10 free sample questions from a bank of 2240, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following is the MOST important reason to maintain key risk indicators (KRIs)?
In order to avoid risk
Complex metrics require fine-tuning
Risk reports need to be timely
Threats and vulnerabilities change over time
Answer: D
2Which of the following controls is an example of non-technical controls?
Access control
Physical security
Intrusion detection system
Encryption
Answer: B
3Which of the following is the MOST important consideration when developing risk strategies?
Long-term organizational goals
Organization's industry sector
Concerns of the business process owners
History of risk events
Answer: A
4Which of the following would BEST facilitate the implementation of data classification requirements?
Implementing technical controls over the assets
Implementing a data loss prevention (DLP) solution
Scheduling periodic audits
Assigning a data owner
Answer: D
5An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning ownership of the associated risk entries?
The volume of risk scenarios is too large.
Risk scenarios are not applicable.
The risk analysis for each scenario is incomplete.
Risk aggregation has not been completed.
Answer: B
6An organization's business process requires the verbal verification of personal information in an environment where other customers may overhear this information. Which of the following is the MOST significant risk?
The customer may view the process negatively.
The information could be used for identity theft.
The process could result in intellectual property theft.
The process could result in compliance violations.
Answer: B
7An organization has initiated a project to launch an IT-based service to customers and take advantage of being the first to market. Which of the following should be of GREATEST concern to senior management?
The project is likely to deliver the product late.
More time has been allotted for testing.
A new project manager is handling the project.
The cost of the project will exceed the allotted budget.
Answer: A
8Which of the following is the MOST important objective of embedding risk management practices into the initiation phase of the project management life cycle?
To deliver projects on time and on budget
To assess inherent risk
To assess risk throughout the project
To include project risk in the enterprise-wide IT risk profile
Answer: C
9Which of the following is the MOST significant indicator of the need to perform a penetration test?
An increase in the number of infrastructure changes
An increase in the number of security incidents
An increase in the number of high-risk audit findings
An increase in the percentage of turnover in IT personnel
Answer: A
10Which of the following provides the MOST reliable information to ensure a newly acquired company has appropriate IT controls in place?