Browse all practice questions for the Risks and Controls Exam 2 Practice. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Conquer Risks and Controls 2026 - Your Ultimate Practice Journey to Mastery! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which of the following describes a phishing attack?
  • When a client's accounts payable computer system was relocated, the administrator provided support through a dial-up connection to a server. Subsequently, the administrator left the company. No changes were made to the accounts payable system at that time. Which of the following situations represents the greatest security risk?
  • In what way does data analytics contribute to risk management?
  • Which of the following is an example of fraudulent financial reporting?
  • What is a risk response plan?
  • The user reviews the outcome of some code. If the outcome is accurate, what stage of the change management process is this?
  • If perceived pressure and opportunity to commit fraud are high and personal integrity is low, then the risk of fraud is?
  • What defines a risk management information system (RMIS)?
  • What are the main types of internal controls?
  • Which factor enhances an organization’s resilience to risks?
  • What is enterprise risk management (ERM)?
  • Which item is not an objective of the IT evaluate, direct, and monitor domain?
  • What is a key benefit of implementing corrective controls?
  • What are the consequences of ineffective internal controls?
  • Which aspect does a positive organizational culture promote?
  • Which of these logical access controls relates to authorization rather than authentication?
  • Define the term "internal control."
  • What does risk evaluation entail?
  • IP spoofing is often used as part of which of the following?
  • What is the purpose of a disaster recovery plan?
  • What is the purpose of encryption in data security?
  • Which of the following is a direct consequence of a breach of confidentiality?
  • Which action should be taken to secure a public Wi-Fi connection?
  • A company's web server has crashed due to a surge of false requests. What type of attack is this indicative of?
  • What does 'risk culture' refer to in an organization?
  • What role do detective controls play in risk management?
  • What role does risk assessment play within organizations?
  • Why is communication important in the internal control process?
  • What are the major classes of asset misappropriation?
  • Why is stakeholder engagement crucial in risk management?
  • Which of the following is a technique used to prevent malware infections?
  • Which of these access roles would you assign to the internal audit manager of a public company?
  • Which of the following technologies is typically used to monitor network traffic and detect intrusions?
  • What is the most widely used international standard for IT governance?
  • Which of the following is a characteristic of effective control activities?
  • Select the statement that is NOT true about COBIT 2019.
  • How do risk financing and risk transfer differ?
  • What does the 'three lines of defense' model represent in risk management?
  • What is one main function of the audit committee?
  • What is the primary goal of risk management in an organization?
  • In risk management, what does 'responding to risks' typically involve?
  • Why is understanding credit risk essential for lending institutions?
  • The inside environment of a data center should include all the following EXCEPT?
  • What identifies active IP addresses while another identifies types of communication occurring on the network?
  • Which of the following is a computer program that appears to be legitimate but performs an illicit action when it is run?
  • What type of risk does outsourcing pertain to?
  • The primary benefit of a cold site compared to a hot site is?
  • What does COSO stand for?
  • Which of the following best describes the purpose of risk assessment?
  • A fraud committed to lessen the amount of earnings that will be taxed this year is an example of?
  • Which measure can assist in assessing cybersecurity risks?
  • What is the difference between eavesdropping and on-path attacks?
  • What is a risk assessment?
  • Which of the following is correct concerning a fraud risk factor?
  • How is 'strategic risk' defined?
  • What primary function does a risk management information system serve?
  • What is a key advantage of using scenario analysis in risk assessment?
  • Which of the following are the key elements of a fraud triangle?
  • What is the primary purpose of a risk management framework?
  • What are key risk indicators (KRIs)?
  • What is an example of a manual control?
  • IP spoofing disguises the source address with which type of IP address?
  • What does compliance risk refer to in an organization?
  • Who plays a pivotal role in a company's cybersecurity program?
  • What does a 'business impact analysis' evaluate?
  • A major difference between skimming and cash larceny is that?
  • What does the term "social engineering" refer to in cybersecurity?
  • What is the significance of risk prioritization in risk management?
  • How is credit risk best described?
  • A security guard opens the door to allow an authenticated person into the data center. A second person enters behind the first person without properly scanning through the security. This method of circumventing physical access controls is called
  • What is required for managing cyber risks?
  • In financial statement fraud, what often happens to overall company performance?
  • The three stages in a change management process, in consecutive order, are?
  • What is the primary function of audits in managing risks?
