Be able to map a monitoring scenario to the right risk or log management action: identify residual risk ownership, verify log source health, and tune SIEM rules. The single most important thing is knowing that detection requires correctly configured correlation and alerting, not just raw log collection.
Start practicing
Risk Identification, Monitoring, and Analysis — choose a session length
Free · No account required
Domain overview
This domain covers risk assessment, continuous monitoring, log management, and incident detection within the SSCP framework. Questions present operational scenarios involving SIEM tuning, log integrity, residual risk documentation, and control validation. You must identify the correct process, document, or configuration change rather than just recognizing terminology.
Exam objectives
Selecting the correct risk treatment and documenting residual risk acceptance
Detecting log management failures such as gaps, tampering, or silent log sources
Configuring SIEM correlation rules and alert thresholds to detect brute-force patterns
Evaluating hardening compliance against CIS benchmarks and interpreting audit exceptions
Confusing risk avoidance, transfer, mitigation, and acceptance when a scenario asks who formally records residual risk.
Assuming a SIEM alert fires automatically; correlation rules and thresholds must be explicitly configured to detect failed-login patterns.
Treating a log file that has not changed size as normal; this often signals logging failure, rotation issues, or tampering.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security analyst is reviewing logs and notices multiple failed login attempts for a user account, followed by a successful login from an unfamiliar IP address at 3:00 AM. Which type of risk is most directly indicated by this scenario?
2An organization calculates the SLE for a server as $5,000 and the ARO as 0.2. What is the ALE?
3During a vulnerability scan, a security analyst discovers that several workstations are missing critical security patches. The organization decides to implement a compensating control by restricting network access to these workstations until patches are applied. Which risk response strategy is being used?
4Which type of IDS uses a baseline of normal behavior to detect anomalies?
5An organization uses User Behavior Analytics (UBA) to detect insider threats. Which of the following activities would most likely trigger an alert for a compromised account?
6Which of the following is a vulnerability source explicitly based on publicly known flaws?
7A company stores log files on a dedicated log server. To ensure log integrity, they implement a solution where logs are written to a WORM (Write Once, Read Many) device. Which property does this primarily protect?
8After a security incident, the incident response team needs to analyze logs from multiple sources to reconstruct the timeline. The SIEM retains logs for 90 days, but the incident occurred 120 days ago. Which action should the organization have taken to ensure log availability?
9An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?
10A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?
11A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address against an administrative account. The SIEM has not generated an alert. Which configuration change would best detect this scenario?
12An organization is calculating the Annualized Loss Expectancy (ALE) for a server. The Asset Value (AV) is $50,000, the Exposure Factor (EF) is 40%, and the Annualized Rate of Occurrence (ARO) is 0.5. What is the Single Loss Expectancy (SLE) and ALE?
13A security analyst is tuning a SIEM to reduce false positives. Which of the following actions is most likely to reduce false positives while maintaining detection of real threats?
14During a vulnerability scan, a tool reports a critical vulnerability on a web server. The system owner claims it is a false positive because the server is not accessible from the internet. However, the server is accessible from the internal network. What is the best course of action?
15A company wants to implement a security baseline for its Windows servers. Which of the following frameworks is most commonly used for this purpose?
16Which type of IDS monitors network traffic at a specific network segment and analyzes packets for malicious patterns?
17An organization wants to detect insider threats by identifying abnormal user behavior. Which technology is best suited for this purpose?
18During a risk assessment, a company identifies that a legacy system cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk response strategy is most appropriate initially?
19A company is implementing a new SIEM. Which THREE factors are most important to ensure log integrity and usefulness for forensic investigations? (Choose THREE.)
20Which TWO of the following are examples of vulnerability sources? (Choose TWO.)
21A security analyst is reviewing logs from a SIEM and notices multiple failed login attempts for a privileged account from an IP address in a foreign country, followed by a successful login after hours. Which type of security monitoring tool would be most effective at detecting this pattern as anomalous behavior based on user baseline?
22During a qualitative risk analysis, an organization assesses a threat of a data breach due to weak encryption. The likelihood is rated as 'Medium' and the impact as 'High'. According to a standard 3x3 risk matrix, what is the overall risk rating?
23An organization experiences a ransomware attack that encrypts file servers. The annualized loss expectancy (ALE) for this risk is calculated as $150,000. The single loss expectancy (SLE) is $30,000. What is the annualized rate of occurrence (ARO)?
