
Certified in the Governance of Enterprise IT
Domain 4Objective 6
Risk Management Lifecycle CGEIT Practice Questions (Page 3)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
32questions here
7free pages
8concepts
19%of the exam
Questions 11–15
- 11
Which of the following is an example of a risk identification activity?
Select an answer first - 12
An organization has decided to mitigate the risk of phishing attacks by implementing multi-factor authentication (MFA) and conducting security awareness training. The risk response plan has been approved. Which of the following activities is part of the risk response implementation phase?
Select an answer first - 13
A company's risk register contains three risks with the following annualized loss expectancies (ALE): Risk A = $50,000, Risk B = $120,000, Risk C = $80,000. The company's risk appetite allows for a maximum annual loss of $100,000 from all risks combined. The risk manager must prioritize responses. Which risk should be addressed first?
Select an answer first - 14
Which of the following is an output of the risk analysis phase?
Select an answer first - 15
An organization is analyzing risks to its customer database. For a specific risk of data corruption, the risk team has determined that the impact would be $100,000 and the likelihood is 20% per year. However, the team is uncertain about the accuracy of the likelihood estimate because there is limited historical data. Which approach would best improve the quality of the risk analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.