
Certified Information Systems Auditor
Domain 2Objective 2
Risk and Compliance Management CISA Practice Questions (Page 6)
Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.
31questions here
7free pages
8concepts
18%of the exam
Questions 26–30
- 26
A large enterprise is implementing a data governance program. The data governance committee has approved a new data classification policy. The IT department is now responsible for enforcing the policy. Which of the following is the MOST critical component for the IT department to implement to ensure the policy is effective?
Select an answer first - 27
An organization has implemented a privacy program and appointed a Data Protection Officer (DPO). The DPO is responsible for monitoring compliance. During a routine audit, the DPO discovers that the marketing department has been collecting customer data without a lawful basis for processing. Which of the following is the MOST appropriate action for the DPO to take?
Select an answer first - 28
Which risk response option involves taking action to reduce the likelihood or impact of a risk?
Select an answer first - 29
An organization is conducting a risk assessment for a new customer relationship management (CRM) system that will store sensitive customer data. The risk team has identified several risks, including unauthorized access, data loss, and system downtime. The team is now prioritizing the risks for treatment. Which of the following is the MOST appropriate approach for prioritizing these risks?
Select an answer first - 30
Which statement best describes the role of risk appetite in an enterprise risk management (ERM) framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.