Practice ISC Risk Management questions with full explanations on every answer.
Start practicing
Risk Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which document is the primary source for defining the 'Risk Appetite' of an enterprise?
2You are performing a qualitative risk assessment. Which factor must be prioritized to ensure the assessment is aligned with the organizational risk appetite?
3You are integrating an enterprise risk register with a GRC tool (e.g., Archer). Which method provides the most accurate view of 'Residual Risk' to the board?
4Your organization adopts the NIST CSF 2.0. Which specific function should be assessed to identify gaps in your enterprise risk management program's Governance component?
5You are managing third-party risk. Which tool or method is most appropriate for a continuous assessment of a cloud service provider (CSP)?
6A Chief Risk Officer is utilizing the FAIR framework to quantify cyber risk. Which input is required to calculate the Loss Event Frequency?
7When integrating risk management with the SDLC, which activity represents the most effective 'Shift-Left' approach to mitigate design-level risk?
8When reporting risk to the Board of Directors, which metric is most effective for demonstrating the value of an investment in a new EDR solution?
9Which risk response strategy is being employed when a company purchases cyber insurance?
10A risk assessment reveals that a legacy system stores PII without encryption. The business cannot replace it. What is the most appropriate risk management action?
11Which of the following is a 'Key Risk Indicator' (KRI) for an organization's email security program?
12Which of the following best describes the 'Risk Management Framework' (RMF) process step of 'Assess'?
13In the context of ISO 31000, what is the primary purpose of 'Risk Communication and Consultation'?
14When executive leadership discusses 'Acceptable Risk', they are referring to:
15An ISSMP is reviewing an organizational risk register. Which field is essential for effective risk prioritization?
16Your organization is performing a supply chain risk assessment. Which factor is most critical when evaluating a critical software vendor?
17During a merger, you identify two different risk assessment methodologies. What is the best strategy for the ISSMP?
18What is the primary objective of a Business Impact Analysis (BIA)?
19Which of the following is an example of a detective control in a risk management program?
20An enterprise is moving to a 'Zero Trust' architecture. How does this impact the risk assessment process?
21You are utilizing a quantitative risk analysis. What is the 'SLE' in the context of an ARO-based calculation?
22An organization is concerned about 'Cloud Concentration Risk'. What is the best mitigation strategy?
23When evaluating the effectiveness of a risk mitigation strategy, which stakeholder is most critical to involve in the sign-off process?
24What is the primary function of an 'Exception Process' in a risk management program?
25Which of the following is a 'Leading Indicator' for an enterprise risk management program?
26In the context of risk reporting, what does a 'Risk Heat Map' effectively communicate to the board?
27Which TWO of the following are primary components of a formal Risk Management policy?
28What is the primary difference between a 'Risk Assessment' and a 'Vulnerability Assessment'?
29When performing a risk assessment on a new SaaS implementation, which document is most useful for understanding the vendor's risk profile?
30When presenting a risk treatment plan to the Board of Directors, which THREE elements should be included to ensure executive buy-in?
31Which TWO methods are commonly used to identify new risks in an enterprise environment?
32When assessing the risk of a third-party service provider, which THREE areas should be evaluated?
33Which TWO actions are part of the 'Risk Monitoring' process?
34Which TWO of the following are valid responses to a high-risk finding?
35When building an Enterprise Risk Management (ERM) program, which THREE factors must be considered to ensure integration with the organization?
36When conducting a risk assessment on an IoT ecosystem, which THREE factors are specifically critical?
37Which THREE criteria are essential for establishing a successful 'Risk Committee'?
38Which THREE of the following are considered 'Risk Assessment' methodologies?
39Which TWO of the following are common challenges in quantitative risk analysis?
40Which TWO factors should be used to weigh the 'Impact' in a risk assessment?
The Risk Management domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 40 questions in the Risk Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Risk Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included