Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Isaca IT Risk Fundamentals Certificate IT-Risk-Fundamentals Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam IT-Risk-Fundamentals Premium Access

View all detail and faqs for the IT-Risk-Fundamentals exam


355 Students Passed

86% Average Score

98% Same Questions
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which of the following is the BEST indication of a good risk culture?

Options:

A.

The enterprise learns from negative outcomes and treats the root cause.

B.

The enterprise enables discussions of risk and facts within the risk management functions.

C.

The enterprise places a strong emphasis on the positive and negative elements of risk.

Questions # 2:

When selecting a key risk indicator (KRI), it is MOST important that the KRI:

Options:

A.

supports established KPIs.

B.

produces multiple and varied results.

C.

is a reliable predictor of the risk event.

Questions # 3:

Which of the following is the PRIMARY objective of vulnerability assessments?

Options:

A.

To determine the best course of action based on the threat and potential impact

B.

To improve the knowledge of deficient control conditions within IT systems

C.

To reduce the amount of effort to identify and catalog new vulnerabilities

Questions # 4:

To address concerns of increased online skimming attacks, an enterprise is training the software development team on secure software development practices. This is an example of which of the following risk response strategies?

Options:

A.

Risk acceptance

B.

Risk avoidance

C.

Risk mitigation

Questions # 5:

What is the PRIMARY purpose of providing timely and accurate risk information to key stakeholders?

Options:

A.

To establish risk appetite

B.

To facilitate risk-based decision making

C.

To develop effective key risk indicators (KRIs)

Questions # 6:

Which types of controls are designed to avoid undesirable events, errors, and other adverse occurrences?

Options:

A.

Corrective controls

B.

Detective controls

C.

Preventive controls

Questions # 7:

Which of the following BEST supports a risk-aware culture within an enterprise?

Options:

A.

Risk issues and negative outcomes are only shared within a department.

B.

The enterprise risk management (ERM) function manages all risk-related activities.

C.

Risk is identified, documented, and discussed to make business decisions.

Questions # 8:

Which of the following is important to ensure when validating the results of a frequency analysis?

Options:

A.

Estimates used during the analysis were based on reliable and historical data.

B.

The analysis was conducted by an independent third party.

C.

The analysis method has been fully documented and explained.

Questions # 9:

Which of the following is MOST important for the determination of I&T-related risk?

Options:

A.

The impact on the business services that the IT system supports

B.

The likelihood of occurrence for most relevant risk scenarios

C.

The impact on competitors in the same industry

Questions # 10:

Which of the following are control conditions that exist in IT systems and may be exploited by an attacker?

Options:

A.

Cybersecurity risk scenarios

B.

Vulnerabilities

C.

Threats

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.