data center. The existing controls include strong network perimeter defenses. The risk is rated as high. Management is concerned about the cost of implementing encryption. You have proposed a control that encrypts data in transit. However, the network team argues that the perimeter controls are sufficient. What is the MOST appropriate response?
Easy682Which of the following is a limitation of qualitative risk analysis?
Easy683An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?
Medium684A financial institution is evaluating cyber insurance to cover potential losses from a ransomware attack. Which factor is most likely to increase the insurance premium?
Medium685A company relies on a third-party cloud provider for critical data processing. As part of its vendor risk management program, the company wants to implement continuous monitoring of the provider's controls. Which of the following is the BEST approach?
Medium686Which of the following BEST describes inherent risk?
Easy687Based on the exhibit, which control is most critical to address first to reduce the risk of unauthorized access?
Hard688A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?
Medium689An organization is evaluating the risk of a ransomware attack. Using the FAIR framework, which of the following components directly multiplies to calculate Loss Event Frequency (LEF)?
Medium690After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?
Hard691A risk manager is integrating the NIST Cybersecurity Framework with the organization's risk management processes. Which TWO functions of the NIST CSF directly support risk assessment?
Medium692A company's IT risk manager is evaluating Key Risk Indicators (KRIs) for the cybersecurity function. Which TWO of the following are valid examples of leading KRIs?
Hard693In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?
Hard694An organization's risk report shows a risk heat map with several risks in the high-likelihood, high-impact quadrant. What is the most appropriate action for the risk owner?
Medium695Which TWO of the following are primary objectives of control monitoring?
Medium696Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?
Easy697You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?
Hard698A quantitative risk analysis for a phishing campaign estimates that threat event frequency is 50 per year, vulnerability is 0.1 (10% of users will click), and loss magnitude per successful attack is $10,000. However, the analyst notes a 90% confidence interval of $5,000 to $20,000 for loss magnitude. Which of the following best describes a limitation of this quantitative analysis?
Hard699A risk practitioner is designing a monitoring dashboard for senior management. Which key performance indicator (KPI) would be MOST useful for tracking control effectiveness over time?
Medium700Refer to the exhibit. Based on the control test results, which of the following is the most immediate risk?
Hard701Which THREE of the following control monitoring techniques are considered continuous monitoring?
Hard702A retail company is identifying risks in its supply chain. Which approach is most effective for identifying previously unknown risks?
Medium703A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?
Hard704A security analyst is reviewing CVE entries and NVD data to identify vulnerabilities in software assets. This activity is part of which vulnerability identification approach?
Medium705A regional bank uses a centralized GRC platform to monitor key risk indicators (KRIs) for operational risk. The chief risk officer (CRO) reviews the monthly risk report and notices that the KRI 'number of system outages exceeding 4 hours' has been consistently reported as 0 for the past six months. However, the IT incident log shows three such outages in the same period. The CRO suspects the KRI is not being accurately reported. What should the risk manager do next?
Medium706In the FAIR framework, Loss Event Frequency (LEF) is calculated as:
Medium707Which of the following best describes the purpose of an IT risk universe?
Easy708During a risk identification workshop, the business process owner states that a key system has no documented dependencies. What is the BEST next step for the risk practitioner?
Medium709Which risk treatment option involves eliminating the activity that creates the risk?
Easy710An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?
Easy711Which control type is designed to stop a risk event from occurring?
Easy712A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?
Hard713A risk assessment reveals that the likelihood of a phishing attack is high, and the impact is moderate. The organization decides to implement security awareness training and email filtering. This is an example of which risk treatment?
Hard714A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)
Medium715A risk is assessed with inherent risk score of 25 on a 5x5 matrix. After implementing controls, the residual risk score is 10. The control effectiveness is considered:
Medium716Which of the following is the PRIMARY purpose of a risk register in the risk identification phase?
Easy717A company is considering using a qualitative risk assessment approach to evaluate IT risks. Which TWO of the following are advantages of qualitative risk analysis over quantitative risk analysis?
Easy718A multinational corporation is developing its IT risk reporting structure. The risk manager must align reports with different audiences. Which THREE of the following reporting frequencies and audiences are correctly matched?
Hard719An organization is designing a risk dashboard for senior management. Which of the following is the MOST important characteristic of the key risk indicators (KRIs) displayed?
Medium720During a risk identification workshop, the team identifies a potential data leakage from a legacy system. What is the FIRST step the risk owner should take?
Hard721During a post-mortem of a security incident, the risk manager notes that the response team failed to execute the incident response plan correctly because the plan was outdated. Which of the following is the BEST corrective action?
Medium722A risk practitioner is developing a tactical risk report for the CISO. Which TWO of the following elements should be included in the report? (Select TWO)
Medium723A third-party vendor has been assessed as high risk due to its access to sensitive data. Which TWO ongoing monitoring activities are most appropriate for this vendor? (Select two.)
