Question 501
When a risk cannot be sufficiently mitigated through manual or automatic controls, which of the following options will BEST protect the enterprise from the potential financial impact of the risk?
Question 502
Which of the following is the BEST source for identifying key control indicators (KCIs)?
Question 503
An organization has identified a risk exposure due to weak technical controls in a newly implemented HR system. The risk practitioner is documenting the risk in the risk register. The risk should be owned by the:
Question 504
The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:
Question 505
Which of the following comes under phases of risk management?

