
Certified in the Governance of Enterprise IT
Domain 4Objective 7
Risk Assessment Methods CGEIT Practice Questions (Page 3)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
30questions here
6free pages
8concepts
19%of the exam
Questions 11–15
- 11
Which of the following is a widely recognized risk assessment framework that provides principles and guidelines for risk management, applicable to enterprise IT governance?
Select an answer first - 12
Which technique is commonly used in quantitative risk assessment to model the range of possible outcomes by running many simulations with random inputs?
Select an answer first - 13
A large enterprise is assessing the risk of a cyberattack on its critical infrastructure. The risk team has detailed data on the frequency of attacks and the cost per incident, but the data is highly variable. The board wants a single number to represent the annualized loss expectancy (ALE) to use in budget planning. However, the risk team is concerned that a single ALE may not capture the variability. What is the best way to address this concern?
Select an answer first - 14
A risk assessment has produced a list of risks with both qualitative ratings (high/medium/low) and quantitative ALE values. The executive team is divided: some prefer the simplicity of the qualitative ratings, while others want the financial detail of ALE. What is the best way to present the results to satisfy both groups?
Select an answer first - 15
An enterprise IT governance team is initiating a risk assessment for a new cloud migration project. The project sponsor wants the assessment completed within two weeks to meet a regulatory deadline. The team has limited historical data on cloud-related incidents. What is the most appropriate first step in conducting the risk assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.