Medium724During a threat modeling exercise for a new web application, the team uses STRIDE. Which threat type under STRIDE corresponds to an attacker modifying data in transit?
Medium725An organization is implementing a risk-aware culture. Which TWO of the following are effective practices?
Medium726An IT risk manager is reviewing the results of a recent risk assessment. The organization has a risk appetite that allows for low residual risk. One identified risk has an inherent risk score of 15 (on a scale of 1-25) and currently has no controls. Which of the following is the BEST recommendation for this risk?
Medium727A risk practitioner is reviewing system logs and notices multiple failed login attempts from a foreign IP address. This observation is an example of which type of risk identification activity?
Easy728According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Medium729In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?
Easy730A risk analyst is identifying operational vulnerabilities. Which TWO of the following are examples of operational vulnerability identification?
Medium731Which risk reporting frequency is most appropriate for tactical risk reporting to the CISO/CIO?
Easy732Which of the following is an example of a detective control?
Medium733Refer to the exhibit. What is the MOST immediate risk identification action?
Medium734A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?
Hard735A risk practitioner is performing a cost-benefit analysis for a proposed control. The annualized loss expectancy (ALE) for a risk is currently $500,000. The proposed control will reduce the ALE by 80%, and the annual cost of the control is $150,000. What is the net benefit of implementing the control?
Medium736An organization uses a SIEM to automatically test access control rules on a continuous basis. This is an example of which type of monitoring?
Hard737Which control implementation activity involves updating system configurations and user access rights when a new security tool is deployed?
Easy738A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?
Medium739A company has implemented an automated control monitoring system that generates alerts when transactions exceed predefined thresholds. The system has been in production for six months. The risk team notices that the number of alerts has been decreasing, while actual control failures have remained constant. Which of the following is the MOST likely cause?
Medium740An organization uses a qualitative risk assessment methodology. The risk matrix has impact and likelihood scales of 1-5. A risk is assessed with impact=4 and likelihood=3. What is the risk level?
Medium741An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?
Medium742A company uses the FAIR model to perform a quantitative risk analysis. The threat event frequency (TEF) is estimated at 10 per year, vulnerability (V) is 0.5, and loss magnitude (LM) per event is $50,000. What is the annualized loss expectancy (ALE)?
Medium743A university's IT department is implementing a single sign-on (SSO) solution for students and faculty. The solution will integrate with existing Active Directory and a cloud-based learning management system (LMS). During risk identification, the team learns that the SSO vendor had a minor security incident last year. The university's security policy requires multi-factor authentication (MFA) for all administrative access, but the SSO solution does not support MFA for student accounts. The project manager insists that MFA for students is not necessary because they only access academic records. The risk team must identify the most significant risk that could affect the university's reputation. Which risk should be documented?
Medium744An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?
Easy745An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?
Medium746A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?
Hard747You are the risk manager for a healthcare organization that uses an electronic health records (EHR) system. The system has a built-in audit log that records all access to patient data. Recently, the Chief Information Security Officer (CISO) raised a concern that there have been multiple reports of unauthorized access to patient records, but the audit log analysis has not identified any suspicious activity. You have been asked to investigate. Your review of the audit log configuration reveals that the system only logs successful access events, not failed access attempts. Additionally, the log retention period is set to 30 days, and the logs are stored in a flat file on the same server as the EHR application. The monitoring team manually reviews the logs at the end of each month. Which of the following is the MOST significant risk associated with the current monitoring approach?
Medium748A risk manager is evaluating the risks associated with using a public cloud provider. Which TWO of the following are key considerations for multi-tenancy isolation? (Select TWO.)
Medium749Which of the following is a primary source of threat intelligence that provides real-time information about active cyber threats and indicators of compromise?
Easy750An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?
Hard751The Chief Information Security Officer (CISO) receives a quarterly report that includes a risk heat map and trend analysis of top risks. This type of reporting is best described as:
Easy752A risk analyst is reviewing monthly control test results. One control failed testing twice in a row. What is the FIRST step the analyst should take?
Easy753A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?
Easy754A company decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?
Medium755During a merger and acquisition (M&A) due diligence, the IT risk manager needs to identify risks in the target company's IT environment. Which approach is most effective for comprehensive risk identification?
Hard756During a control implementation project, the risk manager discovers that the resource requirements have increased significantly, making the original cost-benefit analysis invalid. What should the risk manager do first?
Hard757A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?
Medium758During an IT risk assessment, the risk team identifies a high inherent risk for a legacy application. The team is evaluating control options. Which THREE are considered preventive controls?
Hard759A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?
Medium760An organization has a legacy system that cannot be patched due to vendor end-of-life. The system processes non-critical data. The risk manager has determined that the likelihood of exploitation is low, but the impact would be high. Which risk response strategy is MOST appropriate?
Hard761A company is implementing a risk identification process for third-party risks. Which THREE factors should be considered when identifying risks from a critical software vendor?
Hard762Which TWO of the following are key components of an effective risk and control monitoring program? (Select exactly two.)
Medium763Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?
Easy764During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?
Medium765A company identifies a high inherent risk in its online payment system. After implementing a Web Application Firewall (WAF) and conducting quarterly penetration tests, the residual risk is assessed as medium. Which of the following best explains the relationship between inherent risk, controls, and residual risk?
Hard766A company has multiple business units each using different risk assessment methodologies. The risk committee wants consistent monitoring reports. What is the BEST approach to achieve consistency?
Hard767A company is assessing the risk of a ransomware attack. The security team estimates the threat event frequency as 2 attacks per year, vulnerability as 0.3 (30% chance of success), primary loss as $500,000, and secondary loss as $200,000. What is the annualized loss expectancy (ALE) using the FAIR framework?
Medium768After a risk assessment, the risk owner determines that the residual risk is still above the risk appetite. Which of the following is the MOST appropriate next step?
Medium769Based on the exhibit, which risk is MOST likely to be identified during a risk assessment?
Easy770During a risk assessment, the risk manager identifies that the likelihood of a cyber-attack is high due to recent industry trends. However, the existing controls are deemed effective in reducing impact. Which of the following is the MOST appropriate risk response?
Medium771A risk assessment reveals a high inherent risk that is within the organization's risk appetite. The risk owner documents the risk and formally accepts it. This is an example of which risk treatment option?
Easy772Match each CRISC domain to its description.
Medium773During a risk assessment, an organization identifies that its legacy ERP system has a high likelihood of failure during peak transaction periods. The system supports critical financial operations. The risk owner proposes to upgrade the system, but the project would take 18 months and require significant capital investment. The CEO questions whether the risk can be reduced to an acceptable level more quickly. Which of the following is the MOST appropriate immediate risk response?
Hard774A financial institution is implementing a new continuous monitoring solution for its transaction processing systems. The solution generates alerts for suspicious activities. Which TWO of the following are essential considerations when defining the alert thresholds?
Easy775A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?
Hard776Which of the following is a detective control?
Easy777Which THREE of the following are key components of an effective risk treatment plan?
Hard778Which TWO of the following are examples of corrective controls?
Medium779A company's risk appetite statement specifies that the organization is willing to accept a moderate level of operational risk to achieve strategic agility. This statement directly influences which activity during IT risk identification?
Medium780After a data breach has been contained, what is the most important action for identifying underlying IT risks?
Easy781A risk analyst is reviewing the results of control testing for a critical business process. Which THREE of the following are valid reasons to classify a control as ineffective?
Medium782Put the steps for performing a control self-assessment (CSA) in order.
Medium783An internal audit report identifies that the IT department did not patch a critical vulnerability in a database server for 90 days. The risk manager wants to identify the root cause risk. Which approach should be used?
Medium784Which THREE of the following are common business impact categories used in risk scenarios?
Medium785During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?
Hard786An organization has a risk appetite statement that says 'We accept up to $5 million in operational losses per year.' However, a new cloud migration project is estimated to have a potential operational loss of $8 million if a critical failure occurs. The risk capacity of the organization is $20 million. What should the risk practitioner recommend?
Hard787A Key Control Indicator (KCI) for a critical firewall rule set shows an exception rate of 12% over the past month, exceeding the acceptable threshold of 5%. The control owner is responsible for remediation. Which action should the risk practitioner recommend FIRST?
Hard788Which TWO of the following are primary sources of IT risk identification? (Select exactly TWO.)
Medium789During a risk assessment for a new financial application, the risk manager identifies that the application processes sensitive customer data and is accessible from the internet. Which of the following is the MOST appropriate risk scenario to document?
Medium790A security analyst is using a threat modeling approach that focuses on identifying threats based on the system's requirements and design. Which threat modeling methodology is being used?
Medium791A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?
Hard792Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?
Easy793After implementing controls, the risk remaining is called:
Hard794An organization is conducting a post-implementation review of a new data loss prevention (DLP) control. Which TWO metrics are Key Control Indicators (KCIs) that would best measure the control's effectiveness?
Medium795A company uses a third-party vendor to process customer data. The vendor's security control monitoring reports show no issues. However, the company's internal monitoring detects anomalies in vendor response times. What is the BEST interpretation?
Medium796When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?
Easy797A multinational corporation is assessing the risk of non-compliance with GDPR. Which of the following is the BEST approach to quantify the potential fine?
Hard798An organization is implementing a new access control system to protect sensitive data. Which type of control is most appropriate for preventing unauthorized access?
Medium799A company is evaluating controls for a high-risk process. Which control type is designed to stop a risk event from occurring?
Medium800A company's key risk indicator (KRI) for 'failed login attempts' has exceeded its threshold by 20%. The control owner reports that a recent firewall change caused false positives. What should the risk practitioner do FIRST?
Hard801A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?
Hard802A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?
Hard803A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
Medium804An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)
Hard805A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)
Medium806A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:
Medium807During a risk assessment, the risk manager finds that a critical application has a single point of failure in its network path. The application's availability requirement is 99.99%. The current design achieves only 99.9% uptime. Which risk metric should be calculated first?
Hard808A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?
Hard809During a cloud migration project, the IT risk manager is identifying risks associated with data residency. Which of the following is the MOST effective method to identify applicable regulatory requirements?
Medium810Which TWO of the following are examples of key risk indicators (KRIs) in an IT environment? (Choose two.)
Easy811An organization is developing its IT risk universe. Which of the following is the BEST source of information for identifying potential IT risks?
Easy812Which risk assessment approach is most appropriate for a new technology that has limited historical data and high uncertainty?
Easy813An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?
Easy814An organization is implementing a new control to prevent unauthorized access to its critical database. Which type of control is most appropriate for this requirement?
Easy815Sequence the steps for conducting a business impact analysis (BIA).
Medium816An organization is conducting a threat identification exercise using the STRIDE model. Which threat type would be MOST relevant when analyzing a banking application that allows fund transfers between accounts?
Medium817A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?
Medium818A risk practitioner is developing a risk scenario for a data breach caused by an insider threat. Which of the following is the MOST realistic and complete risk scenario?
Hard819An organization is implementing controls to mitigate the risk of data exfiltration. Which TWO control types would be considered preventive? (Select TWO)
Easy820Which TWO of the following are characteristics of an EFFECTIVE key risk indicator (KRI)?
Medium821A multinational organization uses a third-party vendor for cloud-based identity management. The vendor recently suffered a data breach that exposed user credentials. The risk manager is now re-evaluating the associated risk. Which of the following steps should the risk manager perform FIRST to identify potential new risks?
Hard822A security operations center (SOC) analyst notices multiple failed login attempts from an internal IP address followed by a successful login from an unusual geographic location. Which risk identification technique should the risk manager use to assess this as a potential risk?
Hard823What is the primary risk if the WAF is misconfigured?
Easy824During a risk assessment, a control self-assessment (CSA) indicates that a key control is operating effectively. However, an independent audit finds multiple control failures. Which of the following is the MOST likely reason for this discrepancy?
Medium825An organization is using the FAIR framework to perform a quantitative risk analysis for a data breach scenario. Which TWO of the following are components of the Annualized Loss Expectancy (ALE) calculation in FAIR?
Medium826A control test reveals a 100% pass rate for a detective control. What does this indicate?
Easy827Which of the following is a characteristic of IoT devices that increases cybersecurity risk?
Easy828Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?
Easy829Which THREE of the following are common challenges in risk reporting?
Hard830An organization uses a qualitative risk assessment and assigns a likelihood of '3' and impact of '4' on a 5-point scale. The heat map defines risk scores 12-25 as high. What is the risk rating?
Medium831An organization wants to promote a risk-aware culture. Which of the following actions is MOST effective for encouraging employees to report incidents without fear?
Medium832An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?
Medium833A company has identified that its legacy financial system has a high inherent risk due to outdated architecture. The system cannot be replaced for three years. What is the best risk treatment strategy?
Medium834During IT risk identification, which document serves as the central repository for all identified risks, their characteristics, and current status?
Easy835You are the IT risk manager for a financial institution that processes high-value transactions. The organization uses a cloud-based core banking system and on-premises servers for backup. During a recent risk assessment, you identified that the cloud provider's service-level agreement (SLA) guarantees 99.9% uptime, but the organization's business impact analysis (BIA) indicates that every hour of downtime costs $500,000. The current recovery time objective (RTO) for the core banking system is 4 hours, but the actual recovery capability is 6 hours due to manual steps in failover. The risk owner has accepted this risk informally. You are asked to recommend a course of action to the risk committee. Which of the following is the most appropriate recommendation?
Easy836A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?
Medium837During a risk assessment, the risk practitioner is identifying threats to an application. Which threat modeling technique is specifically designed to analyze application threats using categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Easy838A risk assessment using a 5x5 heat map with likelihood and impact scores is an example of which type of risk analysis?
Easy839A smart manufacturing company has deployed hundreds of IoT sensors and actuators across its production line. These devices are connected directly to the corporate network without any segmentation and communicate using unencrypted protocols. A third-party vendor manages all IoT devices and has administrative access from their own network. Recently, the IT team detected unusual outbound traffic from the IoT segment to unknown IP addresses on the internet. The risk manager is leading a risk identification workshop. Based on this scenario, what is the most critical risk to the organization that should be identified and documented?