24A security team identifies a vulnerability in a web application that allows SQL injection. Which risk response strategy involves implementing input validation and parameterized queries to reduce the risk to an acceptable level?
25After implementing security controls, a risk assessment shows that a residual risk of data exfiltration remains. Which document should formally record this residual risk and the decision to accept it?
26A company's vulnerability scanner reports a critical vulnerability in a third-party library. The remediation SLA for critical vulnerabilities is 48 hours. However, the patch is not yet available from the vendor. Which of the following is the most appropriate immediate action?
27A security analyst is configuring a SIEM to detect data exfiltration. Which of the following correlation rules would best identify potential data exfiltration via DNS tunneling?
28A security engineer is reviewing system logs and notices that the log file size has not changed for several days, despite high system activity. Which log management concern does this indicate?
29Which of the following is a primary purpose of implementing a security baseline such as the CIS Benchmarks?
30A vulnerability scan identifies a critical flaw in a web server. The server is currently in production and cannot be patched immediately due to compatibility issues. The risk response chosen is to implement a web application firewall (WAF) rule to block exploitation attempts. This is an example of which risk response?
31A security analyst is tuning a SIEM and needs to reduce false positives from a rule that alerts on failed logins. The rule currently triggers on any single failed login. Which modification would best reduce false positives while still detecting brute-force attacks?
32Which type of IDS uses a database of known attack patterns to identify malicious activity?
33A company's security policy requires that all logs be stored in a write-once, read-many (WORM) format. What is the primary security objective of this requirement?
34An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?
35A security analyst is configuring a SIEM to detect potential insider threats. Which TWO of the following data sources would be most relevant for detecting an employee exfiltrating sensitive data via email?
36A security team is implementing a vulnerability management program. According to industry best practices, which THREE of the following are essential components of a mature vulnerability management process?
37During a qualitative risk analysis, an organization assigns a risk rating of 'High' for a specific threat. Which combination of factors most directly leads to this rating?
38Which of the following is a primary purpose of a security baseline, such as the CIS Benchmarks?
39An organization is required to maintain audit logs for at least one year for compliance purposes. Which log management practice best ensures the integrity of these logs?
40Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?
41Which of the following is a common vulnerability source that would be documented in a risk register?
42An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?
43A company is preparing for a PCI DSS assessment. According to PCI DSS requirements, how frequently must internal vulnerability scans be performed?
44Which term describes the risk that remains after implementing risk mitigation controls?
45Which TWO of the following are common techniques used in quantitative risk analysis?
46Which TWO of the following are examples of technical threat sources that should be considered during risk identification?
47An organization's web application experienced a data breach due to a SQL injection vulnerability. During the risk analysis phase, the security team calculated the SLE as $25,000 and the ARO as 0.5. What is the ALE?
48A security analyst notices repeated failed login attempts from a single IP address targeting a domain controller. The SIEM alerts after 10 failed attempts within 5 minutes. Which detection type is most likely used?
49During a risk assessment, a company identifies that a legacy system has a known CVE with a CVSS score of 9.8. The system is critical but cannot be patched immediately. The management decides to implement strict network segmentation and monitor the system continuously. This risk response is best described as:
50A security analyst is reviewing logs and notices that an application log shows an error message indicating 'unhandled exception' followed by a stack trace. This log is most likely categorized as which type?
51After implementing a new IDS, the security team receives numerous alerts about legitimate traffic being flagged as malicious. This phenomenon is known as:
52A company's security policy requires that all servers be hardened according to CIS Level 1 benchmarks. During an audit, it is discovered that a server has password complexity settings that exceed Level 1 requirements. Which of the following is the most appropriate action?
53A security analyst is configuring a SIEM to detect potential data exfiltration. Which TWO log sources are most critical for detecting large outbound data transfers?
54An organization is developing a risk register. Which TWO elements are essential for each risk entry?
55A vulnerability management team is scanning a network. Which THREE factors should be considered to minimize false positives?
56A security operations center (SOC) analyst is investigating a series of alerts from the intrusion detection system (IDS) indicating possible command-and-control (C2) traffic. The analyst examines network flow logs and notices periodic outbound connections from an internal server to an external IP address every 30 minutes, with each connection transferring exactly 512 bytes. The external IP address has a low reputation score. Which of the following is the MOST likely explanation for this traffic pattern?
57A security analyst is reviewing firewall logs and notices repeated inbound TCP SYN packets to multiple destination ports on an internal web server, but no corresponding ACK packets are returned. The source IP address is spoofed. Which type of activity does this pattern most likely indicate?
58A financial services firm operates a Security Operations Center that ingests NetFlow records, firewall logs, and endpoint telemetry into a SIEM. An analyst wants to reduce alert fatigue while still surfacing high-fidelity detections. Which approach best supports this goal?
59An organization wants to quantify the potential financial loss from a specific risk scenario. The risk team estimates that a data breach would cost $500,000 in direct expenses and that such an event is expected to occur once every five years. Which metric are they calculating?
60A security analyst at a financial firm is reviewing the risk register and notes that the firm has purchased a cyber insurance policy to cover losses from a data breach. In risk management terms, which of the following best describes this action?
61A security operations center uses Nessus to scan its internal network nightly. A newly deployed web server is reporting a critical TLS vulnerability, but the vulnerability analyst confirms the server is configured to negotiate only TLS 1.3 with approved cipher suites. The scanner plugin was last updated eight weeks ago. Which action should the analyst take FIRST to resolve the discrepancy?
62A security administrator is configuring log collection for a new web application tier. The organization must retain logs for one year and needs to ensure that log data cannot be altered after collection. Which control best meets the integrity requirement?
63A financial services firm wants to reduce the risk of unauthorized access to its customer database. The security manager proposes implementing role-based access controls, encrypting data at rest, and enabling database activity monitoring. After these controls are in place, the residual risk is still considered high by the CISO. Which risk response strategy is the firm currently applying, and what should be done next?
64A security operations center (SOC) manager is evaluating a new intrusion detection system (IDS). The vendor claims the system can detect previously unknown attacks by building a baseline of normal network behavior and flagging deviations. Which detection methodology is the vendor describing?
65A security analyst reviews the health dashboard of the organization's Security Information and Event Management (SIEM) platform and notices that event ingestion from the primary domain controllers stopped at 02:00, while all other log sources continue to report normally. Which of the following should the analyst investigate FIRST to determine why domain controller logs are missing?
66An analyst is tuning an intrusion detection system that generates far too many alerts. The analyst wants to reduce noise while preserving detection of genuinely suspicious behavior. Which approach BEST supports this goal?
67A security analyst is reviewing the organization's SIEM and notices that the daily log volume dropped by 60 percent overnight, but no maintenance window was scheduled. The analyst must determine whether this is a genuine reduction in activity or a monitoring failure. Which action should the analyst take FIRST to validate the health of the monitoring capability?
68A security analyst is reviewing netflow data and notices a workstation periodically sending large amounts of data to an external IP address during non-business hours. The destination IP is not associated with any known business partner. The analyst suspects data exfiltration but needs to confirm before escalating. Which of the following actions would BEST validate the suspicion while preserving evidence?
69A risk analyst is conducting a quantitative risk analysis for a data center. The analyst needs to calculate the annualized loss expectancy (ALE). Which TWO of the following values are required to compute ALE? (Choose two.)
70A risk analyst is documenting threats for a new cloud-hosted application. The analyst must classify threat sources. Which of the following is an example of an environmental threat source rather than a human threat source?
71A financial services firm runs a Security Information and Event Management (SIEM) platform that ingests Windows Security event logs, firewall syslog, and NetFlow records. The CISO asks the analyst to detect brute-force attacks against Active Directory domain accounts. Which approach should the analyst implement to achieve this goal?
72A financial services firm classifies its customer database as its most critical asset. The risk register shows a single entry for "unauthorized database access" with an annualized loss expectancy of $2,000,000. Management approves a database activity monitoring (DAM) solution plus tokenization of account numbers, which reduces the annualized loss expectancy to $300,000. Which of the following BEST describes the $300,000 figure in risk terms?
73A risk analyst is building a risk register for a cloud-hosted customer portal and must classify threats by their source. Which TWO of the following are examples of environmental threat sources that should be documented? (Choose two.)
74An organization uses a risk register to track identified risks. A risk owner reports that a mitigation control was implemented six months ago, but the residual risk rating has not been updated and no post-implementation review was performed. Which activity is MOST important for maintaining the integrity of the risk management process?
75A security administrator is reviewing a vulnerability scan report and notices a finding labeled as a false positive. What is the most appropriate immediate action?
76A security team is building a continuous monitoring program for a regulated environment. The compliance manager wants assurance that monitoring data is trustworthy and that deviations are detected promptly. Which THREE activities should be included in the monitoring program? (Choose three.)
77A security administrator is reviewing the organization's risk register and notices that a risk related to outdated antivirus signatures has been assigned a low risk score because the likelihood is considered low. However, the impact if realized would be severe. Which risk analysis approach is being used, and what is a potential limitation of this approach?
78During a risk assessment, a team identifies that a legacy inventory application has no vendor support and cannot be patched. Leadership decides to accept the risk because replacing the application would cost more than the potential loss. Which term best describes this decision?
79A healthcare organization has completed a risk assessment and documented a set of identified risks in its risk register. Management decides not to purchase cyber insurance and not to implement any additional safeguards for a specific risk involving legacy medical devices. Which risk response strategy has management chosen?
80An analyst is reviewing alerts from a network-based intrusion detection system (NIDS) deployed on a span port at the internet edge. Several alerts reference exploit attempts against services that are not exposed to the internet. Which TWO actions should the analyst take to improve the fidelity of the monitoring data? (Choose two.)
81A security operations center is deploying a network-based intrusion detection system. The team wants to detect attacks that span multiple packets and sessions, such as a slow port scan followed by exploitation attempts. Which detection method should the team prioritize to correlate these related events?
82An organization wants to reduce the likelihood that a terminated employee's credentials can still be used to access SaaS applications after departure. Which control BEST addresses this risk?
83A security manager is assessing the risk of insider threat for a healthcare organization. Which of the following is the most appropriate way to categorize a malicious insider who intentionally exfiltrates patient data?
84A security operations center (SOC) receives an alert from its intrusion detection system (IDS) about a possible SQL injection attack against a web server. The SOC analyst reviews the IDS signature and sees that it triggered on a request containing the string 'OR 1=1'. However, the web application logs show that the request was blocked by a web application firewall (WAF) and returned a 403 error. Which of the following BEST describes the nature of this alert?
85A security administrator has been asked to establish baseline monitoring for a set of Linux web servers so that unexpected changes to critical system files are detected quickly. The administrator wants the tool to compute cryptographic hashes of files, store them, and alert when they change. Which of the following should the administrator deploy to meet this requirement?
86A risk analyst is building a threat model for a new customer-facing web application. The analyst must identify threat sources and classify them appropriately. Which TWO of the following are examples of environmental or natural threat sources that should be documented in the risk assessment? (Choose two.)
87A security team is conducting a risk assessment for a new cloud-based collaboration platform. They need to identify potential threats and vulnerabilities. Which TWO of the following are examples of technical vulnerabilities that should be considered? (Choose two.)
88A security operations center uses a SIEM to monitor authentication activity. The team wants to detect a password spraying campaign in which a single source attempts a small number of common passwords against many different user accounts, staying below the per-account lockout threshold. Which correlation approach would BEST detect this activity?
89An organization's security team is reviewing the results of a recent risk assessment. Management decides to accept a particular risk because the cost of the control exceeds the potential loss, and the risk falls within the stated risk appetite. Which term best describes this decision?
90An analyst reviewing the risk register notices that a web application vulnerability has an annualized loss expectancy (ALE) of $40,000 before controls. A web application firewall (WAF) would cost $12,000 per year to operate and is expected to reduce the ALE to $10,000. Based on this quantitative analysis, what should the analyst recommend?
91A security analyst is reviewing alerts from a Network Intrusion Detection System (NIDS) that monitors a demilitarized zone segment. Over one week, the same alert fires hundreds of times for traffic that the business has confirmed is a legitimate partner integration. The analyst has verified the signature is correctly written and the traffic is truly benign. What is the most appropriate action?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to map a monitoring scenario to the right risk or log management action: identify residual risk ownership, verify log source health, and tune SIEM rules. The single most important thing is knowing that detection requires correctly configured correlation and alerting, not just raw log collection.
The Courseiva SSCP question bank contains 91 questions in the Risk Identification, Monitoring, and Analysis domain, covering the 15% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Risk Identification, Monitoring, and Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included