100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

D486 ITAS 5225 Governance, Risk & Compliance - OA Review (Qns & Ans) - WGU 2025.

Rating
-
Sold
-
Pages
32
Grade
A+
Uploaded on
09-06-2025
Written in
2024/2025

D486 ITAS 5225 Governance, Risk & Compliance - OA Review (Qns & Ans) - WGU 2025.D486 ITAS 5225 Governance, Risk & Compliance - OA Review (Qns & Ans) - WGU 2025.












Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
June 9, 2025
Number of pages
32
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

D486 ITAS 5225 Governance, Risk, &
Compliance

Objective Assessment Review

(Questions & Solutions)

2025




1

, 1. Case:
A multinational enterprise adopts ISO 31000 as the basis for its risk
management program.
Question: Which of the following best describes the primary focus
of ISO 31000?
a) Providing detailed technical controls for IT systems
b) Establishing principles, framework, and processes for risk
management across the organization
c) Ensuring regulatory compliance through specific procedural
checklists
d) Delivering encryption standards for data protection

Correct ANS: b
Rationale: ISO 31000 is a risk management standard that focuses
on establishing a framework, principles, and processes to help
organizations manage risk holistically rather than prescribing detailed
technical controls.

---

2. Case:
A company is implementing a new GRC program and establishes a
board-level risk committee.
Question: What is the main role of this risk committee?
a) To manage day-to-day IT operations
b) To set the organization’s risk appetite and oversee enterprise‑wide
risk management
c) To implement corrective actions during a security breach
d) To configure technical security controls on network devices

Correct ANS: b
2

, Rationale: A board-level risk committee is primarily responsible for
setting risk appetite, defining frameworks, and providing oversight of
enterprise‑wide risk management, ensuring alignment with strategic
objectives.

---

3. Case:
An organization aligns its information security program with the NIST
Cybersecurity Framework.
Question: Which core function of the NIST Framework focuses on
understanding the organization’s risk context?
a) Protect
b) Identify
c) Respond
d) Recover

Correct ANS: b
Rationale: The “Identify” function is foundational; it focuses on
understanding the business context, asset inventory, risk
assessments, and the overall threat landscape, all of which are
essential for informed decision‑making.

---

4. Case:
A regulated financial institution implements Basel III measures in its
risk management strategy.
Question: What is the primary objective of applying Basel III in a
GRC program?
a) Enhancing encryption protocols for data security
b) Measuring capital adequacy and managing financial risk
c) Ensuring IT asset inventory accuracy
d) Standardizing external audit processes exclusively


3

, Correct ANS: b
Rationale: Basel III is designed to improve the banking sector’s
ability to absorb shocks by focusing on capital adequacy and risk
management, which is critical for a regulated financial environment.

---

5. Case:
An organization develops a risk treatment plan after conducting its
risk assessment.
Question: Which of the following options is not considered a
standard risk treatment strategy?
a) Risk elimination
b) Risk transference
c) Risk mitigation
d) Risk acceptance

Correct ANS: a
Rationale: Standard strategies include risk transference, mitigation,
and acceptance. Although "risk avoidance" is common, "risk
elimination" is often impractical because some risk always remains.

---

6. Case:
A company must manage third-party risks in its supply chain within its
GRC program.
Question: Which method is most effective for managing these
risks?
a) Conducting periodic vendor risk assessments and incorporating
contractual security requirements
b) Limiting communication with vendors entirely
c) Relying solely on internal audit findings
d) Outsourcing all IT functions to external providers


4

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Bankart Chamberlain College of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
150
Member since
2 year
Number of followers
31
Documents
4512
Last sold
1 week ago

3.6

21 reviews

5
9
4
0
3
9
2
1
1
2

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions