Which of the following is the way to verify control effectiveness?
Answer and explanation
Correct answer: A
A--Explanation: Control effectiveness requires a process to verify that the control process worked as intended and meets the intended control objectives. Hence the test result of intended objective helps in verifying effectiveness of control.
Question 2
Which of the following should be done FIRST when a new risk scenario has been identified?
Answer and explanation
Correct answer: D
D
Question 3
Which of the following is MOST important to update when an organization’s risk appetite changes?
Answer and explanation
Correct answer: C
C
Question 4
You are the risk professional of your enterprise. You need to calculate potential revenue loss if a certain risks occurs.
Your enterprise has an electronic (e-commerce) web site that is producing US $1 million of revenue each day, then if a denial of service (DoS) attack occurs that lasts half a day creates how much loss?
Answer and explanation
Correct answer: C
C--Explanation: Denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts of person or persons to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root name-servers. The term is generally used with regards to computer networks, but is not limited to this field; for example, it is also used in reference to CPU resource management. As the total revenue of the website for the day is $1 million, and due to denial of service attack it is unavailable for half day. Therefore, Revenue loss = $1,000,000/2 = $500,000
Question 5
Multiple answers
You work as a Project Manager for Company Inc. You have to conduct the risk management activities for a project. Which of the following inputs will you use in the plan risk management process? Each correct answer represents a complete solution. (Choose three.)
Answer and explanation
Correct answers: A, C, D
A,C,D
Question 6
Which of the following is an acceptable method for handling positive project risk?
Answer and explanation
Correct answer: D
Explanation: Exploit is a method for handling positive project risk.
Question 7
As part of an overall IT risk management plan, an IT risk register BEST helps management:
Answer and explanation
Correct answer: B
B
Question 8
Which of the following statements BEST describes policy?
Answer and explanation
Correct answer: A
A--Explanation: A policy is an executive mandate which helps in identifying a topic that contains particular risks to avoid or prevent. Policies are high-level documents signed by a person of high authority with the power to force cooperation. The policy is a simple document stating that a particular high-level control objective is important to the organization's success. Policies are usually only one page in length. The authority of the person mandating a policy will determine the scope of implementation. Hence in other words, policy is an overall statement of information security scope and direction.
Question 9
The Identify Risk process determines the risks that affect the project and document their characteristics.
Why should the project team members be involved in the Identify Risk process?
Answer and explanation
Correct answer: A
A--Explanation: The project team members should be involved in the risk identification so that they will develop a sense of ownership and responsibility for the risk events and the associated risk responses. Identify Risks is the process of determining which risks may affect the project. It also documents risks' characteristics. The Identify Risks process is part of the Project Risk Management knowledge area. As new risks may evolve or become known as the project progresses through its life cycle, Identify Risks is an iterative process. The process should involve the project team so that they can develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions. Risk Register is the only output of this process.
Question 10
Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?