Isaca IT Risk Fundamentals Practice Test - Questions Answers, Page 7
List of questions
Related questions
Which of the following is MOST important to include when developing a business case for a specific risk response?
Stakeholders responsible for the risk response plan
Communication and status reporting of the related risk
A justification for the expense of the investment
Risk monitoring is MOST effective when it is conducted:
following changes to the business's environment.
before and after completing the risk treatment plan.
throughout the risk treatment planning process.
Which of the following is a valid source or basis for selecting key risk indicators (KRIs)?
Historical enterprise risk metrics
Risk workshop brainstorming
External threat reporting services
When selecting a key risk indicator (KRI), it is MOST important that the KRI:
supports established KPIs.
produces multiple and varied results.
is a reliable predictor of the risk event.
The MOST important reason for developing and monitoring key risk indicators (KRIs) is that they provide:
measurable metrics for acceptable risk levels.
information about control compliance.
an early warning of possible risk materialization.
A key risk indicator (KRI) is PRIMARILY used for which of the following purposes?
Optimizing risk management
Predicting risk events
Facilitating dashboard reporting
An enterprise is currently experiencing an unacceptable 8% processing error rate and desires to manage risk by establishing a policy that error rates cannot exceed 5%. In addition, management wants to be alerted when error rates meet or exceed 4%. The enterprise should set a key performance indicator (KPI) metric at which of the following levels?
5%
4%
8%
Which of the following is the MOST important aspect of key performance indicators (KPIs)?
KPIs identify underperforming assets that may impact the achievement of operational goals.
KPIs provide inputs for monitoring the usage of IT assets to determine return on investment (ROI).
KPIs aid management in monitoring the organization's IT infrastructure capacity.
Which of the following is the PRIMARY reason for an organization to monitor and review l&T-related risk periodically?
To address changes in external and internal risk factors
To ensure risk is managed within acceptable limits
To facilitate the timely identification and replacement of legacy IT assets
As part of the control monitoring process, frequent control exceptions are MOST likely to indicate:
excessive costs associated with use of a control.
misalignment with business priorities.
high risk appetite throughout the enterprise.
Question