CISM Practice C Topic 2 Flashcards
A risk mitigation report would include recommendations for:
acceptance
A risk management program should reduce risk to:
an acceptable level.
The MOST important reason for conducting periodic risk assessments is because:
security risks are subject to frequent change.
Which of the following BEST indicates a successful risk management practice?
Residual risk is minimized
Which of the following would generally have the GREATEST negative impact on an organization?
Loss of customer confidence
A successful information security management program should use which of the following to determine the amount of resources devoted to mitigating exposures?
Risk analysis results
Which of the following will BEST protect an organization from internal security attacks?
Prospective employee background checks
For risk management purposes, the value of an asset should be based on:
replacement cost.
In a business impact analysis, the value of an information system should be based on the overall cost:
if unavailable.
Acceptable risk is achieved when:
residual risk is minimized.
The value of information assets is BEST determined by:
individual business managers.
During which phase of development is it MOST appropriate to begin assessing the risk of a new application system?
Feasibility
The MOST effective way to incorporate risk management practices into existing production systems is through:
change management.
Which of the following would be MOST useful in developing a series of recovery time objectives (RTOs)?
Business impact analysis
The recovery time objective (RTO) is reached at which of the following milestones?
Restoration of the system
Which of the following results from the risk assessment process would BEST assist risk management decision making?
Residual risk
The decision on whether new risks should fall under periodic or event-driven reporting should be based on which of the following?
Visibility of impact
Risk acceptance is a component of which of the following?
Mitigation
Risk management programs are designed to reduce risk to:
a level that the organization is willing to accept.
A risk assessment should be conducted:
annually or whenever there is a significant change.
The MOST important function of a risk management program is to:
minimize residual risk.
Which of the following risks would BEST be assessed using qualitative risk assessment techniques?
Permanent decline in customer confidence
Which of the following will BEST prevent external security attacks?
Network address translation
In performing a risk assessment on the impact of losing a server, the value of the server should be calculated using the:
cost to obtain a replacement.