  • Which of the following best describes ransomware?
  • Which of the following is a characteristic of effective risk management?
  • What does 'legal risk' encompass?
  • What does contingency planning entail?
  • How does the assessment of a key risk indicator (KRI) impact decision-making?
  • Why did Amazon and Google choose to NOT build their new data centers near their headquarters?
  • How are cyberattacks generally classified?
  • What is a key risk indicator (KRI)?
  • Why is maintaining a risk control environment significant?
  • Which of the following describes the purpose of detective controls?
  • What are the main components of the COSO framework for internal controls?
  • What is a common consequence of a successful cyber attack?
  • What characterizes an external audit?
  • Which strategy best describes mitigating risk?
  • What is the primary purpose of an internal audit?
  • What is an example of a detective control?
  • Why is it important for organizations to establish clear risk ownership?
  • What does the acronym 'ERM' stand for?
  • What role does communication play in risk management?
  • Which of these is not a component of fraud?
  • What does the term 'breach of confidentiality' refer to?
  • How does scenario analysis benefit risk assessment?
  • What is the difference between qualitative and quantitative risk assessment?
  • What is typically included in a risk mitigation plan?
  • Which security measure helps to prevent unauthorized access by requiring a user to enter a specific code to gain entry?
  • What is the significance of documentation in the risk management process?
  • What is an essential step during the implementation phase of change management?
  • Only _______ have access to the test environment?
  • Corruption fraud schemes include which of the following?
  • Which factor is essential for creating an effective risk management culture?
  • How can technology mitigate risks within an organization?
  • How is 'fraud risk' defined?
  • In relation to risk management, what is the role of technology?
  • What is a risk register?
  • What role does leadership play in risk management frameworks?
  • Incorrect sender addresses are red flags indicating possible what?
  • What is the significance of external audits in risk management?
  • What are some common types of internal controls?
  • Which technology is typically used to provide redundancy in storage systems?
  • In risk management terminology, what does the term 'control' mean?
  • Which statement is true regarding risk management strategies?
  • Which of the following is not one of the ways that the Equifax hackers hid their suspicious network activity?
  • Which of the following best describes reputational risk?
  • Explain the difference between inherent risk and residual risk.
  • What is involved in 'risk communication'?
  • Womping Wembley Corp. maintains three sets of backups, which are updated monthly, weekly, and daily. This approach illustrates what?
  • Which of the following is not a method of attack used in a full cyberattack?
  • What is a common sign of a successful phishing attack?
  • What is the role of performance indicators in assessing internal controls?
  • What role does organizational culture play in risk management?
  • The element of the fraud triangle that a company has influence over is?
  • Why is the concept of 'risk appetite' important in an organization?
  • Which of the following illustrates a common source of operational risk?
  • What role do corrective controls play in internal controls?
  • Why is it important for stakeholders to be informed about risks?
  • An example of an asset misappropriation scheme is?
  • What is the purpose of a 'risk framework'?
  • Which of the following is true about denial-of-service attacks?
  • What is the purpose of segregation of duties?
  • What is a typical target in cyber fraud related to financial reporting?
  • Which type of malware does not require the user to execute any action to spread?
  • What is termed as 'business continuity planning'?
  • What is the difference between inherent risk and residual risk?
  • What is a control objective?
  • How is 'catastrophic risk' best defined?
  • What role do internal controls serve in preventing cyber risks?
  • Which type of attack do network administrators not have control over preventing?
  • The most difficult asset misappropriation fraud scheme to detect, because it leaves no starting point or audit trail for auditors to investigate, is?
  • Why is training considered important in internal controls?
  • What type of risks does legal risk typically include?
  • Define operational risk.
  • Which is true of the differential backup strategy?
  • Which of the following techniques can be used for authenticating users?
  • What is the primary aim of implementing a backup strategy in a data management system?
  • Which of the following is an example of a brute force attack?
  • What is a potential consequence of failing to manage compliance risk?
  • What methods do organizations use to identify risks?
  • What is the primary effect of effective risk response?
  • What is the role of a control owner?
  • How can risks be effectively mitigated according to the concept of risk layering?
  • What is a key component of an effective disaster recovery plan?
  • What does a risk mitigation strategy aim to achieve?
  • How does a strong internal control system contribute to risk management?
  • What does operational risk refer to?
  • What is the primary difference between a virus and a worm?
  • What does 'segregation of duties' mean in internal controls?
  • What can internal and external audits help identify?
  • What is the term for the fraud in which a company inflates its sales revenue by forcing more products through a distribution channel than it can sell?
  • How often should a risk assessment be conducted?
  • What is the purpose of monitoring activities in the COSO framework?
  • What is market risk defined as?
  • What does risk management primarily aim to protect organizations from?
  • What is the purpose of a risk register?
  • How is 'asset risk' defined?
  • Which of these is NOT an advantage of a hot backup site?
  • What does the term 'risk appetite' refer to?
  • What is the main focus of a business continuity plan?
  • What is a risk assessment?
  • What type of control seeks to avoid a potential risk before it occurs?
  • What is a common challenge in implementing internal controls?
  • What is an example of a preventive control?
  • What should be prioritized when assessing risks?
  • What element is crucial for effective risk communication?
  • What action is an example of a control activity?
  • What does the term 'risk tolerance' refer to?
  • What role does IT play in risk management?
  • What does a risk assessment matrix visually represent?
  • What is the purpose of a risk appetite statement?
  • What is the primary goal of risk monitoring?
  • What is the primary focus of asset risk management?
  • How is 'market risk' defined?
  • What does 'compliance risk' refer to?
  • What does the cybersecurity and infrastructure security agency (CISA) recommend for companies facing ransom demands?
  • Why is regulatory compliance significant in risk management?
  • What does 'risk layering' entail?
  • What significant cybersecurity incident occurred with Equifax in 2017?
  • Which of the following is not typically considered a component of risk management?
  • What is 'fraud risk assessment'?
  • How do organizations typically respond to identified risks?
  • The first behavioral element in the fraud triangle is?
  • "The company is so large it won't even notice it" is a type of?
  • What is an example of pressure to commit financial statement fraud?
  • A controller is developing a disaster recovery plan for a corporation's computer systems in the event of a disaster that makes the company's facilities unusable. What best describes the arrangement of the alternative location with duplicate hardware?
  • What role does monitoring activities play in internal controls?
  • How can organizations assess the effectiveness of their internal controls?
  • What is the importance of the Control Environment in the COSO framework?
  • In risk management, how is 'insurance' defined?
  • What is the significance of implementing risk management strategies?
  • What is the significance of control testing?
  • What is a fundamental aspect of a risk mitigation plan?
  • What is an internal control process primarily designed to do?
  • What constitutes a control activity?
  • How can organizations effectively mitigate the risk of cybersecurity threats?
  • Which of the following is a common pitfall in risk management?
  • What is one benefit of conducting thorough risk assessments regularly?
  • What is meant by 'strategic risk'?
  • What does a business continuity plan outline?
  • Which of the following scenarios is NOT an example of a behavioral red flag?
  • What is a control activity in the context of internal controls?
  • Which of the following techniques enhances financial statement reliability?
  • Which analysis helps organizations prepare for disruptions?
  • What does 'continuous improvement' refer to in risk management?
  • In polite tailgating, what action does the authorized user take?
  • Describe the concept of 'risk tolerance.'
  • In what way can risk communication enhance risk management practices?
  • What is the role of top management in risk management?
  • Elenor Rigby's crematorium and pet custodian services wants to choose the strongest control method for accessing its systems. Elenor should choose
  • What is assessed during an internal audit?
  • What is one key benefit of conducting a thorough risk assessment?
  • What is the purpose of internal controls?
  • How does insurance act as a risk management strategy?
  • What is 'reputational risk'?
  • What are the key components of risk management?
  • Which of the following best describes monitoring in risk management?
  • What is a key function of risk management within an organization?
  • What is the primary purpose of risk management in organizations?
  • How can organizations effectively mitigate risks?
  • Which of the following best characterizes the function of a physical access control?
  • What is the primary role of the audit committee in risk management?
  • What effect can a breach of cybersecurity have on a company's reputation?
  • What is the key responsibility of management in risk management?
  • One important purpose of COBIT is to
  • Which of the following describes a method that involves manipulating a user into providing sensitive information?
  • What is meant by 'third-party risk'?
  • Information about phishing attempts that rely on social engineering should be communicated to which group?
  • Which method is frequently used to determine the likelihood and impact of risks?
  • What does effective risk communication lead to?
  • A strong network password is best represented by which of the following examples?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy