CRISC · domain
scenario questions
Practise Certified in Risk and Information Systems Control CRISC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (1062)
Click any question to see the full explanation, or start a practice session above.
A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?
Medium2A board member asks for a summary of the top five risks. The risk practitioner has 10 risks with current residual risk levels. Which approach BEST supports board-level reporting?
Hard3Arrange the steps for performing a risk assessment in the correct order.
Medium4A manufacturing company uses Internet of Things (IoT) sensors to monitor equipment temperature and vibration on the production floor. The sensor data is automatically sent to a central system, but there is a manual log maintained by operators that records their visual inspections. Recently, there have been instances where the sensor data indicated abnormal readings, but the operator logs showed normal conditions, leading to delayed maintenance actions and two equipment breakdowns. The risk manager investigates and finds that operators sometimes forget to update logs or misinterpret sensor alerts. The company wants to improve the reliability of the monitoring process. What should be the primary action?
Medium5A quarterly risk report for the IT steering committee shows a key risk indicator (KRI) called 'patch lag' has increased from 15 days to 45 days. What does this trend most likely indicate?
Medium6A risk practitioner is preparing an IT risk report for the board risk committee. The committee has limited technical background and meets quarterly. Which of the following is the MOST appropriate way to present the aggregated IT risk exposure?
Medium7An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?
Easy8A risk practitioner is reviewing the risk register of an e-commerce company and finds that several risks were identified only through past incident reports. The chief risk officer asks how to broaden risk identification to surface risks that have not yet materialized. Which of the following approaches is MOST effective for identifying emerging and previously unconsidered risks?
Medium9A risk practitioner is performing an external threat environment analysis for a retail chain that accepts card payments. The practitioner wants to identify which external factors should be treated as inputs to the likelihood of payment card data compromise. Which TWO of the following are the MOST appropriate inputs? (Choose two.)
Medium10A small online retailer with 15 employees sells handmade crafts through its e-commerce website. The company processes payments via a third-party gateway. The owner manually reviews transaction logs once a week for fraud indicators, but recently discovered three chargebacks due to unauthorized transactions. The retailer has limited IT budget and no dedicated security staff. The owner wants to improve detection of fraudulent transactions without significant investment. The current manual process takes about two hours per week and often results in delayed detection. The payment gateway offers basic fraud detection features such as IP geolocation and velocity checks, but these are not enabled. What is the most practical first step?
Easy11During the risk identification process, an IT risk universe is defined. Which of the following BEST describes the purpose of an IT risk universe?
Medium12A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?
Medium13A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?
Medium14An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?
Hard15An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?
Hard16During a cost-benefit analysis for a new control, the annualized loss expectancy (ALE) without the control is $500,000. The control is expected to reduce risk by 80% and will cost $150,000 annually to operate. What is the net benefit of implementing the control?
Medium17A risk practitioner is categorizing IT risks for a manufacturing company. Which of the following risks would be classified as an 'operational' IT risk?
Medium18Which of the following is a detective control?
Easy19Which of the following is the most appropriate frequency for operational IT risk reporting to IT management?
Easy20In third-party risk management, which of the following is MOST indicative of a vendor's control effectiveness for a critical vendor?
Medium21A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?
Easy22Which THREE of the following are effective techniques for identifying IT risks?
Medium23A risk practitioner is reviewing the organization's identity and access management (IAM) processes. The organization wants to reduce the risk of excessive access rights for employees who change roles internally. Which of the following controls is MOST effective for this risk?
Medium24A risk practitioner is estimating the likelihood of a ransomware event for a manufacturing firm. The firm has endpoint protection, network segmentation, and offline backups, but the practitioner learns that a third-party maintenance vendor has persistent remote access with shared credentials and no multi-factor authentication. Which of the following BEST explains how this finding should affect the likelihood estimate?
Medium25A risk practitioner is reviewing the risk register and notices that several risks have not been reassessed in over a year. The business environment has changed significantly due to a new regulation. What is the PRIMARY reason the practitioner should escalate this issue to the risk committee?
Medium26A small retail company has determined that the risk of a point-of-sale (POS) system malware infection is high. The company decides to implement a whitelisting solution that only allows approved applications to run on POS terminals. This is an example of which risk response?
Easy27Which THREE of the following are common challenges when implementing a risk monitoring dashboard? (Select exactly three.)
Hard28An organization is implementing a new access control system. Which of the following should be included in the control implementation plan?
Easy29Which of the following is the PRIMARY benefit of using a risk register for monitoring?
Easy30A healthcare organization operates a legacy electronic health record (EHR) system that is manually monitored for access anomalies by a small IT team. The organization is planning to migrate to a new cloud-based EHR with integrated logging and monitoring. However, due to budget constraints, the migration will take two years. In the interim, the risk manager wants to improve monitoring for unauthorized access to patient data. The current manual process involves weekly log reviews, but recent audits have identified instances of delayed detection (up to two weeks) and missed incidents. The IT team can dedicate only 10 additional hours per week for monitoring. What is the best approach to enhance monitoring during the transition period?
Medium31In third-party risk management, which of the following is typically used for initial onboarding assessment of a vendor?
Medium32Which TWO of the following are valid risk scenarios that should be documented during IT risk identification?
Medium33An IT risk manager is preparing a report for the board of directors. Which of the following content elements is most important for strategic risk reporting?
Medium34A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time production monitoring. Which risk is most directly introduced by this convergence?
Medium35An organization's IT risk team is promoting a risk-aware culture. Which initiative is most likely to encourage employees to report security incidents without fear?
Hard36An organization is planning to deploy an IoT solution in a manufacturing plant. The risk manager is asked to identify risks associated with the integration of IoT devices into the plant network. Which of the following techniques would be MOST effective for identifying both technical and operational risks?
Medium37An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?
Easy38When developing realistic risk scenarios, which THREE components are essential according to the ISACA risk scenario template?
Medium39A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?
Easy40Which TWO of the following are primary purposes of risk and control monitoring? (Choose two.)
Medium41A company is implementing a new access control system. According to the project plan, user training will be delivered after the system goes live. What change management issue does this present?
Medium42An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?
Medium43During a quarterly risk review, it is discovered that a previously accepted risk has materialized due to a change in the external environment. What is the MOST appropriate response?
Hard44A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?
Easy45During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control will cost $100,000 annually and is expected to reduce the ALE by 80%. What is the net benefit of implementing this control?
Medium46A risk practitioner is identifying IT risk scenarios for a new e-commerce platform. The platform will process credit card payments and store customer data. Which TWO of the following are examples of external threats that should be considered in the risk identification process? (Choose two.)
Medium47After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?
Medium48Which TWO of the following are examples of inherent risk?
Easy49Which TWO of the following are key risk identification techniques used to identify threats and vulnerabilities in IT systems? (Select exactly 2.)
Medium50A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?
Hard51Which of the following is the BEST practice for determining the frequency of control monitoring activities?
Easy52Which of the following is an example of a 'configuration vulnerability' that should be identified during vulnerability assessment?
Easy53A risk manager notices that a key risk indicator (KRI) for failed login attempts has exceeded the threshold for three consecutive weeks. Which of the following should be the FIRST action?
Easy54An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?
Medium55A retail company uses a manual control to verify that all credit card transactions are processed by authorized payment terminals. The control requires a store manager to compare a daily transaction log against a list of approved terminal IDs. The company processes an average of 10,000 transactions per day across 200 stores. During a recent internal audit, it was found that 15% of stores had not completed the reconciliation for the past month. The audit also revealed that several unauthorized terminals had been used to process transactions, resulting in a data breach of customer payment information. The company's risk appetite for payment card data security is very low. The current monitoring approach includes a quarterly review of control performance by the internal audit team. The risk manager needs to recommend improvements to the monitoring of this control. Which of the following is the BEST recommendation?
Medium56A retail company is conducting a risk assessment for its point-of-sale (POS) systems. The risk team determines that the inherent risk of a malware attack is high. The company implements endpoint detection and response (EDR) tools and network segmentation. After these controls, the risk is re-evaluated. What is this re-evaluated risk called?
Easy57A risk practitioner has completed a risk assessment and documented the findings. Management must now decide how to address each identified risk. Which of the following BEST describes the purpose of the risk response process?
Easy58An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?
Medium59An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?
Medium60An organization uses a qualitative risk assessment methodology. During a recent assessment, several risks were rated as 'high' due to vague definitions. What is the BEST way to improve the accuracy of the assessment?
Medium61A risk manager is evaluating the potential impact of quantum computing on the organization's encryption infrastructure. The organization uses RSA-2048 for key exchanges and digital signatures. According to current quantum computing projections, what is the MOST urgent risk management action to take?
Hard62An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:
Medium63A Key Risk Indicator (KRI) that shows a rising trend in the average time to apply critical security patches suggests:
Medium64In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?
Hard65A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?
Hard66A risk analyst is assessing a newly discovered vulnerability in an internet-facing server. The analyst collects several data points: the vulnerability has a CVSS base score of 9.8, there are known exploits in the wild, and the server is critical for processing customer transactions. However, the organization's intrusion detection system has a signature that blocks the specific exploit, and the server is patched monthly. The analyst must determine the risk level. Which of the following should the analyst use to BEST assess the risk?
Medium67A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)
Medium68A company's risk appetite statement says it is willing to accept moderate levels of operational risk but has low tolerance for compliance risk. During risk identification, which of the following scenarios should be IMMEDIATELY escalated to senior management?
Hard69A risk practitioner notices that the number of failed authentication attempts has spiked by 300% over the past week. Which of the following actions should be taken FIRST?
Hard70During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:
Medium71A multinational corporation is implementing continuous monitoring of its compliance with data privacy regulations across multiple jurisdictions. Which TWO of the following are significant challenges to this approach?
Hard72A risk assessment that assigns monetary values to assets and calculates expected loss is called:
Easy73A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)
Hard74A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?
Medium75An organization uses a third-party SaaS provider for payroll processing. Which of the following is the BEST technique to identify risks associated with this vendor?
Easy76A risk analyst is building a risk register for a newly deployed customer relationship management (CRM) system that stores personally identifiable information (PII). The analyst needs to document the risk that an attacker could exfiltrate the PII database. Which of the following BEST represents the threat component of this risk statement?
Medium77A software company has identified that a critical third-party library used in its product has a known remote code execution vulnerability. The vendor has not released a patch, and the product is used by customers who cannot accept downtime. The risk practitioner recommends isolating the library's functionality in a sandboxed process with restricted permissions. Which risk response strategy does this represent?
Medium78Which of the following is a key component of an IT risk management programme design?
Easy79A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?
Medium80Based on the exhibit, which aspect of risk monitoring is MOST concerning?
Medium81A company uses a risk control self-assessment (RCSA) process that is conducted annually. During a quarterly review, management discovers that several high-risk controls are no longer effective due to changes in the business environment. Which of the following is the BEST way to enhance the monitoring of these controls?
Hard82A risk practitioner at a regional bank is building a risk register and needs to classify each identified risk by its origin. The practitioner documents a risk that a critical payment switch will fail during peak transaction volume because a fan assembly in the switch has exceeded its mean time between failures. Which risk category BEST applies to this entry?
Medium83Refer to the exhibit. During a risk identification review, the risk manager sees this IDS alert. What risk does this alert MOST directly indicate?
Easy84A risk practitioner is conducting an IT risk assessment for a retail bank's new mobile payment application. The threat landscape includes hacktivists, organized crime, and insiders. The practitioner needs to estimate the likelihood of a data breach. Which of the following factors is MOST important to consider when estimating likelihood?
Medium85A medium-sized e-commerce company has a risk monitoring program that tracks key risk indicators (KRIs) monthly. One KRI is the percentage of orders with failed payment transactions. The threshold is 2%, but for the past three months, the KRI has been 2.5%, 3.1%, and 2.8%. The risk owner says this is due to a seasonal increase in fraudulent transactions and expects it to return to normal next month. The company has a compensating control that manually reviews flagged transactions. The internal audit team recently tested the compensating control and found it to be 100% effective. The risk committee wants to know if the KRI breach requires action. What should the risk practitioner recommend?
Medium86An organization has a risk register that includes risks related to regulatory compliance, such as GDPR and SOX. The risk practitioner is now categorizing these risks. Which risk category would BEST fit these compliance-related risks?
Medium87In IT risk reporting, which level of management typically receives operational risk reporting on a weekly or monthly basis?
Medium88An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)
Hard89A risk practitioner is evaluating the effectiveness of the organization's security awareness training program. The practitioner wants to determine whether the training is reducing the risk of phishing attacks. Which of the following metrics would be MOST indicative of the program's effectiveness?
Medium90An organization uses threat intelligence feeds from an Information Sharing and Analysis Center (ISAC). What is the PRIMARY benefit of using ISACs?
Easy91A multinational financial services company has implemented a continuous monitoring program for its trading systems. The program uses automated scripts to check system configurations against a baseline every hour. Recently, the company experienced a significant security incident where a malicious actor exploited a misconfigured firewall rule to exfiltrate sensitive customer data. Post-incident analysis revealed that the misconfiguration had been present for 72 hours before detection. The monitoring scripts did not detect the change because the baseline had been updated two weeks prior to include the misconfiguration as part of a planned change that was later reversed without updating the baseline. The company's change management process requires that all configuration changes be approved and documented, but the reversal of the change was not documented. The incident response team was only alerted when a customer reported suspicious activity. The risk practitioner is tasked with recommending improvements to prevent recurrence. Which of the following is the BEST course of action?
Hard92When assessing IT risks, which of the following is the PRIMARY purpose of developing risk scenarios?
Easy93Which of the following is a primary goal of the 'Protect' function in the NIST Cybersecurity Framework?
Easy94A multinational bank is assessing the risk of a distributed denial-of-service (DDoS) attack on its online banking platform. The risk practitioner has identified that the platform is hosted in a single data center with no redundancy. Which of the following BEST describes the relationship between the threat, vulnerability, and risk in this scenario?
Hard95A risk manager at a healthcare organization is identifying risks related to the use of Internet of Medical Things (IoMT) devices. The organization has a large number of legacy devices that cannot be patched. Which of the following is the MOST significant risk factor to consider when assessing the risk of a ransomware attack?
Hard96A hospital's risk team has documented that its infusion pump fleet runs an unsupported operating system, creating a high risk of compromise. Replacing the pumps requires capital approval that will take 18 months, and the pumps cannot be taken offline in the interim. Which risk response is MOST appropriate for the risk practitioner to recommend?
Medium97Which component of the NIST Cybersecurity Framework is primarily concerned with developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy98In assessing control effectiveness, an IS auditor evaluates both design adequacy and operating effectiveness. Which of the following indicates that a control is operating effectively?
Medium99A risk manager is using a 5×5 likelihood-impact matrix to assess a set of identified risks. What is the PRIMARY advantage of using this qualitative method?
Easy100A financial institution is migrating its core banking system from an on-premises data center to a public cloud infrastructure. The migration is planned in phases over 18 months. The IT risk manager is tasked with identifying risks during the transition. During the first phase, the team moves non-critical applications to the cloud. A vulnerability assessment of the cloud environment reveals that several virtual machines have default administrative credentials enabled. Additionally, the cloud security group configuration for the application tier allows inbound SSH from the entire internet (0.0.0.0/0). The risk manager also learns that the cloud provider's shared responsibility model is not fully understood by the operations team, who believe the provider is responsible for all security controls. The institution's risk appetite statement allows for moderate risk tolerance but prohibits any exposure that could lead to unauthorized access to customer financial data. Which of the following risk scenarios should the risk manager identify as the MOST critical to address immediately?
Hard101An IT manager is identifying risks for a new cloud application. Which of the following is the BEST source for identifying specific threats relevant to cloud services?
Easy102A financial institution monitors the number of unauthorized access attempts to its core banking system. The risk owner recommends increasing the monitoring frequency from daily to hourly because a recent attack exploited a delayed detection. Which of the following is the PRIMARY benefit of this change?
Easy103A risk practitioner at a regional bank is building risk scenarios for the new mobile check deposit feature. The team has identified the event 'attackers exploit a vulnerability in the image processing library to inject malicious code.' Which of the following BEST describes the element that is missing from this risk scenario?
Medium104A security analyst notices that the number of failed login attempts has significantly increased over the past week. The SIEM alerts are not being triggered because the threshold was set too high. What is the MOST effective immediate action to improve monitoring?
Medium105Which THREE are best practices for control monitoring?
Medium106A multinational corporation is assessing the risk of a new cloud-based customer relationship management (CRM) system. The risk manager conducts a qualitative risk assessment using a risk matrix that plots likelihood vs. impact. Which of the following is the PRIMARY benefit of using a qualitative approach over a quantitative approach in this context?
Easy107A financial services firm is evaluating the risk of insider threat in its trading department. The risk team has identified that a small number of traders have elevated privileges that allow them to execute trades and access sensitive market data. The team must determine the MOST effective control to reduce the likelihood of unauthorized trading activity. Which control should they prioritize?
Hard108An organization's risk register lists a ransomware exposure against its primary order-processing system. The chief information security officer decides to purchase cyber insurance that covers ransomware losses up to $10 million. Which risk response has been selected?
Easy109A risk owner wants to implement continuous monitoring for a set of critical controls. Which of the following is the PRIMARY benefit of continuous monitoring over periodic testing?
Easy110A bank's risk committee reviews a monthly risk report that includes KRIs. One KRI shows that the number of failed transactions due to system errors is trending upward. The control owner states that the trend is within the risk appetite. However, the report also shows that the number of customer complaints is stable. What should the risk manager do FIRST?
Hard111During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?
Easy112A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:
Easy113A risk practitioner is reviewing the organization's vulnerability management programme. The vulnerability scan report shows thousands of findings, and remediation teams are overwhelmed. Which of the following is the MOST effective approach to prioritize remediation?
Easy114A multinational manufacturer is assessing the risk of a ransomware attack on its operational technology (OT) network. The risk team has identified that the OT network is segmented from the corporate IT network, but a shared jump server allows administrators to move between them. The team must determine the MOST significant factor that could increase the likelihood of ransomware spreading from IT to OT. Which factor should they prioritize?
Hard115A risk practitioner is assessing the risk associated with the organization's use of third-party APIs that integrate with its core banking platform. The practitioner needs to determine the MOST effective way to monitor the risk exposure of these APIs on an ongoing basis. Which of the following approaches BEST addresses this requirement?
Medium116A risk assessment of a critical financial application identifies a high inherent risk due to outdated software. The risk manager is considering mitigation options. Which TWO of the following would be considered preventive controls?
Medium117A healthcare provider is conducting a risk assessment for its electronic health record (EHR) system. The risk team has identified that a recent upgrade introduced a new vulnerability that could allow unauthorized access to patient data. The vulnerability has a known exploit but no patch is available yet. The team must decide on the BEST immediate risk response. What should they do FIRST?
Medium118A risk practitioner is designing a risk dashboard for the executive team. The organization has a high risk appetite for revenue-generating activities but a low risk appetite for regulatory compliance. Which combination of metrics should be prominently displayed?
Medium119A risk practitioner is assessing the likelihood that a nation-state actor will exfiltrate intellectual property from an aerospace manufacturer. The practitioner wants to express likelihood using a factor that reflects how attractive the manufacturer is as a target relative to its peers. Which approach BEST supports this?
Hard120A multinational corporation is conducting a risk assessment for its third-party vendors. The risk team has assigned a high inherent risk rating to a vendor that provides critical payroll processing. The vendor has recently provided a SOC 2 Type II report with no exceptions, and the contract includes a right-to-audit clause. The risk practitioner must determine the residual risk rating. Which factor is MOST important in making this determination?
Hard121A risk manager at a retail bank is reviewing the security architecture of an internal API that moves funds between customer accounts. The API is reachable only from the bank's private network, and developers argue that mutual TLS and OAuth 2.0 token validation are unnecessary because external attackers cannot reach it. Which risk principle should the risk manager apply to challenge this reasoning?
Hard122A university is implementing a new online learning management system (LMS) that will store student records, grades, and personal information. During the risk assessment, the IT team identifies that the LMS vendor's default configuration allows students to see each other's email addresses in the class roster. This could lead to privacy violations under FERPA regulations. The vendor states that this feature can be disabled in the settings but doing so will require manual configuration for each course. The university has a moderate risk appetite and wants to launch the system within two weeks. Which of the following is the MOST appropriate risk response?
