1.
Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?
2.
Which of the following is the MAIN reason for documenting the performance of controls?
3.
Which of the following is the MOST important element of a successful risk awareness training program?
4.
Whether the results of risk analysis should be presented in quantitative or qualitative terms should be based PRIMARILY on the:
5.
Which of the following will BEST quantify the risk associated with malicious users in an organization?
6.
Which of the following risk management practices BEST facilitates the incorporation of IT risk scenarios into the enterprise-wide risk register?
7.
Which of the following is the MOST important key performance indicator (KPI) to establish in the service agreement (SLA) for an outsourced data center?
8.
From a business perspective, which of the following is the MOST important objective of a disaster recovery test?
9.
Which of the following roles would provide the MOST important input when identifying IT risk scenarios?
10.
Accountability for a particular risk is BEST represented in a: