Question 366
An IT department has organized training sessions to improve user awareness of organizational information security policies. Which of the following is the BEST key performance indicator (KPI) to reflect effectiveness of the training?
Question 367
In response to the threat of ransomware, an organization has implemented cybersecurity awareness activities.
The risk practitioner's BEST recommendation to further reduce the impact of ransomware attacks would be to implement:
Question 368
Implementing which of the following will BEST help ensure that systems comply with an established baseline before deployment?
Question 369
An organization has raised the risk appetite for technology risk. The MOST likely result would be:
Question 370
An organization with a large number of applications wants to establish a security risk assessment program.
Which of the following would provide the MOST useful information when determining the frequency of risk assessments?