Easy840An organization implements an intrusion detection system (IDS) to monitor for security incidents. This is an example of which type of control?
Medium841A company is conducting a Risk Identification for a new payment processing system. The team discovers that the system does not have encryption at rest. This is an example of:
Hard842Which risk treatment option involves formally acknowledging the risk and taking no further action, provided the risk is within the organization's risk appetite?
Easy843An organization using the FAIR framework estimates that a threat event frequency (TEF) is 10 per year, vulnerability is 0.2, and loss magnitude per event is $500,000. What is the annualized loss expectancy (ALE)?
Hard844A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?
Medium845Based on the exhibit, what is the MOST likely risk scenario?
Hard846A risk committee receives a monthly risk report that includes a heat map of inherent risk ratings and a separate list of control deficiencies. The committee members often complain that they cannot easily see which control deficiencies are most critical to address. Which of the following is the BEST improvement to the reporting?
Hard847In the FAIR framework, Loss Event Frequency (LEF) is calculated as:
Medium848Which of the following best describes an advantage of qualitative risk analysis over quantitative risk analysis?
Easy849In the FAIR framework, what does Loss Event Frequency (LEF) represent?
Medium850During a risk assessment, a risk is assigned a likelihood of 'High' and an impact of 'Medium' on a 5×5 heat map. What is the risk rating?
Medium851An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:
Medium852When reporting risk and control monitoring results to the board of directors, which of the following formats is MOST effective?
Easy853Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?
Easy854An organization is implementing a new access control system. Which of the following is the most important activity to ensure the control is effectively integrated into operations?
Medium855Refer to the exhibit. What does the exhibit most likely indicate about the control monitoring?
Easy856A small manufacturing company is conducting its first IT risk assessment. The company has a flat network with no segmentation, and all employees have administrative access to their workstations. The risk practitioner identifies that a malware infection on one workstation could easily spread to the entire network. The company has a limited budget for IT security improvements. Which of the following risk treatment options is MOST cost-effective and practical?
Easy857Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?
Medium858Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Medium859A company plans to deploy an AI-based customer service chatbot that processes personal data. What risk should be identified as the highest priority?
Medium860An incident occurs due to a control that was thought to be automated but was actually manual. The risk register did not reflect this. What is the MOST likely root cause?
Medium861Sequence the steps for developing a disaster recovery plan (DRP).
Medium862Which of the following is an example of a preventive control?
Easy863During a quarterly control review, the risk team discovers that a key manual approval control was bypassed in 15% of transactions due to a recent process change. What is the FIRST action the risk practitioner should take?
Easy864Refer to the exhibit. An organization has identified vulnerabilities on a critical server. The risk owner has limited resources and can remediate only one finding this quarter. Based on the information provided, which approach is the most appropriate risk assessment decision?
Medium865A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?
Easy866GlobalTech Inc., a multinational corporation, is planning to migrate its customer data to a new cloud platform. The migration involves transferring sensitive personally identifiable information (PII) from an on-premises database to a cloud-based CRM. The risk manager conducted a risk assessment and identified several risks, including unauthorized access during transit and residual data exposure due to misconfiguration. Mitigation controls include encryption in transit, encryption at rest, and strict access controls. The residual risk after mitigation is assessed as medium. The risk appetite statement defines that 'No data breach incidents resulting in regulatory fines exceeding $1 million are acceptable.' The estimated potential fine from a breach is $5 million with a likelihood of 2% after controls. The cost of additional controls to reduce likelihood to 0.5% is $500,000. The migrating team proposes to purchase cyber insurance with a $3 million coverage for $200,000 annual premium. The board of directors prefers to accept the residual risk to avoid additional costs. What should the risk manager do?
Hard867What is the primary purpose of a risk heat map in IT risk reporting?
Easy868A risk manager is reviewing the risk register and notices that several risks have been identified as 'high' but no risk owner has been assigned. Which of the following is the MOST appropriate action to ensure proper risk identification going forward?
Hard869A company is performing a qualitative risk analysis for a new cloud migration project. Which TWO of the following are recognized limitations of qualitative risk analysis?
Medium870A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?
Easy871An organization uses a quantitative risk analysis method. The annualized loss expectancy (ALE) for a specific risk is calculated as $500,000. The cost of implementing a control is $150,000 per year, and it is expected to reduce the ALE by 80%. What is the net benefit of implementing the control?
Hard872A financial institution is selecting a risk assessment methodology for evaluating cybersecurity risks across its critical systems. Which of the following is the PRIMARY consideration when choosing between qualitative and quantitative approaches?
Easy873A multinational corporation has recently experienced a significant increase in phishing attacks targeting its employees. The attacks have caused several data breaches, resulting in regulatory fines and reputational damage. The organization has implemented security awareness training for all employees, but the number of successful attacks remains high. Additionally, the organization's risk appetite for cybersecurity incidents is Low. The CRO has asked you to recommend a risk response. You have the following options: A. Accept the risk because the training has reduced the likelihood, and further controls are too expensive. B. Transfer the risk by outsourcing all email and security operations to a managed security service provider (MSSP). C. Implement technical controls such as advanced email filtering and multi-factor authentication (MFA) to reduce the likelihood and impact of phishing attacks. D. Avoid the risk by discontinuing the use of email for business communications. Which course of action is most appropriate given the organization's risk appetite and the current situation?
Medium874An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)
Hard875Which TWO of the following are examples of external risk identification sources? (Choose two.)
Easy876Which THREE of the following are key considerations when selecting a risk response option?
Medium877A financial institution is implementing a new risk monitoring tool that aggregates data from multiple sources. The tool is expected to provide real-time dashboards for risk committees. However, during user acceptance testing, the dashboards show inconsistent data due to time zone differences across sources. What is the best approach to resolve this?
Hard878A risk manager is prioritizing risks based on their inherent risk scores. Which of the following factors should be considered when prioritizing treatment actions?
Medium879A company is assessing the impact of a potential ransomware attack. Which TWO impact categories are considered operational impacts?
Medium880An organization wants to promote a risk-aware culture. Which initiative best supports this goal?
Easy881A risk manager is evaluating the cost-effectiveness of a proposed control. The control costs $50,000 annually to implement and maintain. The current annual loss expectancy (ALE) for the risk is $200,000, and the control is expected to reduce the ALE by 70%. What is the net benefit (or loss) of implementing the control?
Medium882An organization uses Key Control Indicators (KCIs) to measure the effectiveness of its firewall change management process. Which KCI would best indicate a process deficiency?
Hard883Which of the following is a key advantage of using a quantitative risk analysis approach such as FAIR?
Easy884A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?
Easy885During a control monitoring review, the auditor finds that a control designed to detect unauthorized access has not triggered any alerts in six months. What should the risk practitioner do first?
Easy886A multinational corporation is identifying risks associated with cross-border data transfers. Which regulation's risk identification requirements are most relevant?
Hard887Which of the following is the BEST example of promoting a risk-aware culture within an organization?
Easy888A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increased from 15 days to 45 days. How should the risk practitioner interpret this change?
Hard889An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
Hard890Refer to the exhibit. Which type of attack is MOST likely indicated by these log entries?
Hard891A company is designing its risk and control monitoring program. Which TWO of the following are key attributes of effective monitoring?
Easy892Match each risk analysis formula to its component.
Medium893Which TWO of the following factors should be considered when determining the frequency of control monitoring?
Easy894An organization is integrating IT risk into its enterprise risk management (ERM) program. What is the primary benefit of this integration?
Medium895An organization calculates the annualized loss expectancy (ALE) for a cyber attack scenario. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 2. What is the ALE?
Medium896An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?
Medium897A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?
Medium898A financial institution is redesigning its control monitoring program to comply with a new regulatory requirement that mandates near-real-time monitoring of high-risk transactions. The current system performs batch processing daily. Which approach BEST meets the requirement while minimizing operational impact?
Hard899Refer to the exhibit. What does this log entry indicate about the monitoring process?
Medium900An organization is evaluating the impact of a potential data breach. Which THREE of the following are considered indirect financial impacts?
Hard901A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?
Hard902An organization recently experienced a data breach due to a misconfigured cloud storage bucket. As part of the IT risk assessment, which control should be prioritized to prevent recurrence?
Medium903A Key Risk Indicator (KRI) for a critical system is the number of unpatched vulnerabilities older than 30 days. The threshold is set at 5. This KRI is best described as:
Hard904An IT risk manager is categorizing risks identified during a recent assessment. Which TWO categories would include the risk of a system outage caused by a software bug?
Easy905An organization is implementing a new cloud-based customer relationship management (CRM) system. Which of the following risk categories would BEST describe the risk of the CRM system failing to meet performance expectations?
Medium906A company's risk monitoring report shows that a key risk indicator (KRI) has exceeded the threshold for three consecutive months. What is the MOST appropriate action?
Medium907Refer to the exhibit. What risk is most directly indicated by this log entry?
Medium908During a merger and acquisition (M&A) due diligence, the acquiring company's IT risk manager is tasked with identifying risks in the target's IT environment. Which of the following would be the MOST effective technique to uncover hidden risks?
Medium909A company is evaluating its control monitoring program. Which TWO of the following are key elements of an effective control monitoring framework? (Choose two.)
