Question 1
An organization has implemented a preventive control to lock user accounts after three unsuccessful login attempts. This practice has been proven to be unproductive, and a change in the control threshold value has been recommended. Who should authorize changing this threshold?
Question 2
Which of the following should be the risk practitioner s PRIMARY focus when determining whether controls are adequate to mitigate risk?
Question 3
Which of the following BEST enables the identification of trends in risk levels?
Question 4
Which of the following would be MOST helpful when communicating roles associated with the IT risk management process?
Question 5
Implementing which of the following controls would BEST reduce the impact of a vulnerability that has been exploited?
