Exit demo IT-RISK-FUNDAMENTALS IT Risk Fundamentals Certificate PDF format · free preview

Isaca IT-RISK-FUNDAMENTALS - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/it-risk-fundamentals.html

Question 1
Single choice

An alert generated when network bandwidth usage exceeds a predefined level is an example of a:

A.

threat.

B.

risk event.

C.

lag indicator.

D.

key risk indicator (KRI).

Question 2
Single choice

Which of the following is the objective of a frequency analysis?

A.

To determine how often risk mitigation strategies should be evaluated and updated within a specific timeframe

B.

To determine how many risk scenarios will impact business objectives over a given period of time

C.

To determine how often a particular risk scenario might be expected to occur during a specified period of time

Question 3
Single choice

Risk monitoring is MOST effective when it is conducted:

A.

following changes to the business's environment.

B.

before and after completing the risk treatment plan.

C.

throughout the risk treatment planning process.

Question 4
Single choice

Which of the following is an example of an inductive method to gather information?

A.

Vulnerability analysis

B.

Controls gap analysis

C.

Penetration testing

Question 5
Single choice

An enterprise's risk policy should be aligned with its:

A.

current risk.

B.

risk capacity.

C.

risk appetite.

Question 6
Single choice

What is the basis for determining the sensitivity of an IT asset?

A.

Potential damage to the business due to unauthorized disclosure

B.

Cost to replace the asset if lost, damaged, or deemed obsolete

C.

Importance of the asset to the business

Question 7
Single choice

Which of the following is the BEST way to minimize potential attack vectors on the enterprise network?

A.

Implement network log monitoring.

B.

Disable any unneeded ports.

C.

Provide annual cybersecurity awareness training.

Question 8
Single choice

When evaluating the current state of controls, which of the following will provide the MOST comprehensive analysis of enterprise processes, incidents, logs, and the threat environment?

A.

Enterprise architecture (EA) assessment

B.

IT operations and management evaluation

C.

Third-party assurance review

Question 9
Single choice

Which of the following is a benefit of using a top-down approach when developing risk scenarios?

A.

Focus at the enterprise level makes it easier to achieve management support.

B.

The development process is simplified because it includes only I&T-related events.

C.

Identification and assignment of risk ownership for mitigation plans can be done more quickly.

Question 10
Single choice

Incomplete or inaccurate data may result in:

A.

availability risk.

B.

relevance risk.

C.

integrity risk.

Showing 10 of 118 questions · Unlock the full set