Graded A+ 2025|2026
1. 01. IT-related risk management activities are
Answer:
MOST ef- fective when they are:
d) integrated within
a) treated as a distinct process
busi- ness processes
b) conducted by the IT department
c)communicated to all employees
d) integrated within business processes
2. 02. A risk assessment and business impact Answer:
analysis (BIA) have been completed for a major
proposed pur- chase and new process for an c) Review of the risk
organization. as- sessment with
There is disagreement between the information executive management
secu- rity manager and the business for final in- put
department manager who will be responsible
for evaluating the results and identified risk.
Which of the following would be the BEST
approach of the information security
manager?
a) Acceptance of the business manager's
decision on the risk to the corporation
b) Acceptance of the information security
manager's decision on the risk to the
corporation
c)Review of the risk assessment with executive
man- agement for final input
d) Create a new risk assessment and BIA to
resolve the disagreement
3. 03. Who is accountable for ensuring that information is Answer:
categorized and that specific protective measures are
taken?
1/
4