Medium910Match each information security objective to its description.
Medium911A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?
Hard912A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?
Hard913Based on the exhibit, which key risk indicator (KRI) would this log data be MOST useful for calculating?
Easy914Based on the exhibit, what is the MOST significant risk exposure?
Hard915A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?
Hard916Match each risk management term to its definition.
Medium917A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?
Medium918An organization is creating a risk register for its IT risk universe. The risk manager needs to categorize risks to align with the enterprise risk management framework. Which TWO risk categories are most commonly used in IT risk identification?
Easy919Refer to the exhibit. Which of the following is the MOST critical risk that should be addressed first?
Easy920During a quarterly control effectiveness test, internal audit finds that a detective control missed 15% of security incidents. The control owner claims this is within the acceptable error rate of 20%. However, the risk practitioner notes that the missed incidents were high-severity. What should the risk practitioner do?
Medium921A company is conducting an IT risk assessment for the first time. Which of the following should be the FIRST step?
Easy922A company recently experienced a data breach due to an unpatched vulnerability in a public-facing web application. During the post-incident review, the IT risk manager notes that the vulnerability was identified by the vulnerability scanner six months ago but was not remediated because the patch required a critical database server restart. Which of the following is the BEST risk treatment decision to prevent a recurrence?
Medium923A risk practitioner is using the ISACA risk scenario template to document a scenario. The template includes elements such as threat actor, threat type, event, asset/resource, timing, detection, and response. Which element describes the likelihood that the threat event will occur within a specific timeframe?
Hard924During a risk assessment of a legacy system, the assessor finds that no control is currently in place. The inherent risk level is 'critical'. The residual risk will be:
Hard925During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?
Medium926Which TWO of the following are primary sources of risk identification for IT projects?
Easy927A risk practitioner is asked to reduce the number of KRIs tracked from 50 to 20. Which KRIs should be prioritized for removal?
Hard928Which THREE of the following are valid risk identification methods according to ISACA's Risk IT Framework? (Select exactly 3.)
Hard929A retail company is assessing the risk of a POS malware attack. Which approach would BEST quantify the potential financial impact?
Medium930An organization's architecture review board (ARB) is evaluating a new solution architecture. What is the PRIMARY risk management role of the ARB in this context?
Medium931A large retailer is implementing a new point-of-sale (POS) system. The project manager wants to identify risks related to payment card data security. Which risk identification technique would be MOST effective for this purpose?
Medium932A technology startup is developing a mobile payment application. During a risk identification workshop, the team identifies a risk that the application may not comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. What is the BEST way to categorize this risk?
Hard933Refer to the exhibit. If the control objective is to prevent unauthorized access via MFA, what does this test result indicate?
Medium934Which THREE of the following are components of Loss Magnitude in the FAIR framework?
Medium935Which TWO are characteristics of inherent risk?
Medium936A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?
Medium937An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?
Medium938A company's control monitoring dashboard shows that a key control has been operating effectively for six months. However, a recent audit revealed a material weakness. Which of the following is the MOST likely reason?
Easy939A multinational corporation operates in 15 countries with decentralized control monitoring systems. Each regional office uses different tools and processes for monitoring operational risks. The corporate risk team has consolidated quarterly reports, but the board recently raised concerns about inconsistencies and late identification of emerging risks. A root cause analysis revealed that regional monitoring teams define key risk indicators (KRIs) differently and report on different timeframes. Additionally, there is no centralized platform to aggregate data. The risk manager must recommend a solution that balances local autonomy with global visibility. Which option is the most effective?
Hard940In a qualitative risk assessment using a 5x5 heat map, an IT risk is rated with likelihood 4 and impact 5. According to typical heat map conventions (5=Critical, 4=High, 3=Medium, 2=Low, 1=Informational), what is the overall risk rating?
Hard941An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)
Easy942An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:
Easy943A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?
Medium944A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?
Hard945A risk practitioner is designing a quarterly IT risk report for the CISO. Which of the following elements is MOST critical for tactical decision-making?
Hard946A company has an inherent risk score of 20 for a specific threat. After implementing controls, the control effectiveness is assessed as 60% (design adequacy 70%, operating effectiveness 85%). What is the approximate residual risk score?
Hard947Match each compliance framework to its primary focus.
Medium948An internal audit found that a control designed to prevent duplicate payments was bypassed in 5% of transactions. The control owner argues that the control is still effective because the bypass rate is low. What is the BEST response from a risk perspective?
Medium949An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?
Medium950You are the IT risk manager for a mid-sized e-commerce company that processes over 10,000 transactions per day. The company recently migrated its customer database from an on-premises SQL Server to a cloud-based PostgreSQL instance on AWS RDS. The database contains personally identifiable information (PII) including names, addresses, and credit card numbers (stored as encrypted tokens). The migration was performed by the DevOps team with minimal involvement from the security team. Two weeks after the migration, the company experienced a data breach where an attacker exfiltrated a subset of customer records. The forensic investigation revealed that the attacker exploited a misconfigured security group that allowed inbound traffic from the internet on port 5432 (PostgreSQL default port). Additionally, the database had a publicly accessible endpoint, and the master user password was weak (eight characters, no special characters). The attacker used a brute-force attack to guess the password. The security group has since been corrected, and the password has been changed to a strong one. The breach notification laws require reporting within 72 hours. The CEO wants to understand the root cause and prevent recurrence. As the risk manager, which of the following actions should you recommend as the MOST effective to prevent a similar incident?
Hard951Which TWO of the following are key attributes of effective risk reporting?
Easy952An organization is designing a risk indicator monitoring program for its key financial risks. Which of the following is the BEST example of a key risk indicator (KRI) for credit risk?
Easy953A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:
Medium954Which of the following is a limitation of quantitative risk analysis?
Easy955A risk analyst is building a risk register. After identifying a list of risks, what is the NEXT step in the risk identification process according to ISACA best practices?
Medium956Which of the following is the BEST Key Control Indicator (KCI) for measuring the effectiveness of a firewall?
Medium957During a risk assessment for a critical financial application, the IT risk manager identifies a vulnerability in the application's authentication module. The exploit would require authenticated access. Which risk rating is most appropriate if the vulnerability has a CVSS base score of 9.0, but the application is behind a strong firewall and requires two-factor authentication?
Easy958When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?
Easy959During a third-party risk assessment, a vendor is classified as 'critical' due to its access to sensitive customer data. According to the organization's vendor risk appetite, what is the minimum security requirement for this vendor?
Hard960A risk register is being updated after a quarterly risk assessment. One risk has decreased in likelihood due to new controls. However, the risk score remains unchanged because the impact increased. What should the risk practitioner do?
Medium961After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:
Easy962A SIEM event shows multiple failed logins followed by a successful login for the service account 'svc-backup'. The risk practitioner is evaluating the controls. Which finding is MOST significant?
Hard963Which of the following is the BEST indicator that a risk assessment's results are reliable?
Easy964An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?
Easy965Which THREE factors should be considered when determining the inherent risk level of a new IT project prior to any controls?
Hard966You are a risk analyst for a financial institution that uses a legacy mainframe system for core banking transactions. The mainframe is critical for daily operations, but it is no longer supported by the vendor. The system has known vulnerabilities that cannot be patched due to compatibility issues. The institution has a risk appetite that is very low for any disruption to core banking services. Recently, there was a minor outage caused by a hardware failure, which was resolved quickly, but it highlighted the system's fragility. The IT director proposes to migrate to a modern system, but the migration will take 2 years and cost $5 million. The board is concerned about the cost and timeline. You need to recommend an immediate risk treatment to reduce the likelihood of a major outage while the migration is underway. Which of the following is the BEST course of action?
Medium967When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?
Medium968Which of the following threat actors is MOST likely to be motivated by financial gain and possess moderate to high technical capabilities?
Medium969In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?
Medium970Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)
Hard971After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:
Hard972A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)
Hard973When prioritizing risk treatment actions, which factor is most important to consider alongside the risk level?
Easy974An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?
Medium975Which THREE of the following are key components of an effective risk response plan?
Medium976A hospital uses a patient portal that allows patients to access their medical records. The portal has experienced multiple brute-force login attempts. The risk manager wants to identify the most critical risk scenario. Which of the following should be prioritized?
Medium977A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:
Hard978During a control monitoring review, it is discovered that a detective control has a high false positive rate. What is the MOST significant impact of this issue?
Easy979An organization is evaluating the business impact of a potential ransomware attack. Which TWO impact categories should be considered as direct financial losses? (Select TWO)
Medium980A control monitoring system generates an alert when transaction volumes exceed 10,000 per hour. Recently, the system has been generating false positives during peak business hours due to legitimate seasonal spikes. Which of the following is the BEST approach to reduce false positives while maintaining effective monitoring?
Medium981A risk manager is using the FAIR model to quantify cyber risk. Which of the following inputs is MOST directly used to calculate probable financial loss?
Medium982Refer to the exhibit. This JSON snippet defines a monitoring policy for S3 bucket access. Which of the following is a potential risk that might NOT be detected by this monitoring policy?
Hard983An organization uses a Key Control Indicator (KCI) to measure control effectiveness. The KCI shows a control deficiency rate of 12% over the past quarter, exceeding the target threshold of 5%. Which action is MOST appropriate as an initial response?
HardOther domains
All CRISC exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CRISC exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 983 scenario questions questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.