Medium123A retail company has a risk monitoring program that tracks key risk indicators (KRIs) for its e-commerce platform. One KRI measures the number of failed payment transactions as a percentage of total transactions. The threshold is set at 2%. Over the past quarter, the KRI has been fluctuating between 1.8% and 2.5%, breaching the threshold several times. Each time the KRI exceeded the threshold, the risk owner performed a manual investigation and found that the failures were due to transient network issues that resolved on their own. The risk owner has now requested that the threshold be raised to 3% to avoid unnecessary investigations. The risk practitioner is evaluating this request. What should the risk practitioner do?
Medium124An IT risk report to the board of directors should primarily focus on which of the following?
Easy125A risk assessment team is prioritizing IT risks for treatment. Which THREE factors should be considered when prioritizing risks? (Select THREE)
Hard126A risk manager at a multinational bank is assessing the risk of a new third-party SaaS provider that will process customer transaction data. The provider stores data in a country with different data protection laws. Which of the following is the MOST critical risk factor to evaluate FIRST?
Hard127Which of the following is a leading indicator that the risk of a credential-based attack may be increasing?
Easy128A healthcare insurer's risk committee is reviewing key risk indicators (KRIs) for its claims processing platform. The committee wants to ensure the KRIs are actionable and tied to risk appetite. Which TWO of the following characteristics are MOST important for these KRIs to meet that objective? (Choose two.)
Hard129An organization has a risk appetite that is risk-averse. Which risk treatment option would be most aligned with this appetite?
Easy130A company is evaluating control types for a new system. The security team proposes implementing an intrusion detection system (IDS) and a backup restoration process. Which TWO control types do these represent, respectively?
Medium131A risk practitioner is assessing a cloud-hosted payroll application. The vendor's SOC 2 report shows effective controls, but the report covers only the period ending eight months ago, and the vendor has since migrated to a new hosting region. The practitioner needs to determine whether the control environment can still be relied upon. Which of the following is the MOST appropriate next step?
Hard132During an IT risk assessment, the risk owner identifies a high inherent risk for a legacy system. After implementing a firewall and intrusion detection system, the residual risk is calculated. Which of the following best describes residual risk?
Medium133A large financial institution has implemented a risk monitoring framework that includes KRIs for operational risk. Recently, a critical KRI related to trade settlement errors has been showing an upward trend, but it remains within the approved threshold. The risk manager is concerned because the trend indicates potential control degradation. The control owner argues that since the KRI is still within threshold, no action is needed. The risk manager wants to determine the best course of action to address the trend before it breaches the threshold. The organization's risk policy requires proactive monitoring. What should the risk manager do?
Hard134An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?
Medium135An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?
Hard136A risk analyst at a healthcare provider is assessing the risk of a ransomware attack on a clinical data repository. The analyst estimates that a ransomware event would cost $800,000 in recovery and downtime, and that such an event is likely to occur once every four years. What is the annualized loss expectancy (ALE) for this risk?
Medium137A retail company is migrating its customer loyalty application to a cloud provider. During a risk assessment, the risk practitioner notes that the provider's infrastructure is shared across many tenants. Which of the following is the MOST significant risk that this multi-tenancy introduces?
Medium138An organization's board has set a risk appetite statement that says: 'We accept moderate levels of operational risk but will not tolerate any compliance violations.' During risk identification, which type of risk should be given the HIGHEST priority?
Medium139A risk practitioner is assessing the effectiveness of the control environment supporting an online trading platform. Management asserts that controls are mature, but the practitioner must determine which activities constitute control monitoring rather than one-time assurance. Which TWO of the following activities are examples of ongoing control monitoring? (Choose two.)
Hard140A company is assessing a new vendor that will have access to its customer database. The vendor's security questionnaire reveals they lack SOC 2 certification. According to risk tiering, the vendor is classified as critical. What should the company do?
Medium141During a risk assessment, a risk manager is evaluating the effectiveness of a firewall rule set. The manager notes that the firewall logs show a high number of dropped packets from a specific IP range, but no policy changes have been made. The manager suspects the firewall rule set may be misconfigured. Which of the following should the manager do FIRST?
Hard142During a threat modeling exercise using the STRIDE methodology, a security analyst identifies a threat where an attacker can modify data in transit between a web server and database. Which STRIDE category does this threat belong to?
Hard143A financial institution is implementing a cloud-based data analytics platform. The data includes personally identifiable information (PII) of customers in multiple jurisdictions. Which of the following is the MOST critical risk consideration?
Hard144An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
Hard145A company is implementing COBIT 2019 and wants to ensure that risk management activities are aligned with business objectives. Which governance objective is primarily responsible for evaluating, directing, and monitoring risk management?
Medium146A financial institution is adopting AI for credit scoring. The model is currently a black box and requires explainability for regulatory compliance. Which risk is MOST critical to address?
Medium147Which type of control testing is typically performed on a continuous basis using automated tools?
Easy148Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?
Hard149An enterprise is migrating to a public cloud environment. Which THREE of the following are critical cloud-specific risk considerations?
Hard150A risk manager is identifying risks for a new mobile payment application. The application will use end-to-end encryption. Which of the following is the BEST source of risk information for identifying potential threats?
Easy151A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)
Hard152Refer to the exhibit. A SIEM correlation rule 'Brute_Force_SSH' has fired excessively due to traffic from internal monitoring servers. What is the BEST course of action?
Easy153Which THREE of the following are typical exclusions in a cyber insurance policy?
Medium154A risk practitioner is identifying risks for an organization that has adopted a bring-your-own-device policy for remote workers. The practitioner wants to document vulnerabilities that increase the likelihood of a data loss event. Which TWO of the following are MOST appropriately classified as vulnerabilities in this scenario? (Choose two.)
Medium155Refer to the exhibit. The control test failed because unauthorized access attempts were detected. The remediation plan suggests additional logging. Is this remediation appropriate?
Hard156A global investment firm maintains a central risk register. The CISO wants to reduce the number of entries by consolidating risks that share the same root cause. Which action BEST supports this goal while preserving the risk register's integrity?
Medium157Which of the following BEST describes the difference between a threat actor who is a 'hacktivist' and one who is an 'organized crime' actor?
Medium158An organization has received a critical vulnerability alert for a web application firewall. The risk owner is on leave. What should the risk manager do?
Medium159A risk manager is updating the risk report for the IT steering committee. Which THREE elements should be included to provide a comprehensive view of the risk posture?
Hard160A healthcare organization is migrating its electronic health records (EHR) system to a public cloud. The risk manager identifies several risks. Which TWO of the following are the MOST significant risks related to data privacy and regulatory compliance?
Medium161A company is migrating critical applications to the cloud. The risk manager is assessing the shared responsibility model. Which risk is the customer typically responsible for?
Medium162A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?
Easy163A retail company is assessing risk for a legacy point-of-sale system that cannot be patched. The risk team wants to identify controls that would reduce the likelihood of a successful exploitation of known vulnerabilities on these terminals. Which TWO of the following are preventive controls that would BEST reduce the likelihood of exploitation? (Choose two.)
Hard164A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?
Medium165During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?
Easy166A risk analyst is building a scenario for a ransomware event affecting a hospital's electronic health record environment. The analyst wants to capture loss magnitude dimensions that are frequently overlooked when only direct recovery costs are counted. Which TWO loss factors should be included to make the magnitude estimate more complete? (Choose two.)
Medium167A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?
Hard168A risk practitioner at a payments processor is reviewing the organization's risk register and notices that several risk entries describe only the consequence, such as 'customer data is exposed.' The practitioner wants each entry to follow the ISACA risk scenario structure. Which of the following should the practitioner add to each entry to complete the scenario?
Hard169Which type of control is designed to reduce the likelihood of a risk event occurring?
Easy170A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?
Medium171During a vulnerability assessment, a risk practitioner identifies that a web application is vulnerable to SQL injection, which is listed in the OWASP Top 10. Which type of vulnerability identification technique MOST likely discovered this issue?
Medium172An organization has implemented a continuous monitoring solution for its critical applications. The IT team reports that the monitoring tool generates a high volume of false positives. What is the BEST course of action?
Medium173Which of the following is a common exclusion in cyber insurance policies that a risk manager should be aware of?
Easy174A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?
Medium175After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?
Hard176A risk manager is identifying risks for an organization that uses a hybrid cloud environment. The organization stores sensitive data on-premises and in the cloud. Which of the following is the MOST effective method for identifying risks related to data residency and compliance?
Medium177Which THREE of the following are key considerations when evaluating cyber insurance coverage? (Select three.)
Medium178A multinational organization uses multiple risk management systems that do not integrate with each other. The risk team manually consolidates data into a spreadsheet for reporting. This process is error-prone and time-consuming. Which of the following is the BEST long-term solution to improve risk monitoring and reporting?
Hard179A retail company is moving its customer loyalty application to a SaaS platform. The risk practitioner must ensure that the cloud provider's security controls are adequate. Which of the following is the MOST effective way to obtain assurance over the provider's controls?
Medium180A financial institution uses a quantitative risk assessment for a core banking system. The annual loss expectancy (ALE) is calculated as $500,000 with a single loss expectancy (SLE) of $2,500,000. What is the annualized rate of occurrence (ARO)?
Hard181A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?
Medium182When developing IT risk scenarios, connecting them to business impact is critical. Which of the following BEST describes how a risk practitioner should link a technical scenario to business impact?
Hard183A national retail chain is building a risk register for its new e-commerce platform. The CISO asks the risk practitioner to identify the inherent risk associated with a recently disclosed SQL injection vulnerability in a third-party payment gateway module. Which of the following BEST describes inherent risk in this scenario?
Medium184Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?
Medium185Which of the following best describes the purpose of tactical risk reporting?
Medium186A software development company uses a third-party cloud provider to host its source code repositories. The risk practitioner discovers that the provider's contract does not include a right-to-audit clause. The provider has a strong security reputation but is unwilling to add the clause. The company's risk appetite for third-party risk is low. Which action should the risk practitioner recommend FIRST?
Hard187An IT risk report for the board of directors should primarily focus on:
Medium188Which TWO of the following are examples of continuous monitoring activities? (Select TWO.)
Medium189An insurance company is expanding into a new country and must identify IT risks arising from local data protection law, which requires customer data to remain within national borders. The risk practitioner is mapping this requirement into the enterprise risk register. Which of the following is the MOST appropriate way to characterize this risk?
Hard190A retail bank is building a risk register for its newly deployed mobile payment API. The CISO asks the risk practitioner to classify the risk that attackers could manipulate the API request parameters to bypass transaction limits. Under which CRISC risk identification category should this risk PRIMARILY be recorded?
Medium191Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you discover that the target company uses a legacy ERP system that is no longer supported by the vendor. They have no disaster recovery plan for this system, and it contains financial data critical to the merged entity. The integration timeline is aggressive, and replacing the system would delay the merger by 18 months. The executive team is reluctant to delay. What is the BEST risk treatment option?
Hard192An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:
Hard193A company is developing risk scenarios for business impact analysis. Which of the following scenario components directly links the risk event to potential financial loss?
Medium194A risk owner is reviewing a control that has a deficiency rate of 15%. The target deficiency rate is less than 5%. Which of the following is the MOST appropriate immediate action?
Medium195A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)
Medium196Which THREE of the following are essential components of an effective IT risk report to senior management? (Select THREE.)
Hard197A university is deploying a new student information system that will store grades, financial aid records, and health center notes. The risk practitioner must determine the data classification that drives encryption, access, and retention requirements. Which factor is MOST important in setting that classification?
Medium198A company has a low risk appetite but high risk tolerance. Which of the following scenarios is consistent with this situation?
Hard199An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?
Hard200A global manufacturer's risk committee is defining the organization's risk capacity and risk appetite for IT risk. The chief risk officer asks the practitioner to clarify how these two concepts relate. Which of the following statements is MOST accurate?
Hard201A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?
Easy202A risk manager notices that a key risk indicator (KRI) for system downtime has exceeded the threshold for two consecutive months. What is the MOST appropriate immediate action?
Easy203A company implements a new automated control to monitor user access rights. The control sends a daily report of any users with excessive privileges. What is the PRIMARY benefit of this control?
Easy204Which of the following is the BEST indicator that an organization's IT risk assessment process is effective?
Easy205A multinational corporation is implementing a risk treatment plan for a critical vendor that has poor security controls. The risk practitioner has recommended contract renegotiation to include security requirements, but the vendor refuses. The business unit insists on continuing the relationship due to cost savings. The risk practitioner's next step should be to:
Hard206A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)
Medium207An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?
Hard208A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?
Hard209An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:
Medium210An organization is implementing a new identity and access management (IAM) system. The risk manager is tasked with identifying risks associated with the migration from legacy authentication to single sign-on (SSO). Which of the following is the GREATEST risk during this migration?
Easy211An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?
Medium212Which THREE of the following are typical components of a risk scenario?
Hard213An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?
Medium214A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?
Medium215A software development company is assessing the risk of a data breach in its cloud-based source code repository. The risk assessment team has identified that the repository contains proprietary algorithms and customer data. The team is considering implementing a control that would encrypt the data at rest. Which of the following BEST describes the impact of this control on the risk?
Hard216A risk practitioner is identifying risks associated with the decommissioning of a legacy data center. The organization plans to migrate all remaining applications to a cloud environment. Which TWO of the following are the MOST significant risks that should be included in the risk register for this project? (Choose two.)
Hard217A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?
Hard218A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?
Easy219Which of the following is a leading Key Risk Indicator (KRI) for the risk of a data breach?
Medium220A risk manager is evaluating the security of a new API gateway that will expose internal microservices to external partners. The gateway will handle authentication, rate limiting, and request routing. Which risk is MOST critical to address before go-live?
Hard221A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?
Hard222A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?
Hard223During a risk assessment, an organization identifies that its remote workforce uses personal devices for work. The risk manager is concerned about data leakage. The organization has a risk appetite that is 'moderate' and wants to treat the risk. Which of the following is the MOST effective risk treatment option?
Hard224A healthcare provider has identified a risk that a critical medical imaging system runs on an unsupported operating system. The risk owner determines that the residual risk exceeds the organization's risk appetite, but upgrading the system would cost $2 million and disrupt patient care for several weeks. Which of the following is the MOST appropriate next step?
Medium225Which TWO of the following are key elements that should be included in an IT risk assessment report?
Easy226A risk practitioner is estimating the likelihood of a ransomware event affecting a manufacturing firm's operational technology environment. Historical incident data is sparse, so the practitioner convenes plant engineers, security staff, and the insurance broker to elicit calibrated estimates and combine them into a reasoned likelihood. Which technique is being used?
Hard227A risk practitioner is assessing the security of a new software-defined wide area network (SD-WAN) deployment that will carry regulated traffic between branch offices and a cloud environment. The vendor's controller is managed by a third party. Which of the following risks should the practitioner identify as the MOST significant?
Hard228During a risk assessment for a cloud migration project, the IT risk manager identifies that the organization lacks visibility into the cloud provider's security controls. Which approach should the risk manager recommend to address this risk?
Medium229A multinational retailer operates in 14 countries and must report IT risk to its board quarterly. The CISO wants the reporting to drive decisions rather than merely satisfy auditors. Which of the following is the MOST important characteristic of the quarterly IT risk report?
Hard230During a control self-assessment, an operational manager reports that a manual review control is performed quarterly instead of monthly as documented. What should the risk practitioner do?
Easy231A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?
Easy232Which of the following is the best example of a Key Control Indicator (KCI) for a firewall rule review process?
Medium233A financial services firm is performing an IT risk assessment on its legacy 3270-based transaction processing system. The system has no vendor support, no documentation, and only two remaining staff members who understand its internals. The risk committee asks the risk analyst to determine the MOST appropriate way to characterize the risk associated with this asset. Which of the following should the analyst do FIRST?
Medium234A multinational corporation is deploying a new IoT-based inventory management system across its warehouses. The risk practitioner identifies that the IoT devices use default administrative credentials and unencrypted communication protocols. The vendor states that a firmware update to address these issues will not be available for six months. The business cannot delay the deployment due to competitive pressures. Which risk response strategy is MOST appropriate in this situation?
Hard235A retail company has identified that its point-of-sale (POS) terminals are running an outdated operating system that no longer receives security patches. The risk practitioner recommends upgrading the terminals to a supported OS. The cost of the upgrade is $500,000, while the estimated annual loss from a potential breach is $2,000,000 with a 30% likelihood. Which risk response strategy is being recommended?
Easy236An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?
Medium237A company uses a dashboard to monitor KRIs. One KRI shows a warning level, but the data is two months old. What is the primary concern?
Hard238A healthcare organization is required by law to retain patient records for seven years. The IT department proposes storing backups on tapes that are kept in an on-site vault. The risk manager notes that the on-site vault is in a flood zone. Which risk response strategy is being applied if the organization decides to move the tapes to a secure off-site facility in a different geographic region?
Easy239Which of the following is a threat intelligence source that provides information about known exploited vulnerabilities, maintained by a government agency?
Easy240Which type of threat actor is characterized by having significant resources, advanced skills, and often state-sponsored objectives?
Easy241A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?
Hard242Refer to the exhibit. What risk is introduced by this IAM policy?
Hard243After a security incident, a company implements a new control and begins monitoring its effectiveness. Which of the following metrics would BEST indicate that the control is achieving its objective?
Medium244A bank's fraud detection system generates an alert for a transaction, but subsequent investigation finds it false. What should be done?
Medium245An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?
Medium246An IT risk analyst is preparing a report for the board risk committee. The committee wants a single view of how much loss the organization could face from IT risks over the next year if no additional controls are implemented. Which metric should the analyst use?
Easy247During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?
Medium248A financial services firm operates a high-volume transaction processing platform. During a risk assessment, the risk owner determines that the residual risk of database corruption exceeds the risk appetite. The database vendor offers a patch that reduces the vulnerability but requires a 12-hour outage. Business stakeholders refuse the outage. The risk practitioner is asked to recommend a risk response that aligns with the risk appetite without disrupting operations. Which of the following is the BEST recommendation?
Hard249A company is planning to migrate to post-quantum cryptography. What is the primary risk that quantum computing poses to current cryptographic systems?
Medium250A risk practitioner at an insurance company is identifying risks for a newly deployed customer portal that integrates with a third-party identity provider. She wants to document external factors that could increase the likelihood of a data breach. Which TWO of the following are external risk factors she should capture? (Choose two.)
Medium251A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?
Medium252Which of the following is the PRIMARY source for identifying known software vulnerabilities in a systematic manner?
Medium253An organization is selecting a control to prevent unauthorized access to a critical database. Which control type is most appropriate?
Easy254A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk assessment team has identified that the likelihood of an attack is high due to recent industry trends, and the impact would be severe, including patient safety risks and regulatory fines. The organization has a limited budget and wants to implement controls that provide the greatest risk reduction. Which of the following risk response strategies is MOST appropriate in this scenario?
Hard255A risk manager uses a 5x5 heat map to plot the likelihood and impact of identified risks. This approach is an example of which type of risk analysis?
Easy256A multinational corporation uses commercial threat intelligence feeds and participates in an ISAC. However, they recently missed a critical vulnerability exploited in the wild that was not in their feeds. Which additional source should they incorporate to improve vulnerability identification?
Hard257A company operates a legacy system for which the vendor no longer provides security patches. What is the most critical risk to identify regarding this system?
Medium258A retail company is conducting an IT risk assessment for its point-of-sale (POS) system. The risk team has identified several threats, including malware, insider theft, and denial-of-service (DoS) attacks. The company currently uses antivirus software, firewalls, and role-based access controls. Which TWO of the following are the MOST appropriate risk response actions to address the identified threats? (Choose two.)
Medium259A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?
Medium260An organization is implementing a new control to address a high-risk finding. The project manager has scheduled a user training session and updated the relevant policies. Which implementation phase is being addressed?
Hard261Based on the exhibit, which of the following is the MOST likely risk scenario?
Easy262Which risk reporting level is typically provided to the board of directors and focuses on strategic risk posture?
Easy263A company has a control that automatically rejects transactions over $10,000. During a review, it is found that 2% of transactions over $10,000 were approved due to a system glitch. The control owner says the glitch has been fixed. What should the risk practitioner do next?
Hard264A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?
Hard265A multinational manufacturer is migrating its disaster recovery capability for a core ERP system from a warm standby data center to a cloud-based recovery service. The risk practitioner is validating the recovery design. Which TWO of the following should be validated to confirm the recovery time objective can realistically be met? (Choose two.)
Hard266A risk manager is reviewing the control monitoring reports and finds that a key control's effectiveness rating has dropped from 'effective' to 'partially effective' due to increased errors in manual data entry. Which of the following is the BEST course of action?
Hard267A financial services firm is conducting an IT risk assessment on a legacy trading application. The assessment team wants to prioritize risks based on the combination of the likelihood of a threat event and the magnitude of its impact. The firm has limited resources and needs to focus on the most significant risks first. Which of the following BEST describes the purpose of using a risk map (heat map) in this context?
Medium268Which of the following is the BEST example of a key risk indicator (KRI) for the risk of unauthorized access to sensitive data?
Easy269An organization is evaluating cyber insurance to mitigate financial risk from potential data breaches. Which factor would most likely increase the insurance premium?
Medium270An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?
Medium271During a quantitative risk analysis, the risk team calculates the loss event frequency (LEF) using the FAIR framework. If the threat event frequency (TEF) is 10 per year and the vulnerability (V) is 0.3, what is the LEF?
Hard272A manufacturing company's board of directors receives a monthly risk report. Which key performance indicator (KPI) is MOST relevant for the board to assess the effectiveness of internal controls?
Easy273A retail company is prioritizing risks for the coming year. Management wants to focus resources where the potential financial loss is greatest, but the risk team has only ordinal likelihood and impact ratings. Which approach BEST supports this prioritization?
Medium274An IT risk manager is facilitating a brainstorming session to identify threats. Which technique is BEST suited for identifying a wide range of potential threats?
Easy275A hospital's risk practitioner is identifying risks for a new telehealth platform. The IT director asks which source would be MOST useful for identifying vulnerabilities specific to the platform's underlying commercial software components. Which of the following should the practitioner use?
Easy276During a risk assessment, the risk team identifies that a legacy system has multiple known vulnerabilities that cannot be patched. The system is critical for operations. Which of the following risk treatment options is MOST appropriate?
Hard277A risk practitioner at a regional hospital is building a risk register for its new electronic health record (EHR) system. The system stores protected health information (PHI) and is subject to HIPAA. The practitioner wants to ensure that the risk register captures the potential for unauthorized disclosure of PHI. Which of the following should the practitioner PRIMARILY use to identify the relevant threats and vulnerabilities for this system?
Medium278A multinational manufacturer is consolidating IT risk data from business units into a single enterprise risk report for the board. The risk manager must ensure the report supports effective risk-based decision making. Which TWO of the following characteristics are MOST important for the consolidated report to include? (Choose two.)
Hard279A risk practitioner is assessing the likelihood of a distributed denial-of-service (DDoS) attack against an online retailer's checkout service during peak shopping season. Which of the following factors would MOST increase the assessed likelihood of this event?
Hard280A risk manager is assessing the impact of quantum computing on the organization's cryptographic infrastructure. The timeline for quantum advantage is estimated to be 10 years. What is the most appropriate immediate action to address this risk?
Hard281A risk practitioner at a healthcare payer is reviewing the organization's identity and access management (IAM) controls. The practitioner discovers that several terminated employees still have active single sign-on (SSO) sessions and directory accounts. Which of the following is the MOST effective control to address this risk?
Medium282A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?
Medium283A change to a critical application is being implemented without updating the associated security controls. This is most likely a failure in which process?
Hard284A risk analyst is reviewing control monitoring results and notices that a detective control has a high false positive rate. What is the BEST action to improve the control's efficiency?
Easy285A company is conducting a risk assessment of a critical third-party service provider. Which of the following is the BEST source of information to identify risks associated with the provider's sub-processors?
Medium286Which TWO controls are most effective for reducing the risk of data leakage from endpoints in a remote work environment?
Medium287A retail company is conducting a risk assessment for its point-of-sale (POS) system. The risk team has identified several factors that could affect the likelihood of a data breach. Which TWO factors are considered threat event frequency components that increase the likelihood of a breach? (Choose two.)
Medium288A risk practitioner is designing a monitoring dashboard for operational risk. Which of the following is the most important consideration?
Medium289During an IT risk assessment for a new cloud-based customer relationship management (CRM) system, the risk practitioner identifies that the vendor's data center is located in a country with different data protection regulations. Which of the following is the MOST appropriate next step?
Medium290An organization uses a risk register that includes inherent risk, control effectiveness, and residual risk. During a quarterly review, the risk owner updates control effectiveness from 'partially effective' to 'effective'. What effect does this have on the residual risk rating?
Hard291A control owner reports that a preventive control is operating as designed, but the risk owner is concerned that residual risk remains high. What should the risk practitioner do NEXT?
Easy292Which TWO of the following are leading indicators that could be used as KRIs for information security risk? (Select TWO.)
Medium293When performing asset-based vulnerability identification, a security analyst uses the Common Vulnerabilities and Exposures (CVE) database along with the National Vulnerability Database (NVD). Which of the following BEST describes the relationship between CVE and NVD?
Hard294Which of the following best describes residual risk?
Easy295An international bank is expanding its operations into a new country with strict data localization laws. The IT department plans to use a cloud service provider that stores data in neighboring countries but promises compliance. The risk team has identified several potential risks: regulatory fines for non-compliance, data interception during cross-border transmission, and difficulty in auditing the cloud provider. The legal team advises that the contract includes data protection clauses, but these have not been tested. The risk manager must now prioritize risk identification efforts. What is the MOST important risk identification step the risk team should undertake?
Hard296An organization uses automated SIEM rules to continuously monitor for unauthorized access attempts. This is an example of which type of monitoring?
Easy297Which risk identification technique relies on analyzing past incidents to predict future risks?
Easy298A financial services firm has a risk register entry for a core banking application with an inherent risk score of 9 (high). The risk owner implements a new database activity monitoring tool and role-based access reviews. After implementation, the residual risk score is reassessed at 6 (medium). The risk owner now wants to formally document that the risk has been reduced to an acceptable level. Which action should the risk practitioner recommend NEXT?
Medium299A hospital's risk practitioner is building a risk register entry for a ransomware attack on its electronic health record (EHR) system. The practitioner wants to express the risk in terms of how often the event is expected to occur and how much it would cost if it did. Which of the following BEST describes the two components being quantified?
Medium300A multinational corporation has a risk register entry for a potential data breach of customer information. The risk owner has decided to purchase cyber insurance to cover financial losses from a breach. Which of the following BEST describes the residual risk after this risk response?
Hard301An organization is considering moving from periodic control testing to continuous monitoring for its critical financial controls. What is the PRIMARY benefit of this transition?
Hard302A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk team has identified that the organization performs daily incremental backups and weekly full backups, but the backups are stored on the same network share as the EHR data. The risk owner argues that the backup strategy reduces the impact of a ransomware attack. Which statement BEST describes the residual risk after considering this control?
Hard303An organization is performing a business impact analysis (BIA) for its critical applications. Which TWO of the following are primary objectives of a BIA?
Easy304Refer to the exhibit. What is the most appropriate immediate action for the control failure?
Medium305A risk assessment identifies a high-likelihood, high-impact risk associated with a legacy system. The business owner decides to decommission the system to eliminate the risk. Which risk treatment option is being applied?
Medium306In a risk report presented to the board of directors, which of the following elements is most appropriate to include?
Medium307A security operations center (SOC) uses a Security Information and Event Management (SIEM) system to continuously monitor for suspicious activities. Which type of monitoring is being performed?
Medium308A business continuity manager wants to identify risks that could disrupt critical business processes. Which source of information would be MOST valuable for identifying such risks?
Medium309A software development company uses a DevOps pipeline with automated code deployment. Recently, a developer accidentally pushed a configuration file containing database credentials to a public repository. The credentials were changed within an hour, but the file remained public for a few hours. The risk team is now identifying risks in the CI/CD process. The security team has proposed adding static code analysis to detect secrets in code. The development team objects, citing false positives. The risk manager must identify the most significant risk that could lead to a data breach. Which risk should be prioritized?
Hard310A security team is considering implementing a control to prevent unauthorized access to a critical database. Which type of control is most appropriate for this objective?
Easy311A risk assessment reveals that a legacy system has a high vulnerability score but low business criticality. The cost to remediate is high. What is the MOST appropriate risk response?
Medium312A risk practitioner is working with the IT team to design controls for a new cloud-based human resources system. The team proposes using encryption for data at rest and in transit, role-based access controls, and regular backups. The risk practitioner notes that these controls address confidentiality, integrity, and availability. Which of the following should the risk practitioner recommend to ensure the controls remain effective over time?
Hard313An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?
Medium314A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?
Hard315A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?
Hard316A financial institution is assessing the risk of a new real-time payment system. The risk manager calculates that the annualized loss expectancy (ALE) for a potential fraud scenario is $500,000. The cost to implement a fraud detection solution is $200,000 initially with $50,000 annual maintenance. The solution is expected to reduce the ALE by 80%. What is the net benefit of implementing the solution over three years?
Hard317Which type of control is designed to operate before an event to prevent an undesirable outcome?
Easy318Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?
Medium319A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?
Medium320A risk practitioner is facilitating a workshop to identify risks for a new customer-facing payment portal. The CISO wants the exercise to capture risks arising from both internal process weaknesses and external threat sources without producing an unmanageable list. Which approach is MOST appropriate for structuring the risk identification effort?
Medium321A risk manager is evaluating the risk of a distributed denial-of-service (DDoS) attack against the organization's public-facing web application. The organization has a 1 Gbps internet connection and no DDoS mitigation service. Which of the following is the MOST important factor in determining the potential impact of a volumetric DDoS attack?
Hard322A newly appointed risk owner is reviewing a risk register entry for an aging payroll application. The entry shows a likelihood rating, an impact rating, an inherent risk score, and a residual risk score, but no owner signature or review date. Which action should the risk practitioner take FIRST to strengthen the register's usefulness for IT risk assessment?
Easy323A risk practitioner is cataloging external factors that could create IT risk for a logistics firm expanding into a new country. Which TWO of the following are external factors that should be included in the risk identification effort? (Choose two.)
Hard324A risk analyst at a regional bank is assessing the risk to its core banking platform. The analyst finds that the platform has a known vulnerability with a high exploitability score, but the platform is isolated on a segmented network with no external connectivity and strict change control. The analyst must determine the PRIMARY factor that reduces the likelihood of exploitation. Which factor should the analyst emphasize?
Medium325A global retailer's risk committee is reviewing a proposal to transfer the financial impact of payment card fraud to an insurer through a cyber insurance policy. The policy has a $2 million retention and excludes losses caused by unencrypted cardholder data at rest. The organization's cardholder database is currently unencrypted. Which of the following is the MOST significant limitation the risk manager should highlight?
Hard326A risk practitioner is reviewing the results of a control self-assessment (CSA) and finds that the control owner rated a control as 'effective' but an independent audit found control weaknesses. What is the BEST explanation for this discrepancy?
Hard327A risk practitioner is defining key risk indicators (KRIs) for the organization's third-party risk program after several supplier outages disrupted operations. Which TWO characteristics are essential for these KRIs to be effective for the risk committee? (Choose two.)
Hard328In the FAIR model, 'Loss Event Frequency' is calculated as:
Hard329A company is integrating its IT risk management program with the enterprise risk management (ERM) program. What is the primary benefit of this integration?
Hard330An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?
Hard331An organization uses a risk appetite statement that limits operational losses to $2 million per quarter. A new risk reporting dashboard shows that current operational losses are $1.8 million with two weeks remaining in the quarter. The head of risk management wants to ensure that losses remain within appetite. Which of the following control monitoring reports would be MOST useful for proactive decision-making?
Hard332A financial services firm maintains a risk register that lists inherent risk ratings for its core banking platform. During an internal audit, the CIO notes that the register has not been updated to reflect the controls implemented over the past 18 months. Which of the following should the risk practitioner do FIRST to address this gap?
Medium333A risk analyst is evaluating a critical customer database. The asset value is $2,000,000; the exposure factor if the database is compromised is 40%. The annualized rate of occurrence (ARO) for a successful breach is estimated at 0.25. What is the annualized loss expectancy (ALE)?
Medium334Which enterprise architecture layer is most directly responsible for managing the storage and processing of data, and for which data classification and encryption controls are critical?
Easy335During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?
Easy336An organization uses the FAIR framework to calculate annualized loss expectancy (ALE) for a specific risk. Given that the single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2, what is the ALE?
Medium337Which TWO of the following are examples of risk mitigation controls?
Easy338A financial services firm is performing an IT risk assessment on a legacy trading platform. The risk team has identified several weaknesses in the platform's patch management process. Which TWO of the following are examples of vulnerabilities that should be recorded in the risk register? (Choose two.)
Hard339Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)
Easy340Which of the following is an example of a leading indicator?
Easy341During a cost-benefit analysis for a proposed control, the annual loss expectancy (ALE) for a risk is currently $500,000. The control is expected to reduce the ALE by 80% and will cost $150,000 per year. What is the net benefit of implementing the control?
Medium342During a quarterly risk review, a risk owner reports that a critical trading application has exceeded its residual risk tolerance for the second consecutive quarter despite remediation efforts. The risk owner proposes to continue remediation and report again next quarter. Which of the following should the risk manager do?
Medium343An organization is implementing a new cloud-based customer relationship management (CRM) system. The risk practitioner is designing the control monitoring plan. Which approach BEST ensures continuous monitoring of controls across both the application and infrastructure layers?
Hard344An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?
Hard345A risk manager is using a 5x5 heat map to assess IT risks. Which of the following best describes the primary limitation of this qualitative risk analysis approach?
Easy346Which THREE of the following are effective risk treatment strategies?
Hard347Which of the following best describes the primary limitation of qualitative risk analysis?
Medium348A quantitative risk analysis using FAIR requires estimating which THREE primary factors?
Hard349A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?
Hard350When prioritizing risk treatment actions, which of the following should be the primary consideration?
Medium351An organization uses continuous monitoring via SIEM rules to detect anomalies. The SIEM generates an alert when the number of failed logins exceeds a threshold. This monitoring is an example of:
Hard352A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)
Easy353An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?
Hard354A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?
Hard355A risk analyst is assessing the impact of a potential ransomware attack. Which THREE categories of business impact should be considered?
Medium356A healthcare payer's risk committee is deciding how to respond to a risk that its cloud-hosted claims processing platform could become unavailable for more than 24 hours. The platform is critical, the provider offers a financially backed 99.95% availability commitment, and the organization lacks the internal capability to run a secondary environment. Which risk response is MOST appropriate?
Hard357You are the risk manager for a multinational corporation that relies heavily on a cloud-based ERP system. The system is critical for financial reporting and supply chain management. Recently, the company experienced a significant increase in the number of failed user authentication attempts, which were traced to a misconfiguration in the identity management module. The misconfiguration was detected by the security operations center (SOC) through log analysis, but it took three days to identify and resolve. The root cause was a change made by a cloud administrator without following the change management process. The incident resulted in a temporary denial of service for external users. The company's risk appetite for system availability is low, with a tolerance for downtime of no more than one hour per month. The current monitoring controls include quarterly access reviews and SOC monitoring of logs with a 24-hour review cycle. The board has requested a report on the incident and recommendations to prevent recurrence. What is the MOST effective recommendation to improve monitoring and reduce the likelihood of similar incidents?
Hard358Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)
Hard359Which of the following is an example of a detective control in IT risk management?
Easy360A financial institution has a control that manually reviews all wire transfers over $10,000. During an audit, it was found that the review is completed within 24 hours for 95% of transactions, but the target is 99%. The process owner wants to improve the control's effectiveness. Which of the following would be the MOST effective remediation?
Hard361Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?
Hard362A risk manager notices that a key risk indicator (KRI) for network downtime has been steadily increasing over the past three months. The current value is 15% above the risk tolerance threshold. Which of the following is the BEST immediate action?
Easy363An IT risk manager is facilitating a workshop to identify risks for a new mobile banking application. Which technique is MOST appropriate for generating a comprehensive list of risks?
Easy364A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?
Hard365An IT risk manager is performing a risk assessment for a new cloud service. Which TWO of the following are key inputs to the risk identification process? (Select TWO.)
Medium366An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)
Hard367A software company allows developers to push code directly to production using a CI/CD pipeline. A recent post-incident review found that a developer's compromised credentials were used to deploy malicious code that exfiltrated customer data. Which control would MOST effectively reduce the risk of this specific attack path recurring?
Medium368A risk practitioner is conducting a risk assessment for a new mobile application that will process credit card payments. The practitioner needs to identify relevant threats. Which of the following is the MOST appropriate source for identifying threats specific to this application?
Easy369A risk practitioner is identifying risks related to a new API gateway implementation. Which TWO of the following are MOST likely to be significant risks?
Easy370Which TWO of the following are examples of detective controls?
Medium371An organization has a risk indicator that shows the number of failed login attempts per day. The threshold is 100. Last week, the number spiked to 200 on two days. What does this indicate?
Easy372You are the IT risk manager for a financial institution. During a routine vulnerability scan, you discover that a critical web application has a high-severity vulnerability that could allow remote code execution. The development team states that a patch is not yet available from the vendor, and the application is business-critical with no acceptable downtime. The risk owner wants to accept the risk. However, the organization's risk appetite is very low for security vulnerabilities. You have been asked to recommend a course of action. Which of the following should you recommend?
Medium373During a risk assessment for a cloud migration project, the risk team identifies that the new SaaS application has not been tested for interoperability with existing identity management systems. The project manager argues that the integration will be straightforward and asks to remove this from the risk register. Which of the following is the BEST response from the risk practitioner?
Medium374During a third-party risk management review, the organization is tiering its vendors based on risk. Which TWO of the following criteria are most relevant for determining vendor risk tier?
Medium375During a risk assessment, a risk owner is unsure about the likelihood rating for a specific threat. Which of the following is the BEST source of information to determine the likelihood?
Easy376A company is implementing a new cloud-based customer relationship management (CRM) system. The IT risk manager needs to assess the risk of data exfiltration by a malicious insider at the cloud provider. Which risk assessment approach is most appropriate for this scenario?
Medium377A power utility company is required to comply with NERC CIP standards. The risk manager is assessing the impact of connecting a remote substation's OT network to the corporate WAN. Which of the following is the MOST significant risk that must be addressed to comply with NERC CIP?
Hard378A risk practitioner is analyzing the risk of insider threat in a software development company. The practitioner wants to assess the likelihood of a developer exfiltrating source code. Which of the following factors would MOST directly increase the likelihood of this risk?
Medium379Which of the following is the BEST indicator that a control is effective in mitigating a risk?
Easy380A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?
Hard381A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?
Medium382An organization is deploying IoT devices for environmental monitoring in a manufacturing facility. Which THREE of the following are significant security risks that should be addressed? (Select THREE.)
Hard383An access control policy includes a default deny rule (DenyAll) and an explicit allow rule. During a monitoring review, the risk practitioner notices that the DenyAll rule is never evaluated because the explicit allow matches first. What is the MOST likely monitoring gap?
Medium384An organization is implementing continuous monitoring of its network using SIEM rules. Which of the following is the PRIMARY benefit of this approach over periodic manual testing?
Hard385An organization is evaluating threat intelligence feeds to improve IT risk identification. Which of the following criteria should be given the HIGHEST priority when selecting a feed?
Hard386Order the steps for implementing a risk treatment plan.
Medium387An organization is developing an IT risk universe. Which of the following is the PRIMARY purpose of creating a comprehensive IT risk universe?
Medium388A company has identified a risk of data exfiltration through an outdated encryption protocol. The risk assessment team determines that the likelihood is low, but the impact is very high. The company decides to update the encryption protocol. This risk response is an example of:
Medium389An organization is performing a risk assessment for its new customer relationship management (CRM) system. Which of the following is the BEST way to identify threats to the CRM?
Easy390A vulnerability scan of the internal network reveals a critical vulnerability in a legacy application that cannot be patched immediately. What is the FIRST step the risk practitioner should take?
Easy391Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA) during the IT risk assessment process?
Easy392Which TWO of the following are examples of risk avoidance?
Medium393A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?
Medium394A risk practitioner is assessing the security of the organization's software development lifecycle (SDLC). The organization wants to integrate security controls to reduce the risk of introducing vulnerabilities into production. Which TWO of the following are the MOST effective preventive controls to implement during the development phase? (Choose two.)
Medium395You are the risk manager at a financial institution that processes online transactions. The organization relies on a legacy system for transaction authorization, which is monitored via manual log reviews performed weekly by a junior analyst. Recently, the internal audit team identified that several unauthorized transactions were not detected for over two weeks. The logs showed that the authorization control failed intermittently due to a known software bug, but the bug had been documented in the risk register with a low residual risk rating. The CRO asks you to recommend the most effective improvement to the control monitoring process. Which of the following would be the BEST course of action?
Easy396A risk practitioner is using the Delphi technique to estimate the likelihood of a sophisticated ransomware attack against a hospital network. The first round of expert opinions produced widely divergent estimates. Which of the following is the MOST appropriate next step in the Delphi process?
Hard397In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?
Easy398A risk practitioner is facilitating a risk assessment workshop for a new cloud-based HR system. The team is identifying threats. Which TWO of the following are examples of threat events that should be considered? (Choose two.)
Medium399During a risk assessment, an organization identifies that its primary data center is located in a flood-prone area. Which risk treatment option would best address this risk?
Medium400A risk practitioner is quantifying the potential loss from a ransomware scenario affecting a hospital's electronic health record (EHR) platform. Historical data shows an average of two disruptive malware incidents per year, a 30% probability that any single incident escalates to full EHR encryption, and an estimated $4,000,000 business impact when the EHR is unavailable for a full day. What is the annualized loss expectancy (ALE) for this scenario?
Hard401A multinational retailer's risk register shows a high inherent risk rating for its third-party payment processor. The processor has since obtained an independent SOC 2 Type II report with no exceptions, and the retailer's contract includes a right-to-audit clause. The risk owner proposes lowering the residual risk rating to low. Which factor is MOST important for the risk practitioner to consider before approving the revised rating?
Hard402A software development company is adopting a DevOps model and wants to accelerate deployments. The risk manager is concerned that rapid changes could introduce security vulnerabilities. The team proposes implementing automated security testing in the CI/CD pipeline. Which of the following BEST describes the risk response strategy being applied?
Medium403During a risk identification workshop, the team identifies several vulnerabilities. Which TWO of the following are examples of operational vulnerability identification? (Select two.)
Medium404In the NIST Cybersecurity Framework, which function is primarily focused on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Easy405A multinational e-commerce company has experienced multiple security incidents involving unauthorized access to customer payment data. The incidents originated from different regional offices and exploited misconfigured firewall rules. The risk manager needs to identify the root cause of these risks. Which approach would BEST help in identifying the root cause of the IT risk?
Medium406According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?
Easy407Which THREE of the following should be included in a board-level risk report to effectively communicate the organization's risk profile?
Hard408During a risk assessment, a financial institution identifies that its online banking application uses an outdated encryption protocol. The likelihood of exploitation is high, and the impact is moderate. What should the risk owner do FIRST?
Medium409A risk practitioner is conducting a risk assessment for a new customer-facing mobile application. The practitioner wants to identify risks by examining how data flows between the mobile client, the API gateway, and the backend database. Which of the following techniques is being applied?
Easy410Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?
Easy411Which of the following is a key element of promoting a risk-aware culture within an IT department?
Medium412A utility company's risk practitioner is defining the scope of a risk identification exercise for a new advanced metering infrastructure. The practitioner must decide which elements to include. Which action BEST ensures the identification exercise covers the full risk landscape?
Hard413A mid-sized hospital is building its IT risk register. The risk practitioner wants to express the organization's tolerance for a ransomware event that would disrupt electronic health records for 24 hours. Which of the following BEST represents a structured way to document this tolerance?
Medium414A financial services firm is deploying a new customer portal on a public cloud. The security team proposes using digital certificates to authenticate the portal to clients and sign sensitive transaction data. The risk manager must evaluate the residual risk after certificate deployment. Which of the following is the MOST significant residual risk related to the certificate lifecycle?
Medium415Which THREE of the following are characteristics of leading key risk indicators (KRIs)?
Medium416During a vendor risk assessment, a prospective vendor for critical services cannot provide a SOC 2 Type II report. According to the organization's vendor risk appetite, which action should be taken?
Medium417A new web application is being developed using several open-source libraries. Which risk identification method is most effective for identifying vulnerabilities in these libraries?
Medium418A SIEM generates alerts for the following events. Which TWO events should be considered potential emerging risks? (Select exactly 2.)
Easy419Based on the exhibit, which of the following poses the HIGHEST risk to the environment?
Hard420A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?
Hard421A risk manager is designing monthly risk reports for senior management. Which THREE of the following should be included in an effective risk report? (Choose three.)
Easy422In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?
Medium423A multinational corporation is migrating its customer relationship management (CRM) system to a public cloud provider. The data includes personally identifiable information (PII) from multiple jurisdictions. Which risk should be considered most critical during the cloud architecture review?
Hard424A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.
Medium425An organization's risk committee is reviewing key risk indicators (KRIs) for its customer-facing web applications. The KRI for average patch latency has breached its threshold for two consecutive quarters, yet the risk register still lists the associated risk as medium with no treatment plan. Which action should the risk practitioner recommend FIRST?
Hard426A retail company is establishing an IT risk universe. Which of the following should be included as a primary category of IT risk?
Easy427A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?
Hard428A company is implementing a new continuous monitoring tool for its network security controls. Which of the following is the MOST important step to ensure the tool provides meaningful risk information?
Medium429During a VAST threat modeling session for a DevSecOps pipeline, the team focuses on threats that align with agile development. Which of the following is a key advantage of VAST?
Hard430An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?
Medium431A risk manager discovers that a business unit has been using an unapproved software-as-a-service (SaaS) application for three months. The application stores customer PII. Which of the following risk identification techniques should the risk manager use to understand the full extent of the risk?
Hard432A financial services firm's risk register shows that a legacy payment gateway has a high inherent risk of SQL injection. The security team proposes deploying a web application firewall (WAF) in front of the gateway. The risk owner must document how this action will be classified in the risk response plan. Which risk response strategy does deploying the WAF represent?
Medium433Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?
Easy434A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?
Hard435Which TWO of the following are primary sources of risk identification for IT projects? (Select exactly 2.)
Easy436An IT risk manager is reviewing the risk register and finds that the same database server appears in three separate risk entries: one for unauthorized access, one for data corruption, and one for denial of service. What is the PRIMARY benefit of structuring the register this way rather than combining all three into a single entry?
Easy437During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?
Hard438Based on the exhibit, what is the primary risk to the organization?
Medium439A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?
Hard440Which THREE of the following are best practices for reporting risk and control monitoring results to stakeholders?
Hard441A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?
Medium442When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:
Hard443An organization's data classification policy labels customer payment records as confidential. A risk practitioner is reviewing how the data is protected at rest in a public cloud object storage bucket. Which control BEST ensures that a misconfigured bucket does not expose the data to unauthorized parties?
Easy444A risk practitioner at a healthcare insurer is identifying risks for a new telehealth platform. The platform integrates with a third-party video vendor, stores protected health information, and must comply with HIPAA. Which of the following is the MOST appropriate FIRST step in identifying IT risk for this platform?
Hard445An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?
Medium446A retail company uses a third-party vendor for payment processing. The vendor's service level agreement (SLA) requires 99.9% uptime. Recently, there were two incidents of downtime totaling 0.2% in a month, still within the SLA. However, the company's internal risk monitoring detected a pattern of increasing minor incidents. The vendor insists the SLA is met. The risk manager must decide on monitoring and reporting. The company's board wants to understand the risk. What is the best course of action?
Medium447A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?
Easy448During a vendor risk assessment, an organization discovers that a critical vendor has not performed a security assessment in two years. The vendor is tiered as 'medium risk'. According to best practices, what should the risk practitioner recommend?
Medium449An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?
Easy450Which TWO of the following are valid techniques for identifying risk in IT risk assessment?
Hard451A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?
Medium452A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:
Medium453An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?
Medium454A risk practitioner is performing risk identification for a manufacturing firm that relies on industrial control systems (ICS) to operate assembly lines. The practitioner is cataloging vulnerabilities that could be exploited to disrupt production. Which TWO of the following represent vulnerabilities rather than threats? (Choose two.)
Hard455A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?
Hard456An organization is implementing continuous monitoring for its critical systems. Which TWO of the following are examples of continuous monitoring techniques? (Select TWO)
Hard457Order the steps for change management in an IT environment.
Medium458The exhibit shows a control monitoring configuration in JSON format. Which of the following is the MOST critical gap in this monitoring setup?
Medium459Which TWO of the following are appropriate actions when a control deficiency is identified during monitoring? (Select exactly two.)
Medium460A small logistics company has no formal risk assessment process. The new IT manager wants to introduce a simple, repeatable method to identify and evaluate IT risks. Which action should the manager take FIRST?
Easy461An organization is implementing a new access control system. The project manager is concerned about delays due to user training requirements. Which of the following should the risk practitioner prioritize to ensure effective control implementation?
Medium462During a vendor risk tiering exercise, a vendor that stores the organization's customer PII and is critical for daily operations should be classified as which tier?
Hard463An organization maintains a risk register. Which of the following updates should be made on an ongoing basis?
Medium464A retail bank's risk practitioner is building a risk scenario for its online banking platform. He needs to estimate how frequently an attacker could realistically succeed in exploiting the platform's unpatched web tier. Which of the following provides the MOST quantitative basis for this estimate?
Medium465A retail company recently deployed a point-of-sale (POS) system that processes credit card transactions. The system is connected to the corporate network and transmits transaction data to a payment processor over the internet. During a risk assessment, the IT risk manager identifies that the POS system is vulnerable to malware injection via unvalidated input from barcode scanners. Which of the following is the MOST appropriate risk mitigation strategy?
Medium466Match each control type to its example.
Medium467A risk practitioner is helping a mid-sized healthcare organization update its IT risk register after migrating patient scheduling to a SaaS platform. The vendor's SOC 2 Type II report shows no exceptions, but the contract omits breach notification timelines and data deletion commitments. Which action BEST addresses the residual risk?
Medium468In the FAIR framework, which of the following correctly represents the calculation of Loss Event Frequency (LEF)?
Hard469Which type of control is designed to stop an undesirable event from occurring?
Easy470A risk practitioner is assessing the security of an organization's software development lifecycle (SDLC). The organization wants to integrate security early to reduce the cost and impact of fixing vulnerabilities. Which TWO of the following practices are MOST effective for achieving this goal? (Choose two.)
Medium471In the context of IT risk reporting to the board, which THREE elements should be included to effectively communicate risk?
Hard472A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?
Medium473A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?
Medium474A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?
Medium475A company's control monitoring shows that a detective control has been 100% effective for the past year. However, a recent incident revealed that a data breach went undetected for three months. What is the MOST likely cause?
Hard476Which TWO of the following are characteristics of quantitative risk analysis compared to qualitative risk analysis? (Select 2)
Hard477An organization uses a KRI that tracks the average time to patch critical vulnerabilities. The metric has been increasing over the past three months. What does this indicate from a risk perspective?
Hard478When performing a risk assessment, which TWO of the following are components of inherent risk?
Easy479During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?
Medium480A financial services firm is completing its annual IT risk assessment. The CISO wants to compare the relative severity of 40 identified risks across different business units and prioritize which ones to treat first. The risk team has limited quantitative data and needs a consistent, repeatable method that reflects both likelihood and impact. Which approach BEST meets this need?
Hard481A manufacturing company uses an industrial control system (ICS) that is connected to the corporate network for monitoring. The risk manager is identifying risks related to this connectivity. Which of the following is the MOST significant risk?
Easy482A risk practitioner is designing an IT risk management programme. Which of the following is the BEST sequence of components to establish?
Medium483An organization has implemented a new key risk indicator (KRI) for vendor management that measures the percentage of vendors without a signed contract. The current value is 15%, exceeding the risk appetite threshold of 10%. The risk owner wants to know the most appropriate action to take based on this KRI. What should the risk practitioner recommend?
Medium484Match each risk response strategy to its definition.
Medium485A retail company is assessing the risk of a point-of-sale (POS) system compromise. The risk team estimates that a successful attack would cost $500,000 in fines, remediation, and lost sales. The likelihood of such an attack in the next year is estimated at 20%. What is the annualized loss expectancy (ALE) for this risk scenario?
Easy486During risk identification, a risk manager is reviewing threat intelligence sources. Which THREE of the following are considered legitimate sources of threat intelligence? (Choose three.)
Hard487A risk officer is evaluating the effectiveness of a control that prevents unauthorized changes to configuration files. The control has not detected any unauthorized changes in the past year. What does this indicate?
Medium488A risk practitioner is analyzing the results of a phishing simulation. The simulation had a 15% click rate on a test email targeting finance department staff. Which of the following conclusions is MOST valid regarding IT risk identification?
Hard489A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of its electronic health record (EHR) system. The practitioner wants to express the risk in a way that supports later quantification and treatment decisions. Which of the following BEST describes how the risk should be documented in the register?
Medium490During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?
Hard491Which THREE of the following are effective risk identification techniques for a cloud migration project? (Select exactly THREE.)
Hard492An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?
Easy493A risk practitioner is assessing a new e-commerce platform. The business owner insists that the platform must be available 24/7. The practitioner identifies that a distributed denial-of-service (DDoS) attack could cause an outage. Which of the following BEST describes the risk scenario?
Hard494A risk practitioner is using the ISACA risk scenario development approach to articulate a risk related to a third-party payment processor. The practitioner wants to ensure the scenario includes all key components. Which of the following components is MOST critical to include to enable effective risk analysis and treatment?
Hard495A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?
Medium496An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?
Medium497Which TWO methods are commonly used for continuous monitoring of IT controls?
Medium498An organization uses control self-assessments (CSAs) as part of its monitoring program. The results from the latest CSA show that the majority of controls are rated as effective, but an internal audit reveals several control failures in those same areas. What is the MOST likely reason for this discrepancy?
Easy499A company is updating its risk register. Which of the following is the primary purpose of a risk register?
Medium500A company's risk management team is evaluating the effectiveness of its control monitoring program. They find that many controls are tested at the same time each year, leading to a resource bottleneck. Which of the following approaches would BEST address this issue?
Hard501During a quantitative risk analysis, the risk practitioner determines that the single loss expectancy (SLE) for a ransomware attack is $500,000 and the annualized rate of occurrence (ARO) is 0.4. The organization has a risk appetite that accepts annual losses up to $150,000. What is the recommended action?
Hard502After a risk assessment, the risk owner decides to mitigate a high-risk finding by implementing additional access controls. What should the risk manager do NEXT?
Medium503A company's risk assessment identifies that a threat actor has high capability and motivation to exploit a vulnerability. Which factor does this relate to?
Medium504A multinational corporation is conducting a risk assessment for its new online payment platform. The platform processes transactions in multiple currencies and stores sensitive customer financial data. The risk team has identified that the encryption algorithm used for data at rest is outdated and could be vulnerable to advanced attacks. The company's risk appetite is low for data breaches. The security team recommends upgrading the encryption to a modern standard, but the upgrade will require a 48-hour downtime impacting all global transactions. The business unit is concerned about revenue loss during the downtime. As the risk practitioner, what is the BEST course of action to balance security and business continuity?
Easy505A risk manager is assessing the risk of a distributed denial-of-service (DDoS) attack on a critical online service. The service has a service-level agreement (SLA) that requires 99.9% uptime. The manager has identified that the likelihood of a DDoS attack is high, but the impact is considered low because the service can fail over to a backup data center. Which of the following should the risk manager do NEXT?
Hard506Refer to the exhibit. Based on the KRI data for the current week, what action should the risk manager take FIRST?
Easy507During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
Medium508Order the steps for incident response handling.
Medium509A multinational bank is assessing risk for a new mobile banking feature that stores limited customer data on devices. The risk team must decide whether to use a qualitative or quantitative approach. Which of the following is the MOST important factor in making this decision?
Hard510A financial services company is conducting a risk assessment for a new mobile banking application. The risk team identifies that the application will store sensitive customer data on the device. The team must determine the appropriate risk response. The CISO suggests implementing encryption and tokenization to protect the data. The business sponsor argues that these controls will delay the launch and increase costs. The risk owner must decide how to proceed. Which of the following is the MOST appropriate action for the risk owner to take?
Hard511After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?
Medium512Which of the following is a detective control for an information system?
Easy513An organization is implementing the NIST Cybersecurity Framework to manage cyber risk. The risk manager is mapping the 'Detect' function to existing risk management processes. Which of the following activities is MOST directly aligned with the 'Detect' function?
Medium514An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?
Hard515A risk manager is evaluating the risk associated with a new third-party vendor that will have access to customer data. The vendor has been in business for 10 years and holds ISO 27001 certification. Which factor should be given the MOST weight when determining the vendor's risk level?
Medium516An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?
Medium517Which risk assessment method uses a matrix to plot likelihood and impact to determine risk level?
Easy518An organization uses a third-party vendor for payment processing. The vendor's latest SOC 2 report shows a significant control exception in logical access. What is the BEST way to monitor the effectiveness of the compensating controls the vendor has implemented?
Medium519An organization is implementing a control to prevent unauthorized access to its critical database. The control must be designed to block access attempts in real time. Which type of control should be selected?
Medium520A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?
Hard521Which TWO of the following are appropriate criteria for selecting key risk indicators (KRIs)?
Medium522A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?
Easy523Arrange the steps for performing a vulnerability assessment.
Medium524A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?
Medium525Which TWO of the following are key functions of an Architecture Review Board (ARB) in managing risk?
Easy526When identifying vulnerabilities, which of the following is the BEST source for configuration-related vulnerabilities in operating systems?
Medium527A risk practitioner at a software company is reviewing external sources to identify emerging IT risks that could affect the organization's cloud-hosted products. The practitioner wants to use sources that provide structured, timely information about newly disclosed software weaknesses. Which TWO of the following sources BEST meet this need? (Choose two.)
Medium528A multinational corporation is deploying a new enterprise resource planning (ERP) system across 30 countries. The risk manager identifies that data residency laws in several countries require customer data to remain within national borders. The project team proposes using a single global cloud region for simplicity. Which risk response strategy is MOST appropriate for the risk manager to recommend?
Hard529The policy requiring TLS 1.2 or higher for all data transmissions is intended to enforce what security control?
Hard530Which of the following is the PRIMARY purpose of a risk register?
Easy531A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?
Easy532Based on the exhibit, what control monitoring deficiency is evident in the DLP policy?
Hard533An organization is updating its asset inventory to improve IT risk identification. Which of the following asset attributes is MOST critical for assessing cybersecurity risk?
Easy534A retail company has a risk register that includes a risk of inventory shrinkage due to employee theft. The risk manager decides to implement a new surveillance system and conduct background checks on all new hires. Which risk response strategy is being applied?
Easy535A software development team is adopting Agile methodology and wants to integrate risk identification into their sprints. Which approach BEST aligns with Agile principles while ensuring effective risk identification?
Hard536A large enterprise uses a risk matrix with impact categories (very low, low, medium, high, very high) and likelihood (rare, unlikely, possible, likely, almost certain). A risk identified has a 'likely' likelihood and 'high' impact. According to the matrix, risks with this combination are classified as 'high' risk. The risk appetite statement requires that all high risks have a response plan within 30 days. However, the risk owner argues that due to effective compensating controls, the residual risk is only 'medium'. Which of the following is the BEST course of action?
Hard537Which of the following is the BEST indicator that a risk assessment should be performed outside the normal cycle?
Easy538A risk manager is designing a monitoring and reporting framework. Which THREE of the following are essential components of an effective risk and control monitoring program?
Easy539An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?
Medium540An organization is deploying IoT sensors in a manufacturing plant. Which of the following is the MOST significant security risk associated with these devices?
Medium541An organization has implemented a firewall (preventive), intrusion detection system (detective), and a backup restoration plan (corrective) to address a specific risk. The risk manager assesses the control effectiveness as follows: design adequacy is strong, but operating effectiveness is weak due to inconsistent patching. Which of the following best describes the residual risk?
Hard542During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?
Medium543A financial services company's risk register shows that a critical vulnerability in its online banking application has a high likelihood of exploitation and a high impact. The risk owner decides to implement a web application firewall (WAF) and conduct monthly penetration tests. Which risk response strategy is being applied?
Medium544A manufacturing company is integrating its industrial control systems (ICS) with the corporate IT network to enable real-time data analytics. Which of the following represents the MOST significant risk introduced by this convergence?
Hard545Which risk treatment option involves purchasing cyber insurance?
Easy546Which threat actor is most likely motivated by political ideology and may target government systems?
Easy547A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?
Easy548A risk practitioner at a regional bank is compiling a list of internal threat sources for the enterprise risk assessment. Which TWO of the following are internal threat sources that should be included? (Choose two.)
Medium549An organization is selecting a control to reduce the risk of unauthorized data exfiltration. The annual loss expectancy (ALE) for this risk is currently $500,000. The proposed control costs $80,000 annually and is expected to reduce the ALE by 60%. What is the net benefit (reduction in risk exposure minus control cost) of implementing this control?
Medium550Which TWO of the following are types of insider threats?
Easy551Which of the following is a Key Risk Indicator (KRI) that provides leading indication of increasing vulnerability risk?
Easy552After implementing a set of controls, the risk owner calculates the residual risk. Which of the following is true about residual risk?
Medium553Which THREE of the following are key components of a risk assessment report?
Medium554Which TWO of the following are examples of risk avoidance? (Select TWO.)
Medium555A company is evaluating the cost-benefit of a new control that reduces the annualized loss expectancy (ALE) from $500,000 to $100,000. The control has an annual cost of $150,000. What is the net benefit of implementing this control?
Medium556A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:
Medium557A company has implemented a key risk indicator (KRI) for system availability, with a threshold of 99.5%. The monitoring team observes that availability has dropped to 99.2% for two consecutive months. What is the most appropriate next step?
Medium558A risk practitioner has completed a quantitative risk analysis for a customer-facing payment platform. The analysis shows an inherent annualized loss expectancy (ALE) of $2.4 million. Management wants to fund a tokenization control that reduces the ALE to $600,000, but the control costs $1.9 million per year to operate. Which action should the risk practitioner recommend?
Medium559A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?
Easy560An organization decides to outsource its data center operations to a third party. This is an example of which risk response?
Easy561A risk practitioner at a regional bank is building a threat landscape for its new mobile payment platform. A recently published report from a national CERT indicates that a loosely organized group has been targeting payment APIs across the region, exploiting known authentication weaknesses. The practitioner wants to determine whether this group should be treated as a relevant threat source in the risk register. Which of the following is the MOST appropriate FIRST step?
Medium562An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?
Easy563An organization is designing a risk and control monitoring program for a new cloud-based application. Which of the following is the MOST important factor to consider when selecting Key Risk Indicators (KRIs)?
Medium564An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?
Medium565A risk practitioner is reviewing the organization's risk response plan for a database containing personally identifiable information (PII). The plan states that the database will be encrypted at rest, access will be restricted to authorized personnel, and regular backups will be performed. Which risk response strategy is being applied?
Easy566An organization is evaluating a new security control that costs $50,000 annually to implement and maintain. The current annualized loss expectancy (ALE) for a related risk is $200,000. The control is expected to reduce the ALE by 85%. Using cost-benefit analysis, what is the net benefit of implementing this control?
Medium567A multinational manufacturer has completed a quantitative risk analysis for a ransomware scenario affecting its primary ERP system. The analysis shows an annualized loss expectancy (ALE) of $2.4 million. A proposed endpoint detection and response (EDR) solution would cost $600,000 annually and is projected to reduce the ALE by 60%. The CFO asks the risk practitioner to justify the investment. Which of the following is the BEST response?
Hard568An organization's risk register shows that a critical database containing customer records has a high inherent risk rating. Management installs database activity monitoring, enforces encryption at rest, and implements quarterly access reviews. After these actions, the risk is re-rated as medium. Which risk concept does the re-rated medium value BEST represent?
Easy569A logistics firm relies on a third-party cloud provider to host its shipment tracking system. The provider's latest SOC 2 report includes a qualified opinion noting that access review controls were not operating effectively during part of the audit period. The firm's risk practitioner must determine the appropriate risk response. Which of the following is the MOST appropriate action?
Medium570You are the IT risk manager for a mid-sized e-commerce company. The company processes credit card payments and stores customer data. Recently, the company experienced a security incident where an attacker exploited a SQL injection vulnerability in the web application, exfiltrating a database of customer records. The vulnerability was introduced three months ago during a feature upgrade. The development team claims they followed secure coding guidelines, but the vulnerability was missed due to insufficient testing. The company's risk appetite is moderate, and they have a risk management policy that requires risks to be treated within 30 days of identification. The CISO wants to know the most effective way to reduce the likelihood of similar incidents. You have assessed that the current risk score for web application vulnerabilities is 16 (High). The company has a bug bounty program, but it has not been effective. Which of the following courses of action would BEST address the root cause and reduce the risk?
Hard571A multinational corporation is migrating critical applications to a public cloud provider. The IT risk manager needs to design a risk assessment approach that addresses shared responsibility. Which of the following is the MOST appropriate approach?
Hard572A risk practitioner is reviewing the organization's risk register and notices that a risk related to outdated encryption protocols on a file server has been assigned an owner. According to CRISC principles, what is the PRIMARY responsibility of the risk owner?
Easy573Which TWO outcomes indicate that a risk assessment process is effective?
Easy574An enterprise risk analyst is aggregating risk data from three business units that each used a different likelihood scale: Unit A used a 1-3 scale, Unit B used a 1-5 scale, and Unit C used a 1-10 scale. Before consolidating results into the enterprise risk register, which action BEST ensures the aggregated risk ratings remain meaningful for management reporting?
Medium575Which control type is primarily focused on identifying that a risk event has occurred?
Medium576A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts from the Asia-Pacific region has dropped significantly over the past week. Upon investigation, the log source status shows that 30% of the devices in that region have not sent any logs in 48 hours. What is the MOST likely cause?
Hard577Which TWO of the following are valid triggers for initiating a risk assessment outside the regular cycle? (Select 2)
Medium578During a risk assessment, the risk practitioner discovers that a critical database does not have an active failover solution. The database is used by multiple business applications. Which of the following factors should be given the HIGHEST weight when determining the inherent risk level?
Medium579A risk practitioner is evaluating the organization's identity and access management (IAM) controls as part of an IT risk assessment. The organization has a hybrid environment with on-premises Active Directory and a cloud identity provider. Which TWO of the following are the MOST significant risks that should be prioritized? (Choose two.)
Medium580An organization wants to promote a risk-aware culture. Which TWO of the following initiatives are most effective for achieving this?
Easy581A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?
Medium582Which of the following threat actors is MOST likely to be motivated by ideology rather than financial gain?
Easy583A quantitative risk analysis for a data breach yields an Annualized Loss Expectancy (ALE) of $500,000. The Single Loss Expectancy (SLE) is $100,000. What is the Annualized Rate of Occurrence (ARO)?
Medium584A risk practitioner is identifying risks associated with a new cloud-based customer relationship management (CRM) system. The organization has concerns about data leakage and service availability. Which TWO of the following are examples of vulnerabilities that could lead to these risks? (Choose two.)
Medium585A company uses cyber insurance to cover losses from data breaches. This is an example of which risk treatment?
Hard586An e-commerce company discovers that a third-party payment processor suffered a breach exposing customer card data. The processor contract includes a clause requiring the vendor to indemnify the company for breach-related costs. The risk owner updates the register to show that financial loss from this vendor risk is now borne by the processor. Which risk response strategy has been applied?
Easy587A financial services firm has identified that its primary data center is located in a region prone to hurricanes. The risk manager proposes purchasing business interruption insurance to cover potential losses from a catastrophic event. Which risk response strategy does this represent?
Medium588A software company has a risk appetite statement allowing no more than two hours of downtime per quarter for its customer-facing API. During a quarterly review, the risk practitioner discovers that a single unplanned database failover event caused 90 minutes of downtime, and a separate configuration error caused 45 minutes. Both events were resolved, but no root cause analysis was completed for either. Which of the following should the risk practitioner recommend FIRST?
Hard589A risk manager is reviewing the organization's risk treatment plan for a critical web application. The plan includes implementing a web application firewall (WAF), conducting regular penetration tests, and purchasing cyber insurance. The risk manager notes that the residual risk after these treatments is still above the risk appetite. According to CRISC, what should the risk manager do NEXT?
Hard590Which TWO risk identification techniques are most appropriate for identifying emerging risks from new technologies?
Hard591A risk practitioner is performing a risk assessment on an organization's use of a cloud-based payroll platform. The practitioner is identifying the inherent risk factors that exist before any controls are considered. Which TWO of the following are inherent risk factors for this scenario? (Choose two.)
Hard592A risk manager is documenting the results of an IT risk assessment. She has identified the risk, analyzed its likelihood and impact, and evaluated existing controls. Which of the following should she do NEXT?
Easy593After a security incident, an organization discovers that a critical database was accessed by an unauthorized user due to weak authentication controls. As part of the IT risk assessment process, which step should have identified this vulnerability?
Medium594A risk practitioner is selecting a risk analysis technique for a new mobile banking feature. The team has limited historical loss data, the feature involves several interconnected components, and stakeholders disagree about how failures propagate between them. Management wants a technique that structures expert judgment about causal pathways and produces a visual model of how component failures combine to cause the top-level loss event. Which technique BEST meets these requirements?
Hard595A company's risk management policy requires a risk register to be maintained. Which of the following is the primary purpose of a risk register?
Medium596An organization is implementing a new data loss prevention (DLP) solution. The risk manager is identifying potential risks related to the DLP solution itself. Which of the following is a risk that should be considered?
Easy597A company uses a DevOps approach with a continuous integration/continuous deployment (CI/CD) pipeline. Which risk identification technique is best suited for detecting code vulnerabilities early in the development lifecycle?
Medium598During a risk assessment of a web application, the risk owner identifies that the application uses outdated encryption algorithms. What is the most appropriate next step?
Easy599A risk analyst is evaluating the effectiveness of the organization's existing control environment for a newly identified risk involving unauthorized access to a human resources database. Which TWO of the following activities would BEST help the analyst determine whether the current controls reduce the risk to an acceptable level? (Choose two.)
Medium600A global manufacturer is performing an IT risk assessment for its industrial control systems (ICS). The risk team is evaluating threat sources and wants to identify factors that INCREASE the likelihood of a threat event occurring. Which TWO of the following factors increase the likelihood of a threat event? (Choose two.)
Hard601An organization is implementing a quantitative risk assessment for its customer database. Which TWO elements are essential for calculating the annualized loss expectancy (ALE)?
Hard602An organization has a risk culture where employees are hesitant to report security incidents due to fear of blame. Which of the following initiatives would MOST effectively promote a risk-aware culture?
Hard603A financial services firm has completed its annual IT risk assessment. The chief risk officer asks the IT risk analyst to classify each identified risk according to the organization's risk taxonomy before any response decisions are made. Which activity should the analyst perform FIRST?
Medium604A company is identifying risks associated with a new cloud-based CRM. Which of the following is the MOST effective method for identifying potential threats?
Easy605Which standard is specifically designed for industrial automation and control systems security and provides a framework for addressing security in IACS?
Medium606A risk analyst has completed a control self-assessment and found that a key preventive control failed testing in two consecutive quarters. The risk owner asks the analyst to update the risk register. Which action BEST reflects an appropriate risk response?
Easy607An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?
Medium608A risk assessment team is calculating the Annual Loss Expectancy (ALE) for a critical server. The Single Loss Expectancy (SLE) is $50,000 and the Annual Rate of Occurrence (ARO) is estimated to be 2. The team is considering implementing a new backup solution costing $40,000 per year. Which TWO of the following statements are true regarding the cost-benefit analysis? (Select TWO.)
Hard609A retail company is assessing risk for a new customer loyalty application. The risk team determines that the inherent risk is high, then evaluates existing controls and finds that the residual risk is within the organization's risk appetite. The CIO asks what the residual risk rating represents. Which statement BEST describes residual risk in this context?
Medium610A risk practitioner at a healthcare insurance company is building the risk register entry for ransomware affecting its claims-processing platform. The practitioner must document the loss event type, the asset at risk, and the expected loss magnitude in the organization's risk taxonomy. Which of the following BEST describes the risk component that represents the expected loss magnitude?
Medium611A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?
Medium612Which TWO of the following are primary factors that determine how often a risk assessment should be performed?
Medium613A healthcare organization is subject to strict regulatory requirements regarding patient data privacy. The organization has a control that requires all access to patient records to be logged and reviewed weekly by the compliance team. The review is currently performed manually by sampling 10% of the logs. The compliance team reports that the review takes 20 hours per week and they are often unable to complete it on time. As a result, some suspicious access patterns are detected weeks after they occur. The risk manager needs to propose an improvement to the monitoring process. The organization's risk appetite for undetected unauthorized access is very low. Which of the following is the MOST effective recommendation?
Medium614A large e-commerce company uses several key risk indicators (KRIs) to monitor credit card fraud. The risk committee noticed that one KRI has been trending above the threshold for three consecutive months, yet no risk response was initiated. Which of the following is the MOST likely root cause?
Medium615A risk assessment team is evaluating the effectiveness of existing controls for a critical application. Which of the following approaches best determines whether controls are operating as intended?
Medium616An organization is reviewing its enterprise architecture to identify risks. In which IT architecture layer would a risk related to data classification and data sovereignty be primarily addressed?
Hard617Which of the following best describes the purpose of a risk heat map in an IT risk report?
Easy618Sequence the steps for implementing a new control based on risk assessment findings.
Medium619A hospital's risk practitioner is assessing a new telehealth platform that stores protected health information. During risk identification, she maps threats to the platform. Which of the following BEST illustrates a threat to this platform rather than a vulnerability or a control weakness?
Hard620A company uses a third-party SaaS application for payroll processing. What is the most important activity to identify IT risks associated with this service?
Easy621A financial services firm has completed a risk assessment and determined that the residual risk for its online banking platform exceeds the board-approved risk appetite. The CISO must recommend risk response options to the risk committee. Which TWO of the following are appropriate risk response actions? (Choose two.)
Hard622A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?
Hard623Which of the following is a key component of the NIST Cybersecurity Framework's 'Identify' function?
Easy624A company is adopting a DevSecOps approach and wants to conduct threat modeling early in the development lifecycle. Which threat modeling methodology is BEST suited for this environment due to its focus on agile and continuous integration?
Medium625After a control self-assessment (CSA) workshop, business units reported that 80% of controls are operating effectively. However, internal audit's recent testing indicates a 30% control failure rate. What is the BEST explanation for this discrepancy?
Hard626An organization uses a third-party vendor for critical data processing. The vendor has experienced two minor security incidents in the past year with no data loss. The risk manager is updating the vendor risk assessment. Which approach best aligns with ISACA's guidance?
Hard627An organization is implementing a bring your own device (BYOD) program. The risk practitioner is asked to identify the control that BEST reduces the risk of data leakage from lost or stolen mobile devices.
Easy628An organization has recently suffered a ransomware attack that encrypted critical files. During the post-incident review, the risk team is identifying key risk indicators (KRIs) to improve early detection. Which of the following KRIs would be MOST effective in detecting similar attacks in the future?
Hard629Which THREE of the following are indicators of potential IT risk in an organization? (Select exactly THREE.)
Easy630A risk practitioner is mapping identified IT risks to the organization's risk taxonomy. A risk has been logged for 'unauthorized access to the HR system resulting from excessive user privileges.' Under which risk category should this be classified?
Hard631A global organization is consolidating risk data from multiple business units into a single enterprise risk management (ERM) system. The risk practitioner notices that KRIs for the same risk type (e.g., cybersecurity) are calculated differently across units. What is the BEST approach to ensure consistent and reliable risk monitoring and reporting?
Hard632During a risk assessment, the risk manager identifies a vulnerability in a web application that could allow SQL injection. The development team states they will fix it in the next release, which is six months away. What should the risk manager do?
Easy633A retail bank is documenting its risk appetite for IT risk. The board states that the bank will accept only minimal risk of unauthorized disclosure of customer payment data, but is willing to accept moderate availability risk in internal reporting systems. A risk practitioner is asked to translate this statement into operational terms. Which action BEST reflects establishing risk tolerance in this context?
Easy634A risk assessment report includes both inherent and residual risk ratings. The inherent risk for a process is rated as 'high' based on a 5×5 heat map. After applying a set of controls, the residual risk is rated as 'medium'. What does this indicate about the control effectiveness?
Medium635A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?
Hard636An organization is implementing a new cloud-based CRM system. The risk manager is reviewing the solution architecture for security risks. Which architectural layer should be evaluated to ensure data encryption at rest and in transit?
Medium637Which THREE of the following are common consequences in an IT risk scenario?
Medium638A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)
Medium639A risk practitioner is identifying external threats to a retail bank's online transaction platform. The bank wants to understand threats that originate from outside the organization and target customer accounts. Which TWO of the following are external threats relevant to this scenario? (Choose two.)
Hard640An architecture review board (ARB) is evaluating a new solution architecture that processes sensitive data. Which of the following should the ARB review to ensure security risks are addressed before implementation?
Medium641A company is prioritizing risk treatment actions. Which THREE factors should be considered when prioritizing risks?
Medium642When implementing a new access control system, which activity is essential during the change management process?
Easy643Which THREE of the following are key components of an effective risk reporting framework?
Hard644A financial institution is considering adopting a new AI/ML model for credit scoring. The model uses customer demographic data and transaction history. Which of the following risks is MOST likely to cause regulatory penalties if not addressed?
Medium645Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?
Hard646A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?
Easy647A credit union's risk committee has approved a risk response for its core banking platform: purchase an insurance policy against ransomware losses and keep the current backup process unchanged. Six months later, a ransomware event encrypts production data and the backup restoration takes four days, breaching regulatory reporting deadlines. Which risk response did the risk committee most likely select, and why did it fail to address the operational impact?
Medium648A large e-commerce company is assessing the risk of a distributed denial-of-service (DDoS) attack on its web applications. The company has experienced three DDoS attacks in the past year, each causing significant downtime and revenue loss. The current mitigation strategy relies on an on-premise appliance that can handle up to 10 Gbps of attack traffic. Recent industry reports indicate that DDoS attacks are growing in volume and sophistication, with some exceeding 100 Gbps. The company's risk appetite for availability is moderate. The security team has proposed migrating to a cloud-based DDoS protection service that scales to 200 Gbps, but it will increase annual operational costs by 40%. The business is concerned about the cost increase. Which of the following is the BEST risk treatment decision?
Hard649A company has identified a risk of data breach due to weak encryption. The current controls include encryption at rest but not in transit. The risk assessment team calculates inherent risk as high and residual risk as high. What should the team recommend FIRST?
Medium650An organization recently experienced a significant security incident that was not detected by existing monitoring controls. The risk team is reviewing the effectiveness of the control monitoring framework. Which THREE of the following are key factors that should be evaluated to improve detection capabilities?
Medium651An organization is evaluating whether to accept a risk. Which TWO conditions must be met for risk acceptance to be appropriate?
Medium652A risk practitioner at a healthcare payer is reviewing the organization's disaster recovery (DR) strategy for its core claims adjudication system. The business owner has stated that the maximum tolerable downtime is 4 hours, but the current DR plan relies on restoring from nightly tape backups, which would take at least 30 hours. Which of the following is the MOST appropriate action for the risk practitioner to take FIRST?
Medium653A retail company's risk practitioner is reviewing how risks flow between the enterprise risk management function and the IT risk function. The CISO argues that IT risks should be reported only within IT, while the CRO wants material IT risks elevated to the enterprise register. Which CRISC principle BEST resolves this disagreement?
Medium654Put the steps for developing an information security policy in order.
Medium655A hospital network is selecting key risk indicators (KRIs) for its electronic health record (EHR) availability risk. The risk committee wants indicators that will provide early warning before an outage affects patient care. Which TWO of the following are the most appropriate KRIs for this purpose? (Choose two.)
Medium656A risk manager is evaluating IoT device risks for a smart building project. Which TWO of the following are significant IoT security risks?
Medium657A large bank has implemented a sophisticated risk and control monitoring system with multiple dashboards and automated reporting for key risk indicators (KRIs). However, the board of directors has been receiving conflicting KRI reports from different business units (e.g., retail banking, corporate lending, and wealth management). For example, the fraud KRI shows a high risk in retail but low risk in wealth management, yet both units use the same underlying data source. The chief risk officer (CRO) is concerned that the board is losing confidence in the risk reporting. An investigation reveals that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. What is the most likely root cause and the best remediation?
Hard658Which of the following is an example of a leading Key Risk Indicator (KRI) for IT risk?
Medium659An organization wants to promote a risk-aware culture. Which initiative is most effective in encouraging employees to report security incidents without fear?
Hard660A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)
Medium661A risk practitioner is connecting a risk scenario to business impact. The scenario involves a ransomware attack that encrypts critical financial systems, resulting in a two-week outage. Which of the following is the MOST appropriate business impact category?
Hard662An organization is planning to adopt post-quantum cryptography. Which TWO considerations are MOST important for migration planning?
Medium663A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?
Hard664A financial services firm is conducting an IT risk assessment for its customer-facing mobile banking application. The risk team has identified that the application's authentication mechanism relies on a third-party single sign-on (SSO) provider. During a workshop, the risk owner states that the likelihood of a breach is low because the SSO provider has a strong security reputation. However, the risk team notes that no service-level agreement (SLA) exists with the provider. Which risk factor is MOST directly affected by the absence of an SLA, and how should the risk practitioner proceed?
Medium665A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:
Hard666A newly hired risk analyst is asked to classify the organization's risk universe before any assessment begins. The analyst lists categories such as strategic, operational, financial, compliance, and reputational. Which of the following BEST explains why this categorization is useful for IT risk identification?
Easy667An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?
Medium668An organization's risk committee is reviewing a consolidated IT risk report before a board meeting. The report shows that a critical payment system has a residual risk rating above tolerance, but the remediation project is not scheduled to complete for nine months due to vendor dependencies. The committee must decide how to report this to the board. Which of the following is the MOST appropriate action?
Hard669A multinational corporation has a risk register entry for a supplier that provides critical components. The supplier has a history of financial instability, and the risk of supply chain disruption is high. The risk owner decides to dual-source the components from a second supplier. Which risk response strategy does this represent, and what is the primary benefit?
Hard670An energy utility is assessing risk to its industrial control system (ICS) network. The risk analyst discovers that the same risk scenario is rated as high risk by the operations team using a qualitative heat map and as low risk by the enterprise risk team using a quantitative model. Both teams used the same underlying data. Which of the following is the MOST likely explanation for the discrepancy?
Hard671In a quantitative risk analysis using FAIR, which of the following best represents Loss Magnitude (LM)?
Medium672Which of the following is the primary purpose of a risk and control monitoring program?
Easy673An Architecture Review Board (ARB) is evaluating a new solution architecture for a customer-facing web application. Which of the following is the PRIMARY risk the ARB should consider?
Medium674For a risk with very low likelihood and low impact, what is the typical risk response?
Easy675An organization is considering cyber insurance to transfer residual risk. Which factor would MOST significantly influence the premium?
Medium676A company is considering outsourcing its data center operations to a cloud provider. Which risk treatment option is the company primarily exercising?
Medium677Refer to the exhibit. Based on the exhibit, what is the most appropriate action regarding the control OWF?
Hard678A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?
Medium679An organization decides to discontinue a high-risk business process that cannot be effectively mitigated. This is an example of which risk treatment option?
Easy680In the context of threat modeling for a web application, which technique is specifically designed to be integrated into Agile and DevSecOps processes, emphasizing collaboration and visualization?
Hard681A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?
Hard682During a risk assessment, the risk practitioner develops a scenario involving a disgruntled employee exfiltrating sensitive customer data through a USB drive. The organization has a strict policy against removable media but lacks technical controls to prevent USB usage. Which element of the risk scenario is the vulnerability?
Hard683Which of the following best describes risk capacity?
Easy684What is the primary purpose of a control self-assessment (CSA)?
Easy685Which of the following is a key characteristic of a well-maintained risk register?
Easy686A security awareness program is being designed to promote a risk-aware culture. Which TWO elements are most critical for the program's success?
Medium687A risk analyst uses a 5x5 heat map to evaluate a set of IT risks. For a particular risk, the likelihood is rated as 4 (likely) and impact as 5 (very high). What is the resulting risk rating?
Medium688In the context of ERM integration, IT risk is typically considered a subset of which broader risk category?
Medium689During a risk assessment, a risk practitioner identifies that a legacy application uses a deprecated encryption protocol. The application is critical for business operations and cannot be patched. Which of the following is the BEST approach to assess the risk?
Medium690A retail bank's risk practitioner is assessing the risk that a core banking system outage could halt transaction processing. The practitioner wants to identify the specific conditions or characteristics of the environment that could allow the outage to occur or worsen its effect, rather than the events themselves. Which of the following is the practitioner identifying?
Hard691A retail company monitors its key risk indicator (KRI) for credit card transaction fraud. The KRI has exceeded the established threshold for three consecutive days, but the weekly control performance report shows all fraud detection controls operating effectively. What should the risk practitioner do FIRST?
Medium692A risk practitioner is assessing the risk of a legacy application that supports a critical business process. The application vendor no longer provides security patches. The business cannot replace the application within the next 12 months due to budget constraints. Which of the following is the MOST appropriate risk treatment?
Hard693A risk practitioner is using the TRIKE threat modeling methodology. Which TWO of the following are characteristics of TRIKE?
Hard694You are the IT risk manager at a multinational corporation that recently migrated its customer database to a cloud-based platform. The database contains personally identifiable information (PII) subject to GDPR. During a routine vulnerability scan, you discover that the database is accessible from the internet without encryption (port 1433 open). The cloud provider's shared responsibility model indicates that securing the database configuration is the customer's responsibility. You have identified the risk as high likelihood and high impact. The business owner argues that the database is only accessible to a limited IP range and that encryption would degrade performance. Which course of action should you recommend to treat the risk?
Medium695A vendor risk manager is tiering vendors based on the criticality of services and data access. A vendor that processes sensitive customer data for a core business application should be classified as which tier?
Medium696A risk practitioner is creating a risk scenario for a ransomware attack. Which of the following is the BEST sequence to describe the scenario using the ISACA risk scenarios template?
Medium697A financial institution is evaluating the risk of a new mobile payment application. The risk team calculates the Annual Loss Expectancy (ALE) as $500,000 based on a single loss expectancy (SLE) of $100,000 and an annual rate of occurrence (ARO) of 5. After implementing a new encryption control at a cost of $150,000 per year, the ALE is reduced to $200,000. What is the residual risk in terms of ALE after one year of control operation?
Hard698During a quarterly risk review, the CISO notes that the number of failed authentication attempts has increased by 300% over the last month. The IT team confirms no changes to authentication systems. This metric is BEST categorized as which of the following?
Hard699Which of the following is an example of a corrective control?
Easy700Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?
Easy701An organization is implementing a new access control system. Which of the following is the MOST important consideration during the implementation phase?
Medium702A company has implemented a new control to detect unauthorized access attempts. What is the PRIMARY purpose of monitoring this control?
Easy703A risk practitioner has completed a risk assessment for a new cloud-based payroll platform. The business owner wants to proceed immediately because the platform will save $200,000 annually. The residual risk exceeds the organization's risk appetite, and no compensating controls are in place. Which action should the risk practitioner recommend FIRST?
Medium704A database error log shows repeated login failures followed by a successful authentication. Which control failure is MOST likely?
Easy705After a risk assessment, the risk owner states that the residual risk for a specific asset is within the organization's risk tolerance. Which of the following BEST describes the action that should be taken?
Easy706Which TWO are primary objectives of IT risk identification?
Easy707An organization notices a spike in failed authentication attempts over the past week. This metric is best classified as which type of risk indicator?
Hard708A risk manager is evaluating the security of a new containerized application deployment in a hybrid cloud environment. The organization uses Kubernetes for orchestration and must ensure that container images are free from known vulnerabilities before deployment. Which of the following controls is MOST effective for this purpose?
Hard709A risk manager is facilitating a risk identification workshop for a new cloud migration initiative. Which TWO techniques are most effective for identifying potential IT risks at this stage?
Medium710A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?
Medium711A risk practitioner is using a 5×5 heat map with likelihood and impact ratings. Which of the following is a key advantage of this qualitative risk analysis approach?
Easy712In a risk-aware culture, which of the following behaviors is MOST encouraged?
Easy713Which of the following is the primary purpose of a risk heat map in a risk report?
Easy714A company has implemented a new cloud-based customer relationship management (CRM) system. The IT risk manager is tasked with identifying risks related to this system. Which of the following is the MOST important risk identification technique to use initially?
Easy715Which type of control is primarily designed to prevent an unwanted event from occurring?
Easy716A manufacturing firm's risk practitioner is facilitating a workshop to identify IT risks for a new industrial control system (ICS) rollout. Operational engineers, IT staff, and a third-party integrator are present. Which of the following approaches BEST supports comprehensive IT risk identification in this setting?
Medium717Which THREE of the following are key indicators that a risk identification process is effective? (Choose three.)
Hard718The exhibit shows a log entry from a GRC system. Which of the following is the MOST significant concern regarding this risk score update?
Medium719A manufacturing company uses IoT sensors on the factory floor to monitor equipment performance. The sensors transmit data to a central server via Wi-Fi. During a risk identification workshop, the operations manager reveals that some sensors are operating on outdated firmware with known vulnerabilities. The IT director proposes replacing all sensors at a high cost. The risk team notes that a breach could cause production downtime but the sensors only collect non-sensitive operational data. The company has a low tolerance for downtime. What should the risk team identify as the most critical risk?
Medium720An organization defines its risk appetite as 'no more than one major security incident per year.' During the year, a major incident occurs. The monitoring team reports this to the risk committee. What should be the NEXT step?
Easy721A hospital's risk practitioner is identifying risks to its electronic health record platform. The practitioner documents that a single system administrator holds the only account with rights to restore the production database, and no documented procedure exists for that task. Which risk factor does this finding PRIMARILY represent?
Easy722An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)
Hard723A financial services firm is conducting a risk assessment for a new mobile banking application. The risk practitioner needs to evaluate the likelihood of a threat exploiting a vulnerability. Which of the following factors is MOST relevant when assessing the likelihood of a threat event?
Medium724A mid-sized retail company operates 50 stores across three regions. Each store uses a point-of-sale (POS) system that transmits credit card transactions to a centralized payment processor. The company recently deployed a new SaaS-based inventory management application that connects to the POS system via API. The IT department has no formal process for tracking third-party connections. The risk manager suspects that unknown or unauthorized connections may exist. During a risk identification review, the risk manager discovers that the POS vendor's API documentation was shared with the inventory SaaS provider without a non-disclosure agreement (NDA). Additionally, the API keys for the POS system are stored in plain text configuration files on the inventory SaaS application server. The company's security policy requires encryption of all sensitive data in transit and at rest. Which of the following should the risk manager prioritize as the HIGHEST risk scenario to document in the risk register?
Medium725A software development company is launching a new mobile application that will collect user location data. The risk manager identifies that the data collection could violate privacy regulations if not properly disclosed. The legal team recommends updating the privacy policy and obtaining explicit user consent. Which risk response strategy is this?
Medium726A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?
Hard727A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?
Medium728An organization is implementing COBIT 2019 and the board has requested assurance that risk management activities are aligned with business objectives. Which governance objective is primarily focused on ensuring risk optimization through evaluation, direction, and monitoring?
Medium729After a major system upgrade, the control testing team reports that a critical automated control failed intermittently. The control owner states it's a temporary glitch. What is the best course of action?
Hard730After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?
Medium731An organization is migrating on-premises applications to a public cloud. Which THREE of the following should be considered as key risk identification activities?
Medium732An organization is conducting a vulnerability assessment of its IT assets. Which of the following sources is MOST authoritative for identifying known software vulnerabilities?
Easy733A key control indicator (KCI) for a critical access control shows a deficiency rate of 12% for the quarter, exceeding the target of 5%. Which of the following should be the risk practitioner's PRIMARY action?
Hard734A risk manager notices that a key risk indicator (KRI) has been consistently above the threshold for three months. What should be the first action?
Medium735The risk team is evaluating the cost-effectiveness of a proposed control that will reduce the annualized loss expectancy (ALE) for a cyber attack from $500,000 to $100,000. The annual cost of the control is $150,000. What is the net benefit of implementing this control?
Medium736A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?
Medium737A company calculates the annualized loss expectancy (ALE) for a server outage as $75,000. The cost to implement a high-availability solution is $200,000 with a lifespan of 5 years and annual maintenance of $10,000. What is the residual risk if the solution reduces outage likelihood by 90%?
Hard738Which THREE of the following are examples of risk mitigation controls? (Select THREE.)
Easy739An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?
Hard740Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)
Medium741You are the risk manager for a healthcare provider. A risk assessment identified that patient data is transmitted over unencrypted connections between clinics and the data center. The existing controls include strong network perimeter defenses. The risk is rated as high. Management is concerned about the cost of implementing encryption. You have proposed a control that encrypts data in transit. However, the network team argues that the perimeter controls are sufficient. What is the MOST appropriate response?
Easy742Which of the following is a limitation of qualitative risk analysis?
Easy743An organization is designing an IT risk management program. Which of the following should be the PRIMARY consideration when developing a risk register?
Medium744Which of the following BEST describes inherent risk?
Easy745An e-commerce company is conducting an IT risk assessment for its order management system. The risk team has identified a risk that the system could fail during peak holiday traffic, causing revenue loss. The team needs to estimate the potential financial impact of this event to inform treatment decisions. Which activity is the team performing?
Easy746A large retail company is implementing a new cloud-based inventory management system. The system will store sensitive customer data and integrate with existing on-premises ERP. The risk manager is asked to identify the most critical risk to address in the shared responsibility model. Which risk is MOST likely to be overlooked?
Medium747An organization is evaluating the risk of a ransomware attack. Using the FAIR framework, which of the following components directly multiplies to calculate Loss Event Frequency (LEF)?
Medium748After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?
Hard749A company's IT risk manager is evaluating Key Risk Indicators (KRIs) for the cybersecurity function. Which TWO of the following are valid examples of leading KRIs?
Hard750In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?
Hard751An organization's risk report shows a risk heat map with several risks in the high-likelihood, high-impact quadrant. What is the most appropriate action for the risk owner?
Medium752Which COBIT 2019 domain objective focuses on ensuring that risk is optimized through evaluation, direction, and monitoring?
Easy753You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?
Hard754A risk practitioner is designing a monitoring dashboard for senior management. Which key performance indicator (KPI) would be MOST useful for tracking control effectiveness over time?
Medium755Which THREE of the following control monitoring techniques are considered continuous monitoring?
Hard756A retail company is identifying risks in its supply chain. Which approach is most effective for identifying previously unknown risks?
Medium757A risk manager is evaluating the risk of quantum computing for the organization's encryption. The organization uses RSA-2048 for data encryption. What is the PRIMARY consideration in planning for post-quantum cryptography migration?
Hard758A security analyst is reviewing CVE entries and NVD data to identify vulnerabilities in software assets. This activity is part of which vulnerability identification approach?
Medium759A regional bank uses a centralized GRC platform to monitor key risk indicators (KRIs) for operational risk. The chief risk officer (CRO) reviews the monthly risk report and notices that the KRI 'number of system outages exceeding 4 hours' has been consistently reported as 0 for the past six months. However, the IT incident log shows three such outages in the same period. The CRO suspects the KRI is not being accurately reported. What should the risk manager do next?
Medium760Which of the following best describes the purpose of an IT risk universe?
Easy761A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?
Hard762A risk analyst is preparing a risk register for a new customer relationship management (CRM) system hosted in a public cloud. For each identified risk, the analyst assigns a likelihood rating (1–5) and an impact rating (1–5) based on team consensus, and then multiplies the two scores to produce a risk score. Which risk assessment approach is the analyst using?
Medium763During a risk identification workshop, the business process owner states that a key system has no documented dependencies. What is the BEST next step for the risk practitioner?
Medium764Which risk treatment option involves eliminating the activity that creates the risk?
Easy765A risk practitioner is preparing a quarterly report for the board risk committee. Senior management wants the report to show that IT risk is being managed within appetite, but the practitioner discovers that two critical control failures were identified three weeks ago and remediation is only 40 percent complete. Which approach best satisfies the practitioner's reporting obligation?
Hard766An organization is implementing a new access control system to prevent unauthorized access to sensitive data. Which type of control is being implemented?
Easy767Which control type is designed to stop a risk event from occurring?
Easy768An insurance company's risk committee is reviewing a new mobile claims application. A penetration test found that the app stores authentication tokens in plaintext in the device's shared application storage, where any other app on a rooted or jailbroken device can read them. The development team proposes to add certificate pinning. Which of the following is the MOST appropriate risk response?
Hard769A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?
Hard770A multinational corporation is developing a risk treatment plan for a newly identified risk: a critical vendor's financial instability could disrupt the supply chain. The risk manager is considering several options. Which TWO of the following are examples of risk mitigation controls that directly reduce the likelihood or impact of this risk? (Choose two.)
Hard771A risk assessment reveals that the likelihood of a phishing attack is high, and the impact is moderate. The organization decides to implement security awareness training and email filtering. This is an example of which risk treatment?
Hard772A risk analyst is building a control assessment for a payment processing environment. She needs to determine whether a new control objective is adequately addressed. She has identified the control objective, the associated risk, and the control activity. Which of the following should she do NEXT to complete the control assessment?
Medium773A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)
Medium774A risk practitioner is using the MITRE ATT&CK framework to identify threats relevant to a financial services firm's cloud-hosted trading platform. The practitioner wants to focus on techniques adversaries use after obtaining initial access to cloud infrastructure. Which of the following BEST describes how ATT&CK should be applied in this risk identification effort?
Hard775Which of the following is the PRIMARY purpose of a risk register in the risk identification phase?
Easy776A company is considering using a qualitative risk assessment approach to evaluate IT risks. Which TWO of the following are advantages of qualitative risk analysis over quantitative risk analysis?
Easy777A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)
Medium778An organization is designing a risk dashboard for senior management. Which of the following is the MOST important characteristic of the key risk indicators (KRIs) displayed?
Medium779During a risk identification workshop, the team identifies a potential data leakage from a legacy system. What is the FIRST step the risk owner should take?
Hard780A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?
Easy781A multinational bank must report technology risk to its board risk committee each quarter. The committee has asked the risk team to strengthen the reporting so it drives decisions rather than just describing activity. Which TWO of the following changes would BEST achieve that objective? (Choose two.)
Hard782A risk practitioner is analyzing the threat landscape for a hospital's connected medical devices. The devices run legacy operating systems that cannot be patched and are accessible from the clinical network. Which factor MOST increases the likelihood of exploitation?
Medium783A risk practitioner at a financial services firm is identifying IT risk scenarios for a new mobile banking application. The firm uses the ISACA risk scenario development approach. Which TWO of the following are essential components of a well-defined risk scenario? (Choose two.)
Hard784A financial services firm has a risk register entry for a critical trading application. The business owner proposes adding a redundant data center to reduce downtime risk. The risk practitioner notes that the redundancy will cost $2 million annually and reduce expected annual loss from $3 million to $500,000. Which factor is MOST important for the risk practitioner to evaluate before recommending approval?
Hard785During a threat modeling exercise for a new web application, the team uses STRIDE. Which threat type under STRIDE corresponds to an attacker modifying data in transit?
Medium786An IT risk manager is reviewing the results of a recent risk assessment. The organization has a risk appetite that allows for low residual risk. One identified risk has an inherent risk score of 15 (on a scale of 1-25) and currently has no controls. Which of the following is the BEST recommendation for this risk?
Medium787A risk practitioner is reviewing system logs and notices multiple failed login attempts from a foreign IP address. This observation is an example of which type of risk identification activity?
Easy788According to the NIST Cybersecurity Framework, which function involves developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Medium789In the context of IT governance, which COBIT 2019 process is specifically focused on ensuring risk optimization?
Easy790A regional insurance company has just completed an IT risk assessment and documented the identified risks in a central repository. The risk practitioner now wants to ensure that each risk has an assigned owner, a defined response, and a status that can be tracked over time. Which of the following should the practitioner use to meet these needs?
Easy791Which of the following is an example of a detective control?
Medium792A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?
Hard793A global company is moving its critical applications to a public cloud. Which THREE of the following are key risk considerations in the shared responsibility model?
Hard794A risk practitioner is performing a cost-benefit analysis for a proposed control. The annualized loss expectancy (ALE) for a risk is currently $500,000. The proposed control will reduce the ALE by 80%, and the annual cost of the control is $150,000. What is the net benefit of implementing the control?
Medium795An organization uses a SIEM to automatically test access control rules on a continuous basis. This is an example of which type of monitoring?
Hard796Which control implementation activity involves updating system configurations and user access rights when a new security tool is deployed?
Easy797A multinational corporation is conducting a risk assessment for its supply chain. The risk team has identified a critical supplier that provides a unique component. The supplier is located in a region prone to natural disasters. The team wants to evaluate the risk and determine the appropriate risk response. Which of the following should be the FIRST step in this evaluation?
Medium798A risk manager is evaluating the application of IEC 62443 for industrial control systems. Which THREE of the following are key security requirements addressed by this standard?
