
Certified in the Governance of Enterprise IT
Domain 4Objective 6
Risk Management Lifecycle CGEIT Practice Questions (Page 5)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
32questions here
7free pages
8concepts
19%of the exam
Questions 21–25
- 21
A healthcare provider is implementing a new patient portal that will store sensitive health data. During the risk identification phase, the risk team has listed several potential risks. Which of the following is the most appropriate example of a risk to include in the risk register?
Select an answer first - 22
An organization conducts an annual risk management process review. They find that the risk identification phase consistently misses risks related to third-party vendors. What is the most effective way to apply continuous improvement to this issue?
Select an answer first - 23
What is the primary purpose of the risk response implementation phase?
Select an answer first - 24
A retail company has identified a high-impact, high-likelihood risk of a distributed denial-of-service (DDoS) attack on its e-commerce site. The risk is above the company's risk tolerance. The risk manager is considering response options. Which response strategy would be most effective in reducing the risk to an acceptable level?
Select an answer first - 25
A manufacturing company is analyzing risks to its ERP system. The risk team has identified a potential ransomware attack. They estimate that if the attack occurs, the company would lose $5 million in revenue and incur $1 million in recovery costs. Based on historical data and threat intelligence, they assess the likelihood of occurrence at 10% per year. What is the annualized loss expectancy (ALE) for this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.