Podcast
Questions and Answers
According to the COSO framework, which component involves selecting risk responses and monitoring performance?
According to the COSO framework, which component involves selecting risk responses and monitoring performance?
- Risk assessment
- Control activities
- Information and communication
- Risk response (correct)
What is the purpose of the review and revision component in the COSO framework?
What is the purpose of the review and revision component in the COSO framework?
- To identify and analyze potential cyber risks facing the organization
- To select appropriate risk responses based on the organization's risk appetite
- To gather relevant information from internal and external sources for risk management
- To assess the value proposition of cyber risk management capabilities and drive value as change occurs (correct)
Which component of the COSO framework is responsible for gathering information from internal and external sources to support cyber risk management?
Which component of the COSO framework is responsible for gathering information from internal and external sources to support cyber risk management?
- Control environment
- Monitoring activities
- Risk assessment
- Information and communication (correct)
What does COSO recommend regarding the integration of its ERM framework?
What does COSO recommend regarding the integration of its ERM framework?
What is the purpose of preventive controls in the context of cyber risk mitigation?
What is the purpose of preventive controls in the context of cyber risk mitigation?
Which of the following is NOT a characteristic of effective options (choices/distractors) in multiple-choice questions?
Which of the following is NOT a characteristic of effective options (choices/distractors) in multiple-choice questions?
According to the guidelines provided, which of the following should be avoided when constructing the stem (question) of a multiple-choice item?
According to the guidelines provided, which of the following should be avoided when constructing the stem (question) of a multiple-choice item?
What is the recommended approach for representing common student misconceptions in multiple-choice questions?
What is the recommended approach for representing common student misconceptions in multiple-choice questions?
Which component of the COSO framework takes a holistic, portfolio-centric view of organizational and cyber risk?
Which component of the COSO framework takes a holistic, portfolio-centric view of organizational and cyber risk?
What is the purpose of detective controls in the context of cyber risk mitigation?
What is the purpose of detective controls in the context of cyber risk mitigation?