Medium799A company has implemented an automated control monitoring system that generates alerts when transactions exceed predefined thresholds. The system has been in production for six months. The risk team notices that the number of alerts has been decreasing, while actual control failures have remained constant. Which of the following is the MOST likely cause?
Medium800An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?
Medium801A risk practitioner is facilitating a workshop to identify risks for a new customer data analytics platform. During the session, participants repeatedly describe how a competitor might copy the platform's features and how a regulator might question the platform's data retention practices. The practitioner wants to ensure the workshop produces structured risk statements rather than general concerns. Which of the following should the practitioner do NEXT?
Hard802A company uses the FAIR model to perform a quantitative risk analysis. The threat event frequency (TEF) is estimated at 10 per year, vulnerability (V) is 0.5, and loss magnitude (LM) per event is $50,000. What is the annualized loss expectancy (ALE)?
Medium803An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?
Easy804An organization’s continuous monitoring program includes automated vulnerability scanning and log review. Which of the following is a Key Risk Indicator (KRI) that would BEST signal an increasing risk of a successful network breach?
Medium805A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?
Hard806You are the risk manager for a healthcare organization that uses an electronic health records (EHR) system. The system has a built-in audit log that records all access to patient data. Recently, the Chief Information Security Officer (CISO) raised a concern that there have been multiple reports of unauthorized access to patient records, but the audit log analysis has not identified any suspicious activity. You have been asked to investigate. Your review of the audit log configuration reveals that the system only logs successful access events, not failed access attempts. Additionally, the log retention period is set to 30 days, and the logs are stored in a flat file on the same server as the EHR application. The monitoring team manually reviews the logs at the end of each month. Which of the following is the MOST significant risk associated with the current monitoring approach?
Medium807An organization is planning for post-quantum cryptography migration. Which THREE of the following are key considerations for this migration?
Hard808A risk analyst is reviewing monthly control test results. One control failed testing twice in a row. What is the FIRST step the analyst should take?
Easy809A risk practitioner is reviewing the results of a risk assessment and needs to determine the risk level for a series of identified risks. The organization uses a risk matrix with likelihood and impact scales. Which of the following is the PRIMARY purpose of determining the risk level?
Easy810A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?
Easy811A company decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?
Medium812During a merger and acquisition (M&A) due diligence, the IT risk manager needs to identify risks in the target company's IT environment. Which approach is most effective for comprehensive risk identification?
Hard813A retail company's risk register shows that a point-of-sale system vulnerability has a high likelihood and high impact. The IT team proposes applying a vendor patch, but the patch has not been tested with the custom payment application. Which risk response strategy is being considered?
Easy814During a control implementation project, the risk manager discovers that the resource requirements have increased significantly, making the original cost-benefit analysis invalid. What should the risk manager do first?
Hard815A financial services firm's risk practitioner is building a risk register entry for a customer-facing mobile banking application hosted in a public cloud. The application stores PII and processes payments. Management wants to understand the inherent risk before any controls are considered. Which of the following BEST represents the inherent risk of this asset?
Medium816A healthcare provider has experienced repeated phishing incidents that led to credential compromise. The risk committee has approved a new email security control that will quarantine suspicious messages and enforce multifactor authentication. Which TWO activities are essential to validate that the control is operating effectively after implementation? (Choose two.)
Medium817A risk manager is designing an IT risk management programme. Which THREE of the following are essential components of a risk management policy?
Medium818During an IT risk assessment, the risk team identifies a high inherent risk for a legacy application. The team is evaluating control options. Which THREE are considered preventive controls?
Hard819An organization has decided to purchase cyber insurance to cover potential losses from a ransomware event affecting its order-processing systems. Which risk response has the organization selected?
Easy820A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?
Medium821An organization has a legacy system that cannot be patched due to vendor end-of-life. The system processes non-critical data. The risk manager has determined that the likelihood of exploitation is low, but the impact would be high. Which risk response strategy is MOST appropriate?
Hard822A risk practitioner is designing a key risk indicator (KRI) program for a cloud-hosted customer portal. The CISO wants indicators that provide early warning of deteriorating risk conditions rather than reporting losses that have already occurred. Which TWO of the following are the MOST appropriate KRIs for this objective? (Choose two.)
Medium823A company is implementing a risk identification process for third-party risks. Which THREE factors should be considered when identifying risks from a critical software vendor?
Hard824A financial services firm is migrating its customer relationship management (CRM) system to a SaaS provider. The risk practitioner must assess the provider's security posture. Which of the following is the MOST reliable source of assurance?
Medium825Which of the following is a primary concern when using AI/ML models for decisions subject to regulatory oversight?
Easy826During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?
Medium827A company identifies a high inherent risk in its online payment system. After implementing a Web Application Firewall (WAF) and conducting quarterly penetration tests, the residual risk is assessed as medium. Which of the following best explains the relationship between inherent risk, controls, and residual risk?
Hard828A company has multiple business units each using different risk assessment methodologies. The risk committee wants consistent monitoring reports. What is the BEST approach to achieve consistency?
Hard829A risk practitioner is preparing a risk register for a hospital's new telemedicine platform. During interviews, the CIO states that the platform's availability is critical because clinicians rely on it for urgent consultations. The practitioner needs to document how this business dependency influences risk identification. Which of the following BEST describes the role of business criticality in this context?
Easy830A company is assessing the risk of a ransomware attack. The security team estimates the threat event frequency as 2 attacks per year, vulnerability as 0.3 (30% chance of success), primary loss as $500,000, and secondary loss as $200,000. What is the annualized loss expectancy (ALE) using the FAIR framework?
Medium831After a risk assessment, the risk owner determines that the residual risk is still above the risk appetite. Which of the following is the MOST appropriate next step?
Medium832Based on the exhibit, which risk is MOST likely to be identified during a risk assessment?
Easy833A risk assessment reveals a high inherent risk that is within the organization's risk appetite. The risk owner documents the risk and formally accepts it. This is an example of which risk treatment option?
Easy834During a risk assessment, an organization identifies that its legacy ERP system has a high likelihood of failure during peak transaction periods. The system supports critical financial operations. The risk owner proposes to upgrade the system, but the project would take 18 months and require significant capital investment. The CEO questions whether the risk can be reduced to an acceptable level more quickly. Which of the following is the MOST appropriate immediate risk response?
Hard835A financial services firm is identifying risks for a new mobile banking feature that will rely on a third-party identity verification provider. The vendor has provided a SOC 2 Type II report, but the firm has not yet reviewed it. Which of the following BEST describes how the firm should treat the vendor-related risk during identification?
Medium836A financial institution is implementing a new continuous monitoring solution for its transaction processing systems. The solution generates alerts for suspicious activities. Which TWO of the following are essential considerations when defining the alert thresholds?
Easy837A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?
Hard838Which THREE of the following are key components of an effective risk treatment plan?
Hard839Which TWO of the following are examples of corrective controls?
Medium840After a data breach has been contained, what is the most important action for identifying underlying IT risks?
Easy841A risk analyst is reviewing the results of control testing for a critical business process. Which THREE of the following are valid reasons to classify a control as ineffective?
Medium842Put the steps for performing a control self-assessment (CSA) in order.
Medium843An internal audit report identifies that the IT department did not patch a critical vulnerability in a database server for 90 days. The risk manager wants to identify the root cause risk. Which approach should be used?
Medium844A risk practitioner is identifying risks for a pharmaceutical company that shares clinical trial data with external research partners. The practitioner learns that partners access the data through a shared portal with role-based access, and that one partner recently terminated its agreement but retained portal credentials. Which of the following is the MOST significant risk identification finding?
Hard845Which THREE of the following are common business impact categories used in risk scenarios?
Medium846During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?
Hard847An organization has a risk appetite statement that says 'We accept up to $5 million in operational losses per year.' However, a new cloud migration project is estimated to have a potential operational loss of $8 million if a critical failure occurs. The risk capacity of the organization is $20 million. What should the risk practitioner recommend?
Hard848A Key Control Indicator (KCI) for a critical firewall rule set shows an exception rate of 12% over the past month, exceeding the acceptable threshold of 5%. The control owner is responsible for remediation. Which action should the risk practitioner recommend FIRST?
Hard849Which TWO of the following are primary sources of IT risk identification? (Select exactly TWO.)
Medium850During a risk assessment for a new financial application, the risk manager identifies that the application processes sensitive customer data and is accessible from the internet. Which of the following is the MOST appropriate risk scenario to document?
Medium851A risk practitioner at a regional bank is building a risk register entry for the loss of a critical core banking application. The head of IT operations insists on recording a single, point-in-time likelihood estimate of 15% derived from last year's incident log, and refuses to consider any range. Which CRISC-aligned principle should the practitioner apply to MOST appropriately represent this IT risk?
Medium852A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?
Hard853A healthcare organization is required by regulation to retain patient records for seven years. The risk manager is evaluating a new cloud storage solution that offers encryption at rest but stores data in multiple jurisdictions. Which of the following is the MOST critical risk consideration when selecting this solution?
Hard854Which COBIT 2019 governance objective focuses on ensuring that the enterprise's risk appetite and tolerance are understood, articulated, and communicated, and that risk is managed appropriately?
Easy855After implementing controls, the risk remaining is called:
Hard856A company uses a third-party vendor to process customer data. The vendor's security control monitoring reports show no issues. However, the company's internal monitoring detects anomalies in vendor response times. What is the BEST interpretation?
Medium857When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?
Easy858A multinational corporation is assessing the risk of non-compliance with GDPR. Which of the following is the BEST approach to quantify the potential fine?
Hard859An organization is implementing a new access control system to protect sensitive data. Which type of control is most appropriate for preventing unauthorized access?
Medium860A company is evaluating controls for a high-risk process. Which control type is designed to stop a risk event from occurring?
Medium861A company's key risk indicator (KRI) for 'failed login attempts' has exceeded its threshold by 20%. The control owner reports that a recent firewall change caused false positives. What should the risk practitioner do FIRST?
Hard862A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?
Hard863A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?
Hard864A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
Medium865An IT risk manager is developing KRIs for a critical application. Which TWO of the following are leading indicators that the risk level may be increasing? (Select TWO)
Hard866A hospital's risk team is assessing a clinical imaging archive. The team determines that a ransomware event would encrypt the archive and disrupt diagnostic services, with an estimated single-loss magnitude of $2,000,000. Existing controls reduce the likelihood of a successful attack to an estimated 0.4 occurrences per year. What is the annualized loss expectancy (ALE) for this risk?
Hard867A risk practitioner is designing a risk report for the board of directors. Which TWO content elements are most appropriate for strategic risk reporting? (Select two.)
Medium868A bank is identifying IT risks and categorizes a potential data breach as both a compliance risk (due to GDPR) and a reputational risk. This is an example of:
Medium869During a risk assessment, the risk manager finds that a critical application has a single point of failure in its network path. The application's availability requirement is 99.99%. The current design achieves only 99.9% uptime. Which risk metric should be calculated first?
Hard870A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?
Hard871A software company has completed a risk assessment showing that a critical SaaS platform has a residual risk above appetite due to weak vendor access controls. Budget is limited and the remediation will take six months. The CISO must decide how to proceed while the risk remains elevated. Which action BEST aligns with CRISC risk response principles?
Hard872Which risk assessment approach is most appropriate for a new technology that has limited historical data and high uncertainty?
Easy873An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?
Easy874An organization is implementing a new control to prevent unauthorized access to its critical database. Which type of control is most appropriate for this requirement?
Easy875A risk practitioner is preparing a risk report for the executive committee. The committee has limited time and has previously complained that reports contain too much technical detail. Which approach BEST communicates the most critical IT risks to this audience?
Medium876A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?
Medium877A risk practitioner is assessing the risk of a distributed denial-of-service (DDoS) attack against an online retailer's public storefront. The CISO asks which factors would MOST directly increase the likelihood that such an attack would succeed in disrupting service. (Choose two.)
Hard878An organization is implementing controls to mitigate the risk of data exfiltration. Which TWO control types would be considered preventive? (Select TWO)
Easy879A financial services firm is defining the scope of its annual IT risk assessment. The board has asked the risk team to ensure the assessment covers both internal and external factors that could affect the confidentiality of customer data. Which TWO activities should the team include to meet this expectation? (Choose two.)
Hard880A security operations center (SOC) analyst notices multiple failed login attempts from an internal IP address followed by a successful login from an unusual geographic location. Which risk identification technique should the risk manager use to assess this as a potential risk?
Hard881An organization's risk register lists a risk with an annualized loss expectancy (ALE) of $200,000. A proposed control would reduce the ALE to $50,000, and the control costs $40,000 per year to operate. What is the value of the control's risk reduction?
Easy882A risk practitioner is reviewing the risk register for a cloud-based customer relationship management (CRM) system. The register contains several entries, and the practitioner must identify which entries represent inherent risk rather than residual risk. Which two of the following entries are examples of inherent risk? (Choose two.)
Medium883A financial services firm's risk committee has approved a risk response plan for its core payment platform. The plan requires monthly tracking of key risk indicators (KRIs) and quarterly reporting of control test results to the board. Six months later, the CIO asks the risk manager to confirm that the approved response is still appropriate given new regulatory guidance. Which of the following should the risk manager do FIRST?
Medium884During a risk assessment, a control self-assessment (CSA) indicates that a key control is operating effectively. However, an independent audit finds multiple control failures. Which of the following is the MOST likely reason for this discrepancy?
Medium885An organization is using the FAIR framework to perform a quantitative risk analysis for a data breach scenario. Which TWO of the following are components of the Annualized Loss Expectancy (ALE) calculation in FAIR?
Medium886A control test reveals a 100% pass rate for a detective control. What does this indicate?
Easy887Which of the following is a characteristic of IoT devices that increases cybersecurity risk?
Easy888A bank's risk committee is reviewing a proposal to increase the risk appetite threshold for third-party data processing failures from 2 to 5 incidents per year. The head of internal audit objects, noting that three such failures occurred in the last 12 months and one caused a regulatory finding. Which action should the risk committee take FIRST?
Hard889A multinational retailer's risk register shows a high inherent risk for its point-of-sale (POS) payment environment. After implementing tokenization, the risk owner records a residual risk rating of low. During the next quarterly review, the internal audit team finds that several legacy POS terminals still transmit clear-text card data. Which risk response principle was violated?
Hard890Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?
Easy891Which THREE of the following are common challenges in risk reporting?
Hard892An organization uses a qualitative risk assessment and assigns a likelihood of '3' and impact of '4' on a 5-point scale. The heat map defines risk scores 12-25 as high. What is the risk rating?
Medium893A hospital's risk team is assessing a new telehealth platform. The vendor reports that its encryption module was certified two years ago. The team wants to determine whether the residual risk of relying on that module is acceptable. Which action should the team take FIRST?
Hard894An organization wants to promote a risk-aware culture. Which of the following actions is MOST effective for encouraging employees to report incidents without fear?
Medium895An organization is implementing a continuous monitoring solution for its network. Which of the following is an example of continuous monitoring?
Medium896A company has identified that its legacy financial system has a high inherent risk due to outdated architecture. The system cannot be replaced for three years. What is the best risk treatment strategy?
Medium897During IT risk identification, which document serves as the central repository for all identified risks, their characteristics, and current status?
Easy898A hospital network is deploying a new medical imaging archive. The risk practitioner learns that the vendor's support engineers require remote access to the archive for maintenance. Which of the following is the BEST control to manage the third-party access risk?
Hard899You are the IT risk manager for a financial institution that processes high-value transactions. The organization uses a cloud-based core banking system and on-premises servers for backup. During a recent risk assessment, you identified that the cloud provider's service-level agreement (SLA) guarantees 99.9% uptime, but the organization's business impact analysis (BIA) indicates that every hour of downtime costs $500,000. The current recovery time objective (RTO) for the core banking system is 4 hours, but the actual recovery capability is 6 hours due to manual steps in failover. The risk owner has accepted this risk informally. You are asked to recommend a course of action to the risk committee. Which of the following is the most appropriate recommendation?
Easy900A manufacturing company is integrating its operational technology (OT) network with the corporate IT network to enable real-time data analytics. Which of the following risks should be prioritized during the risk assessment?
Medium901During a risk assessment, the risk practitioner is identifying threats to an application. Which threat modeling technique is specifically designed to analyze application threats using categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Easy902A smart manufacturing company has deployed hundreds of IoT sensors and actuators across its production line. These devices are connected directly to the corporate network without any segmentation and communicate using unencrypted protocols. A third-party vendor manages all IoT devices and has administrative access from their own network. Recently, the IT team detected unusual outbound traffic from the IoT segment to unknown IP addresses on the internet. The risk manager is leading a risk identification workshop. Based on this scenario, what is the most critical risk to the organization that should be identified and documented?
Easy903An organization implements an intrusion detection system (IDS) to monitor for security incidents. This is an example of which type of control?
Medium904A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?
Easy905A company is conducting a Risk Identification for a new payment processing system. The team discovers that the system does not have encryption at rest. This is an example of:
Hard906Which risk treatment option involves formally acknowledging the risk and taking no further action, provided the risk is within the organization's risk appetite?
Easy907A hospital is deploying IoT medical devices that connect to the network. Which risk is MOST concerning from a cybersecurity perspective?
Medium908An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.
Easy909Based on the exhibit, what is the MOST likely risk scenario?
Hard910A hospital's risk practitioner is building a risk register entry for the loss of a critical electronic health record (EHR) system. The practitioner wants to express the risk in a way that combines the probability of the event with the magnitude of its business impact so that leadership can compare it against other enterprise risks. Which of the following BEST represents this expression?
Medium911A risk analyst is prioritizing remediation efforts across four identified risks. The analyst has likelihood and impact ratings but must also account for the speed at which each risk could materialize and the organization's ability to respond. Which concept is the analyst applying to adjust the prioritization?
Medium912In the FAIR framework, Loss Event Frequency (LEF) is calculated as:
Medium913A risk practitioner at a regional hospital is building a risk register and needs to classify each identified risk by its source. During interviews, staff describe a recurring situation: a radiology scheduling application has no automated account deprovisioning, so terminated employees retain access for weeks until a supervisor manually reports them. Which risk identification category BEST describes this finding?
Medium914In the FAIR framework, what does Loss Event Frequency (LEF) represent?
Medium915During a risk assessment, a risk is assigned a likelihood of 'High' and an impact of 'Medium' on a 5×5 heat map. What is the risk rating?
Medium916A multinational retailer's IT risk manager must define key risk indicators (KRIs) for its third-party payment processing relationships. Which TWO characteristics must the selected KRIs exhibit to be effective for ongoing risk monitoring? (Choose two.)
Medium917An organization uses the CISA Known Exploited Vulnerabilities (KEV) catalog as a primary source for vulnerability identification. This catalog is BEST described as:
Medium918When reporting risk and control monitoring results to the board of directors, which of the following formats is MOST effective?
Easy919Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?
Easy920A small manufacturing company is conducting its first IT risk assessment. The company has a flat network with no segmentation, and all employees have administrative access to their workstations. The risk practitioner identifies that a malware infection on one workstation could easily spread to the entire network. The company has a limited budget for IT security improvements. Which of the following risk treatment options is MOST cost-effective and practical?
Easy921Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?
Medium922A risk practitioner at a healthcare payer is building the risk identification taxonomy for a new claims-processing platform. The CISO asks why the taxonomy must explicitly distinguish between a 'threat event' and a 'loss event' rather than treating both as 'risk' in the register. Which statement BEST justifies that distinction?
Medium923Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Medium924An incident occurs due to a control that was thought to be automated but was actually manual. The risk register did not reflect this. What is the MOST likely root cause?
Medium925Sequence the steps for developing a disaster recovery plan (DRP).
Medium926A healthcare organization's risk register shows that a critical server lacks vendor support and has a high inherent risk of failure. The risk owner proposes to implement redundant hardware and a failover cluster. The cost of the redundancy is $200,000, while the estimated annual loss from failure is $150,000. Which factor is MOST important for the risk practitioner to consider when evaluating this proposed risk response?
Hard927A risk practitioner is selecting a risk analysis technique for a new payment processing system. The team has limited historical loss data, wants to incorporate expert judgment, and needs to prioritize risks for management review. Which technique is MOST appropriate?
Easy928Which of the following is an example of a preventive control?
Easy929During a quarterly control review, the risk team discovers that a key manual approval control was bypassed in 15% of transactions due to a recent process change. What is the FIRST action the risk practitioner should take?
Easy930A risk manager is designing an IT risk management programme. Which document should be created FIRST to guide the overall approach to risk management?
Easy931What is the primary purpose of a risk heat map in IT risk reporting?
Easy932A risk manager is reviewing the risk register and notices that several risks have been identified as 'high' but no risk owner has been assigned. Which of the following is the MOST appropriate action to ensure proper risk identification going forward?
Hard933A risk practitioner is assessing a customer-facing API that processes payment tokens. The team has documented the threat community, the vulnerability, and the potential loss magnitude, but the assessment stalls because no one can agree on how often the threat would realistically attempt exploitation. Which factor is the practitioner attempting to establish to complete this scenario-based risk analysis?
Hard934A company is performing a qualitative risk analysis for a new cloud migration project. Which TWO of the following are recognized limitations of qualitative risk analysis?
Medium935A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?
Easy936An organization uses a quantitative risk analysis method. The annualized loss expectancy (ALE) for a specific risk is calculated as $500,000. The cost of implementing a control is $150,000 per year, and it is expected to reduce the ALE by 80%. What is the net benefit of implementing the control?
Hard937A financial institution is selecting a risk assessment methodology for evaluating cybersecurity risks across its critical systems. Which of the following is the PRIMARY consideration when choosing between qualitative and quantitative approaches?
Easy938An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)
Hard939A risk practitioner is evaluating the risk that a cloud provider's regional outage disrupts a company's order management system. The company has a recovery time objective (RTO) of four hours, but the provider's documented regional recovery capability is estimated at twelve hours. Which of the following BEST characterizes the risk exposure this gap represents?
Hard940Which TWO of the following are examples of external risk identification sources? (Choose two.)
Easy941Which THREE of the following are key considerations when selecting a risk response option?
Medium942A financial institution is implementing a new risk monitoring tool that aggregates data from multiple sources. The tool is expected to provide real-time dashboards for risk committees. However, during user acceptance testing, the dashboards show inconsistent data due to time zone differences across sources. What is the best approach to resolve this?
Hard943A risk manager is prioritizing risks based on their inherent risk scores. Which of the following factors should be considered when prioritizing treatment actions?
Medium944A risk practitioner is evaluating the organization's vulnerability management programme. The organization scans its internal network weekly, but the CIO is concerned that critical internet-facing services are not adequately covered. Which TWO of the following changes would MOST improve the identification of exploitable vulnerabilities on externally exposed assets? (Choose two.)
Medium945A company is assessing the impact of a potential ransomware attack. Which TWO impact categories are considered operational impacts?
Medium946An organization wants to promote a risk-aware culture. Which initiative best supports this goal?
Easy947A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?
Medium948A risk manager is evaluating the cost-effectiveness of a proposed control. The control costs $50,000 annually to implement and maintain. The current annual loss expectancy (ALE) for the risk is $200,000, and the control is expected to reduce the ALE by 70%. What is the net benefit (or loss) of implementing the control?
Medium949A bank is adopting a third-party API gateway to expose account balance services to fintech partners. The risk practitioner must ensure that a partner's excessive or unusual API consumption cannot degrade service for other partners or core banking systems. Which control is MOST appropriate to address this risk?
Hard950An organization uses Key Control Indicators (KCIs) to measure the effectiveness of its firewall change management process. Which KCI would best indicate a process deficiency?
Hard951A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?
Easy952A risk practitioner is interviewing business unit leaders to identify IT risks for an annual risk assessment. One leader states that the customer relationship management system is critical because sales staff cannot work without it. Which of the following BEST describes the risk practitioner's next action to validate this input?
Easy953During a control monitoring review, the auditor finds that a control designed to detect unauthorized access has not triggered any alerts in six months. What should the risk practitioner do first?
Easy954A multinational corporation is identifying risks associated with cross-border data transfers. Which regulation's risk identification requirements are most relevant?
Hard955Which of the following is the BEST example of promoting a risk-aware culture within an organization?
Easy956A Key Risk Indicator (KRI) for vulnerability management is the "average patch lag time" (number of days between patch release and deployment). In the last month, this metric increased from 15 days to 45 days. How should the risk practitioner interpret this change?
Hard957A risk practitioner is reviewing the organization's risk register and notices that a risk related to a legacy payroll system has been assigned an owner from the IT department. The risk owner is responsible for which of the following?
Easy958An organization uses a Key Risk Indicator (KRI) that tracks the average number of days to patch critical vulnerabilities. The KRI has been trending upward over the last three months, from 15 days to 30 days, while the risk appetite threshold is 20 days. Which conclusion is most appropriate?
Hard959A company is designing its risk and control monitoring program. Which TWO of the following are key attributes of effective monitoring?
Easy960An energy utility's board risk committee receives a quarterly IT risk report showing that overall risk exposure is within appetite, yet a recent regulatory audit identified unpatched internet-facing systems. The risk manager must improve the report so the committee is not misled in the future. Which change is MOST effective?
Hard961An organization is integrating IT risk into its enterprise risk management (ERM) program. What is the primary benefit of this integration?
Medium962A software development company identifies that developers are storing API keys in plaintext within source code repositories. The risk practitioner proposes a risk treatment plan that includes implementing a secrets management solution and rotating all exposed keys. The Chief Technology Officer asks how the risk practitioner will confirm that the treatment plan is reducing the risk over time. Which metric is MOST appropriate for monitoring the effectiveness of this risk response?
Easy963An organization calculates the annualized loss expectancy (ALE) for a cyber attack scenario. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 2. What is the ALE?
Medium964A global logistics company's risk practitioner is identifying risks for a new customs-clearance application. She wants to ensure the risk identification is complete before moving to analysis. Which of the following approaches BEST supports completeness of the risk identification?
Hard965An organization is evaluating cyber insurance options. Which of the following factors is MOST likely to influence the insurance premium?
Medium966A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?
Medium967A risk manager is assessing the potential impact of quantum computing on the organization's cryptographic infrastructure. What is the MOST immediate action the organization should take?
Hard968An organization recently experienced a data breach due to a misconfigured cloud storage bucket. As part of the IT risk assessment, which control should be prioritized to prevent recurrence?
Medium969A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?
Medium970An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?
Medium971An organization is implementing a new cloud-based customer relationship management (CRM) system. Which of the following risk categories would BEST describe the risk of the CRM system failing to meet performance expectations?
Medium972A company's risk monitoring report shows that a key risk indicator (KRI) has exceeded the threshold for three consecutive months. What is the MOST appropriate action?
Medium973A multinational retailer operates point-of-sale terminals in 30 countries. During an IT risk assessment, the risk analyst notes that a single compromised terminal could expose payment card data across multiple jurisdictions, each with different breach notification laws. The CISO asks the analyst to determine the MOST appropriate risk metric to communicate this exposure to the board. Which of the following should the analyst use?
Hard974A risk team is assessing a legacy inventory system that supports a product line scheduled for retirement in nine months. The system has an unpatched vulnerability that cannot be remediated without breaking vendor support, and the business has confirmed it will not extend the product line. Which risk response is MOST appropriate for the remaining exposure?
Hard975During a merger and acquisition (M&A) due diligence, the acquiring company's IT risk manager is tasked with identifying risks in the target's IT environment. Which of the following would be the MOST effective technique to uncover hidden risks?
Medium976A company is evaluating its control monitoring program. Which TWO of the following are key elements of an effective control monitoring framework? (Choose two.)
Medium977Match each information security objective to its description.
Medium978An organization is designing its identity and access management architecture. The risk practitioner wants to reduce the risk of credential theft leading to unauthorized access to critical systems. Which of the following is the MOST effective control to address this risk?
Medium979Which TWO of the following are examples of risk transfer? (Select TWO.)
Medium980A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?
Hard981A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?
Hard982Which THREE of the following are commonly used techniques for identifying IT risks in a large enterprise?
Hard983Based on the exhibit, which key risk indicator (KRI) would this log data be MOST useful for calculating?
Easy984A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?
Hard985A software company is defining key risk indicators (KRIs) for its cloud service availability risk. The risk owner wants indicators that provide early warning of deteriorating conditions rather than after-the-fact outcomes. Which TWO of the following are the most appropriate leading KRIs for this risk? (Choose two.)
Medium986Match each risk management term to its definition.
Medium987A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?
Medium988A risk practitioner is documenting how the organization handles the risk that a critical SaaS vendor could suffer an outage that halts order processing. The vendor publishes a 99.9% uptime commitment and will credit service fees if it is missed. Which action BEST addresses the residual business impact that the credit does not cover?
Easy989A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?
Medium990During a quarterly control effectiveness test, internal audit finds that a detective control missed 15% of security incidents. The control owner claims this is within the acceptable error rate of 20%. However, the risk practitioner notes that the missed incidents were high-severity. What should the risk practitioner do?
Medium991A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?
Easy992A healthcare organization is performing a risk assessment on its electronic health record (EHR) system. The risk team has identified that a legacy interface engine transmits unencrypted patient data between two internal segments. The organization's risk appetite for data confidentiality breaches is low. The IT team proposes to accept the risk because the segments are internal and firewalls separate them from the internet. Which risk response should the risk practitioner recommend FIRST?
Hard993A company is conducting an IT risk assessment for the first time. Which of the following should be the FIRST step?
Easy994A retail company is launching a new e-commerce platform. The risk management team has identified that the platform's payment gateway integration could be exploited to intercept customer credit card data. The team proposes several controls. Which of the following are examples of risk mitigation controls? (Choose two.)
Medium995During a risk assessment of a legacy system, the assessor finds that no control is currently in place. The inherent risk level is 'critical'. The residual risk will be:
Hard996During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?
Medium997Which TWO of the following are primary sources of risk identification for IT projects?
Easy998A global manufacturing company is designing its IT risk reporting program. The board has requested that reports be actionable, comparable over time, and aligned with the enterprise risk management framework. Which TWO of the following characteristics are MOST important for the IT risk reports to meet these objectives? (Choose two.)
Hard999A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?
Hard1000A risk practitioner is asked to reduce the number of KRIs tracked from 50 to 20. Which KRIs should be prioritized for removal?
Hard1001Which THREE of the following are valid risk identification methods according to ISACA's Risk IT Framework? (Select exactly 3.)
Hard1002A hospital's IT risk manager is preparing a quarterly risk report for the executive committee. The report currently lists 240 technical vulnerabilities with CVSS scores but no business context. The CIO asks for a report that helps executives decide where to allocate limited remediation funding. Which change best aligns the report with risk response and reporting objectives?
Easy1003A manufacturer is identifying IT risk associated with a legacy inventory management system that no longer receives vendor security patches. The risk practitioner documents the unsupported platform as a vulnerability. Which additional asset-based factor should the practitioner evaluate to determine how this vulnerability contributes to overall risk?
Medium1004A global retailer is identifying IT risks related to a new cloud-based point-of-sale (POS) system. The risk practitioner wants to use a top-down approach. Which of the following is the MOST appropriate starting point for this approach?
Hard1005A large retailer is implementing a new point-of-sale (POS) system. The project manager wants to identify risks related to payment card data security. Which risk identification technique would be MOST effective for this purpose?
Medium1006A technology startup is developing a mobile payment application. During a risk identification workshop, the team identifies a risk that the application may not comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. What is the BEST way to categorize this risk?
Hard1007Refer to the exhibit. If the control objective is to prevent unauthorized access via MFA, what does this test result indicate?
Medium1008Which THREE of the following are components of Loss Magnitude in the FAIR framework?
Medium1009Which TWO are characteristics of inherent risk?
Medium1010A risk analyst is identifying threats to a retail bank's newly deployed public application programming interface (API) that allows third-party fintech partners to initiate account transfers. Which of the following is the MOST relevant threat to consider during risk identification for this API?
Easy1011A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?
Medium1012An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?
Medium1013A risk practitioner is facilitating a risk assessment workshop for a new cloud-based customer relationship management (CRM) system. The business owner is eager to launch the system and states that the risk assessment is unnecessary because the cloud provider is ISO 27001 certified. Which of the following is the MOST appropriate response from the risk practitioner?
Easy1014A company's control monitoring dashboard shows that a key control has been operating effectively for six months. However, a recent audit revealed a material weakness. Which of the following is the MOST likely reason?
Easy1015A risk practitioner is facilitating a risk identification workshop for a retail bank's new real-time payments service. Business stakeholders keep proposing controls such as multifactor authentication and transaction limits as 'risks.' Which action BEST keeps the identification phase technically sound?
Hard1016A multinational corporation operates in 15 countries with decentralized control monitoring systems. Each regional office uses different tools and processes for monitoring operational risks. The corporate risk team has consolidated quarterly reports, but the board recently raised concerns about inconsistencies and late identification of emerging risks. A root cause analysis revealed that regional monitoring teams define key risk indicators (KRIs) differently and report on different timeframes. Additionally, there is no centralized platform to aggregate data. The risk manager must recommend a solution that balances local autonomy with global visibility. Which option is the most effective?
Hard1017In a qualitative risk assessment using a 5x5 heat map, an IT risk is rated with likelihood 4 and impact 5. According to typical heat map conventions (5=Critical, 4=High, 3=Medium, 2=Low, 1=Informational), what is the overall risk rating?
Hard1018An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)
Easy1019A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)
Hard1020An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:
Easy1021A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?
Medium1022A risk manager is using the FAIR model to quantify cyber risk. After analyzing a ransomware scenario, the probable loss event frequency (LEF) is estimated at 0.2 per year, and the probable loss magnitude (LM) is $5 million. What is the annualized loss expectancy (ALE) in this scenario?
Hard1023A retail company is conducting a risk assessment for its new e-commerce platform. The assessment team is identifying inherent risks and wants to ensure they consider both internal and external factors that could increase the likelihood of a risk event. Which TWO of the following are examples of external factors that can increase inherent risk? (Choose two.)
Medium1024A multinational retailer operates in a jurisdiction that requires all payment data to remain within national borders. The risk practitioner is asked to verify that a newly deployed cloud payment service complies with this requirement before it goes live. Which activity best provides this assurance?
Medium1025A financial services firm's IT risk register shows that a legacy payment gateway has a high inherent risk of data breach. Management decides to purchase a cyber insurance policy that covers up to $5 million per incident, while keeping the gateway in production unchanged. Which risk response option has management chosen?
Medium1026Match each compliance framework to its primary focus.
Medium1027An internal audit found that a control designed to prevent duplicate payments was bypassed in 5% of transactions. The control owner argues that the control is still effective because the bypass rate is low. What is the BEST response from a risk perspective?
Medium1028An organization is updating its IT risk universe. Which of the following is the MOST important factor to consider when defining the universe?
Medium1029A multinational retailer's risk committee is reviewing its risk register. The CISO argues that a newly identified vulnerability in the point-of-sale system should be escalated immediately to the board. The risk manager notes that the vulnerability has a low likelihood of exploitation and existing compensating controls reduce the impact to a tolerable level. Which of the following is the MOST appropriate action for the risk manager to take?
Hard1030You are the IT risk manager for a mid-sized e-commerce company that processes over 10,000 transactions per day. The company recently migrated its customer database from an on-premises SQL Server to a cloud-based PostgreSQL instance on AWS RDS. The database contains personally identifiable information (PII) including names, addresses, and credit card numbers (stored as encrypted tokens). The migration was performed by the DevOps team with minimal involvement from the security team. Two weeks after the migration, the company experienced a data breach where an attacker exfiltrated a subset of customer records. The forensic investigation revealed that the attacker exploited a misconfigured security group that allowed inbound traffic from the internet on port 5432 (PostgreSQL default port). Additionally, the database had a publicly accessible endpoint, and the master user password was weak (eight characters, no special characters). The attacker used a brute-force attack to guess the password. The security group has since been corrected, and the password has been changed to a strong one. The breach notification laws require reporting within 72 hours. The CEO wants to understand the root cause and prevent recurrence. As the risk manager, which of the following actions should you recommend as the MOST effective to prevent a similar incident?
Hard1031Which TWO of the following are key attributes of effective risk reporting?
Easy1032An organization is designing a risk indicator monitoring program for its key financial risks. Which of the following is the BEST example of a key risk indicator (KRI) for credit risk?
Easy1033A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?
Hard1034A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:
Medium1035Which of the following is a limitation of quantitative risk analysis?
Easy1036A software development company is assessing risks related to its cloud infrastructure. The risk team uses a qualitative approach and creates a risk register. During a review, the team notices that a risk related to unauthorized access to customer data has a likelihood rating of 4 (on a 5-point scale) and an impact rating of 5. The risk owner decides to implement multi-factor authentication (MFA) and role-based access control (RBAC). After implementation, the likelihood rating is reduced to 2, while impact remains 5. What is the PRIMARY purpose of updating the risk register with these new ratings?
Medium1037A risk practitioner is assessing the security of an organization's use of public cloud infrastructure. The organization stores sensitive data in object storage buckets. Which TWO of the following are the MOST significant risks related to misconfigured cloud storage? (Choose two.)
Hard1038A hospital's radiology department wants to let referring physicians upload imaging orders through a new web portal that stores protected health information (PHI). The risk practitioner must ensure the portal meets the HIPAA Security Rule. Which of the following is the MOST appropriate control to implement first?
Medium1039During a risk assessment for a critical financial application, the IT risk manager identifies a vulnerability in the application's authentication module. The exploit would require authenticated access. Which risk rating is most appropriate if the vulnerability has a CVSS base score of 9.0, but the application is behind a strong firewall and requires two-factor authentication?
Easy1040When integrating IT risk into the enterprise risk management (ERM) program, what is the PRIMARY benefit?
Easy1041A hospital's IT risk register lists a risk that its medical imaging archive could become unavailable. The risk owner has documented the risk, set a review date, and decided to take no action because the potential impact is within the hospital's risk appetite. Which risk treatment option has the risk owner selected?
Easy1042After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:
Easy1043An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?
Easy1044A hospital network is identifying IT risks for its newly deployed medical imaging archive. The risk practitioner wants to document risks in a way that links each risk to the business process it could disrupt. Which CRISC concept is the practitioner applying when connecting an IT risk to the business objective it threatens?
Easy1045You are a risk analyst for a financial institution that uses a legacy mainframe system for core banking transactions. The mainframe is critical for daily operations, but it is no longer supported by the vendor. The system has known vulnerabilities that cannot be patched due to compatibility issues. The institution has a risk appetite that is very low for any disruption to core banking services. Recently, there was a minor outage caused by a hardware failure, which was resolved quickly, but it highlighted the system's fragility. The IT director proposes to migrate to a modern system, but the migration will take 2 years and cost $5 million. The board is concerned about the cost and timeline. You need to recommend an immediate risk treatment to reduce the likelihood of a major outage while the migration is underway. Which of the following is the BEST course of action?
Medium1046When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?
Medium1047Which of the following threat actors is MOST likely to be motivated by financial gain and possess moderate to high technical capabilities?
Medium1048In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?
Medium1049Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)
Hard1050After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:
Hard1051A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)
Hard1052When prioritizing risk treatment actions, which factor is most important to consider alongside the risk level?
Easy1053An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?
Medium1054A risk practitioner at a regional hospital is building a risk register entry for the loss of availability of the electronic health record (EHR) system. The CIO asks which element of the risk scenario establishes the frequency with which the loss event is expected to occur so that the register can be prioritized against other entries. Which component of the risk scenario should the practitioner document?
Medium1055A retail company is migrating its e-commerce order database to a public cloud provider. The database stores customer names, addresses, and partial payment card numbers. The risk practitioner must determine who is accountable for protecting this data once it resides with the provider. Which of the following principles BEST guides this determination?
Easy1056Which THREE of the following are key components of an effective risk response plan?
Medium1057A hospital uses a patient portal that allows patients to access their medical records. The portal has experienced multiple brute-force login attempts. The risk manager wants to identify the most critical risk scenario. Which of the following should be prioritized?
Medium1058A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:
Hard1059During a control monitoring review, it is discovered that a detective control has a high false positive rate. What is the MOST significant impact of this issue?
Easy1060A control monitoring system generates an alert when transaction volumes exceed 10,000 per hour. Recently, the system has been generating false positives during peak business hours due to legitimate seasonal spikes. Which of the following is the BEST approach to reduce false positives while maintaining effective monitoring?
Medium1061A risk manager is using the FAIR model to quantify cyber risk. Which of the following inputs is MOST directly used to calculate probable financial loss?
Medium1062An organization uses a Key Control Indicator (KCI) to measure control effectiveness. The KCI shows a control deficiency rate of 12% over the past quarter, exceeding the target threshold of 5%. Which action is MOST appropriate as an initial response?
HardOther domains
All CRISC exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CRISC exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 1062 scenario questions questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.