Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Isaca IT-Risk-Fundamentals - IT Risk Fundamentals Certificate Exam

Page: 1 / 4
Total 118 questions

A business impact analysis (BIA) generates the MOST benefit when:

A.

keeping impact criteria and cost data as generic as possible.

B.

measuring existing impact criteria exclusively in financial terms.

C.

using standardized frequency and impact metrics.

Which of the following is the PRIMARY concern with vulnerability assessments?

A.

Threat mitigation

B.

Report size

C.

False positives

To be effective, risk reporting and communication should provide:

A.

risk reports to each business unit and groups of employees.

B.

the same risk information for each decision-making stakeholder.

C.

stakeholders with concise information focused on key points.

Which risk response option has been adopted when an enterprise outsources disaster recovery activities to leverage the skills and expertise of a third-party provider?

A.

Risk mitigation

B.

Risk avoidance

C.

Risk transfer

Which of the following is the MOST important factor to consider when developing effective risk scenarios?

A.

Risk events that affect both financial and strategic objectives

B.

Previously materialized risk events impacting competitors

C.

Real and relevant potential risk events

Which of the following is the BEST way to interpret enterprise standards?

A.

A means of implementing policy

B.

An approved code of practice

Q Documented high-level principles

Key risk indicators (KRIs) are metrics designed to:

A.

alert there is an increased chance of exceeding risk appetite.

B.

be a direct measure of risk for each business line.

C.

measure current risk levels in comparison to past levels.

Which of the following is the MOST important aspect of key performance indicators (KPIs)?

A.

KPIs identify underperforming assets that may impact the achievement of operational goals.

B.

KPIs provide inputs for monitoring the usage of IT assets to determine return on investment (ROI).

C.

KPIs aid management in monitoring the organization's IT infrastructure capacity.

Which of the following is combined with risk impact to determine the level of risk?

A.

Threat level

B.

Likelihood

C.

Vulnerability score

What is the PRIMARY purpose of providing timely and accurate risk information to key stakeholders?

A.

To establish risk appetite

B.

To facilitate risk-based decision making

C.

To develop effective key risk indicators (KRIs)