
Certified in the Governance of Enterprise IT
Domain 4Objective 5
Business Risk, Exposures and Threats CGEIT Practice Questions (Page 2)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
26questions here
6free pages
7concepts
19%of the exam
Questions 6–10
- 6
Which combination of factors typically results in the highest risk significance?
Select an answer first - 7
A manufacturing company's leadership is reviewing its risk register. The CISO warns that a recent ransomware campaign has targeted industrial control systems (ICS) in the sector. The company's ICS are isolated from the internet but share a network with the corporate IT environment. Which threat should the risk team assess as the most likely vector for a ransomware attack on the ICS?
Select an answer first - 8
Which threat category is most directly concerned with the failure of internal processes or systems?
Select an answer first - 9
A software company is assessing the risk of a critical vulnerability in its legacy customer database. The vulnerability is known and exploits are publicly available. The database contains sensitive customer information. The company has not yet patched the system. What is the most appropriate immediate action for the risk team?
Select an answer first - 10
Which of the following is an example of a strategic threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.