Q: 17
Within a governance structure for risk management, which of the following activities should be
performed by the second line of defense?
Options
Discussion
A isn't it. Pretty sure it's C, saw this on a recent practice.
D Identifying and assessing risk seems like second line work in some orgs, especially when the boundaries blur with risk management teams.
Probably D, since identifying and assessing risk is often tied to the second line's responsibilities.
C is right here. In the three lines of defense model, the second line like risk or compliance monitors how risks and controls are managed, not the hands-on implementation or audits. Saw a similar question on a practice test.
Pretty sure it's D. Contract monitoring means you’re actually checking if suppliers are meeting the agreed SLAs, which targets the downtime issue. Still not 100% sure, anyone else ran into similar questions?
Be respectful. No spam.
Question 17 of 35