1.
Which of the following statements are true regarding the use of heat maps as risk assessment tools? 1. They focus primarily on known risks, limiting the ability to identify new risks. 2. They rely heavily on objective assessments and related risk tolerances. 3. They are too complex to provide an easily understandable view of key risks. 4. They are helpful but limited in value in a rapidly changing environment.
2.
The most important reason to use risk assessment in audit planning is to:
3.
In creating a risk-based plan, which of the following best describes a top-down approach to understanding business processes?
4.
Which of the following are typical responsibilities for operational management within a risk management program? 1. Implementing corrective actions to address process deficiencies. 2. Identifying shifts in the organization's risk management environment. 3. Providing guidance and training on risk management processes. 4. Assessing the impact of mitigation strategies and activities.
5.
Which of the following statements about COBIT is not true?
6.
In order to provide useful information for an organization's risk management decisions, which of the following factors is least important to assess?