Topic 2 : Pool B Jul-Aug-Sep
Prudent business practice requires that risk appetite not exceed:
A.
inherent risk.
B.
risk tolerance.
C.
risk capacity.
D.
residual risk.
risk capacity.
The number of tickets to rework application code has significantly exceeded the established threshold. Which
of the following would be the risk practitioner s BEST recommendation?
A.
Perform a root cause analysis
B.
Perform a code review
C.
Implement version control software.
D.
Implement training on coding best practices
Perform a root cause analysis
An organization has determined a risk scenario is outside the defined risk tolerance level. What should be the
NEXT course of action?
A.
Develop a compensating control.
B.
Allocate remediation resources.
C.
Perform a cost-benefit analysis.
D.
Identify risk responses
Identify risk responses
The MOST significant benefit of using a consistent risk ranking methodology across an organization is that it
enables:
A.
allocation of available resources
B.
clear understanding of risk levels
C.
assignment of risk to the appropriate owners
D.
risk to be expressed in quantifiable terms
clear understanding of risk levels
Which of the following is MOST important to understand when determining an appropriate risk assessment
approach?
A.
Complexity of the IT infrastructure
B.
Value of information assets
C.
Management culture
D.
Threats and vulnerabilities
Complexity of the IT infrastructure
Page 27 out of 193 Pages |
Previous |