Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

IT-Risk-Fundamentals Exam Dumps - Isaca IT Risk Fundamentals Certificate Questions and Answers

Question # 4

Which of the following is the FIRST step in an advanced persistent threat (APT) attack?

Options:

A.

Identify administrators and crack passwords to obtain administrator access.

B.

Use social engineering to encourage employees to visit an infected website.

C.

Collect information on the infrastructure of an organization to know where to attack.

Buy Now
Question # 5

Which of the following is used to estimate the frequency and magnitude of a given risk scenario?

Options:

A.

Risk analysis

B.

Risk register

C.

Risk governance

Buy Now
Question # 6

Which of the following should be found in an I&T asset inventory to help inform the risk identification process?

Options:

A.

Loss scenario information for assets

B.

Security classification of assets

C.

Regulatory requirements of assets

Buy Now
Question # 7

When should a consistent risk analysis method be used?

Options:

A.

When the goal is to produce results that can be compared over time

B.

When the goal is to aggregate risk at the enterprise level

C.

When the goal is to prioritize risk response plans

Buy Now
Question # 8

An enterprise has moved its data center from a flood-prone area where it had experienced significant service disruptions to one that is not a flood zone. Which risk response strategy has the organization selected?

Options:

A.

Risk mitigation

B.

Risk transfer

C.

Risk avoidance

Buy Now
Question # 9

The MOST important reason for developing and monitoring key risk indicators (KRIs) is that they provide:

Options:

A.

measurable metrics for acceptable risk levels.

B.

information about control compliance.

C.

an early warning of possible risk materialization.

Buy Now
Question # 10

Which of the following presents the GREATEST risk for the continued existence of an enterprise?

Options:

A.

When its risk appetite and tolerance are reviewed annually

B.

When its actual risk eventually exceeds organizational risk appetite

C.

When its risk appetite and actual risk exceed its risk capacity

Buy Now
Question # 11

Which of the following is the BEST indication of a good risk culture?

Options:

A.

The enterprise learns from negative outcomes and treats the root cause.

B.

The enterprise enables discussions of risk and facts within the risk management functions.

C.

The enterprise places a strong emphasis on the positive and negative elements of risk.

Buy Now
Question # 12

Which of the following is the PRIMARY reason to conduct a cost-benefit analysis as part of a risk response business case?

Options:

A.

To determine if the reduction in risk is sufficient to justify the cost of implementing the response

B.

To determine the future resource requirements and funding needed to monitor the related risk

C.

To calculate the total return on investment (ROI) over time and benefit to enterprise risk management (ERM)

Buy Now
Question # 13

Which of the following is a valid source or basis for selecting key risk indicators (KRIs)?

Options:

A.

Historical enterprise risk metrics

B.

Risk workshop brainstorming

C.

External threat reporting services

Buy Now
Exam Name: IT Risk Fundamentals Certificate Exam
Last Update: Feb 22, 2025
Questions: 118
IT-Risk-Fundamentals pdf

IT-Risk-Fundamentals PDF

$25.5  $84.99
IT-Risk-Fundamentals Engine

IT-Risk-Fundamentals Testing Engine

$28.5  $94.99
IT-Risk-Fundamentals PDF + Engine

IT-Risk-Fundamentals PDF + Testing Engine

$40.5  $134.99