Courseiva

SY0-701 · topic practice

Risk Management practice questions

Practise Security+ SY0-701 Risk Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Risk Management

What the exam tests

What to know about Risk Management

Risk Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Risk Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Risk Management questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Risk Management explanation →

A vendor-supported legacy application can run only with a deprecated browser plug-in on two engineering workstations for 30 days while a replacement is tested. Management wants to allow the exception without weakening the security program. What is the best action?

Before contracting with a cloud-based payroll provider, the security team requests a security questionnaire, proof of controls, and an independent audit report. What activity is this?

Question 3mediummultiple choice
Read the full Risk Management explanation →

A security manager is leading a risk assessment for the organization. The team identifies a legacy application that contains a known critical vulnerability. The vendor has discontinued support and no patch is available. The manager calculates that the annualized loss expectancy (ALE) for exploiting this vulnerability is $50,000. Implementing a third-party web application firewall (WAF) as a compensating control would cost $80,000 per year. The organization's leadership decides that accepting the risk is the most cost-effective approach. Which of the following documents should the security manager update to formally record this risk acceptance decision and obtain the necessary sign-off?

Management wants to ensure a file server backed up every night can actually be restored within a 4-hour recovery time objective after an incident. Which two actions best improve recovery confidence? Select two.

Question 5mediummultiple choice
Read the full Risk Management explanation →

Based on the exhibit, which access design change best reduces fraud risk without stopping the payroll process?

Exhibit: Payroll application roles: - HR-Editor: can update employee records - Payroll-Approver: can release payment batches - Audit-Reader: can view reports only

Current assignment: User Lisa has both HR-Editor and Payroll-Approver because she "handles payroll end to end." Management wants to reduce the chance of one person creating and approving a fraudulent payment.

Exhibit

Exhibit:
Payroll application roles:
- HR-Editor: can update employee records
- Payroll-Approver: can release payment batches
- Audit-Reader: can view reports only

Current assignment:
User Lisa has both HR-Editor and Payroll-Approver because she "handles payroll end to end."
Management wants to reduce the chance of one person creating and approving a fraudulent payment.
Question 6mediummultiple choice
Read the full Risk Management explanation →

A project team identifies a new risk with a high likelihood of minor data exposure during a pilot rollout. The impact is low, but the issue would become harder to address after production launch. The business owner wants the project to proceed. What should the risk owner do NEXT?

Question 7mediummultiple choice
Read the full Risk Management explanation →

A software supplier used by your organization begins subcontracting a critical part of its service to an unknown hosting company. Which contractual control would BEST help manage this supply chain risk?

Question 8mediummultiple choice
Read the full Risk Management explanation →

After implementing MFA and stronger monitoring, a department still has a small chance of account misuse that could affect a low-value internal tool. The business owner reviews the remaining exposure and agrees it is within tolerance. What should happen next?

Question 9mediummultiple choice
Read the full Risk Management explanation →

A company manages 300 laptops and wants to reduce risk from missed patches while avoiding a widespread outage if an update has compatibility issues. Which patching approach is the best choice?

Question 10mediummultiple choice
Read the full Risk Management explanation →

After a ransomware event, the team restores a file server from backup, but management wants proof that the restore process will work before the backups are declared trusted. What should be done next?

Question 11mediummultiple choice
Read the full Risk Management explanation →

A records manager finds a folder of payroll reports on a shared drive. The business says the reports are no longer active, but legal retention rules require keeping them for another two years. What is the best action?

Question 12mediummultiple choice
Read the full Risk Management explanation →

A security manager at a healthcare organization is reviewing the results of a third-party vendor risk assessment for a cloud-based email service that will store protected health information (PHI). The assessment reveals that the vendor encrypts data at rest using AES-256 but does not support customer-managed encryption keys. The vendor's data center is located in a country that is not subject to HIPAA jurisdiction. The vendor's previous penetration test report is over 18 months old. Which of the following is the most appropriate risk management action for the security manager to take?

Question 13mediummultiple choice
Read the full Risk Management explanation →

A security manager at a healthcare organization is responsible for maintaining the information security policy. A project manager requests a policy exception to use a cloud-based analytics platform that stores patient data. The platform currently encrypts data at rest with AES-128 instead of the required AES-256. The security manager assesses the risk and determines that the likelihood of data exposure is low due to other compensating controls already in place, but the impact would be high. The residual risk is within the organization's risk appetite. Which of the following is the most appropriate action for the security manager to take?

Question 14mediummultiple choice
Read the full Risk Management explanation →

Based on the exhibit, what is the best governance action before the sales team uses the legacy portal without MFA?

Exhibit

Policy excerpt:
- All privileged remote access must use MFA.

Standard excerpt:
- Approved MFA methods are authenticator app or FIDO2 security key.

Procedure excerpt:
- Service desk validates identity, enrolls the device, and closes the ticket.

Exception request:
- The legacy partner portal supports only password authentication for 60 days until migration completes.
- The business owner asked for a quick email approval so the team can proceed today.
Question 15mediummultiple choice
Read the full Risk Management explanation →

A finance application has a known vulnerability in a third-party reporting component. The vendor says a patch will not be available for six months, but the business cannot stop using the application. What is the BEST risk treatment for the organization to pursue next?

Question 16mediummultiple choice
Read the full Risk Management explanation →

A weekly scan reports three findings: a medium-severity missing patch on a lab VM with no network access, a high-severity default credential on a management interface reachable from the internet, and a low-severity outdated browser plug-in on a visitor kiosk. Which issue should be remediated first?

Question 17easymultiple choice
Read the full Risk Management explanation →

Before applying a critical patch to a production application server, which action best reduces the risk of extended downtime if the patch fails?

Question 18easymultiple choice
Read the full Risk Management explanation →

A supplier tells your company it wants to use a new subcontractor to process customer data. What is the BEST contract control to reduce this risk?

Question 19mediummultiple choice
Read the full Risk Management explanation →

Based on the exhibit, which change best reduces the risk of lateral movement if a user workstation is compromised?

Exhibit

Simplified network view

Internet
  |
Perimeter firewall
  |
User VLAN 10 ---------------------------
|  Workstations                       |
|  File shares                        |
|  Domain services                    |
|  SSH allowed from User VLAN to all servers |
---------------------------------------------

Current rule set:
- TCP 22 from any device in VLAN 10 to internal Linux servers
- TCP 3389 from any device in VLAN 10 to Windows servers
- No dedicated admin network
- No bastion host
Question 20mediummultiple choice
Read the full Risk Management explanation →

Based on the exhibit, what is the best next step before the marketing SaaS platform goes live?

Exhibit

Risk register excerpt:
- Third-party service: CampaignInsight SaaS
- Data stored: Campaign names, business contact emails, and campaign performance metrics
- Known gaps: No customer-managed encryption keys, SOC report is current but lists two low-severity findings, and the vendor cannot support custom log export this quarter
- Compensating controls: SSO, SCIM deprovisioning, monthly access review, and export restrictions
- Business impact if delayed: Launch slips by 45 days and a contract penalty may apply
- Residual risk rating after controls: Medium

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Risk Management sessions

Start a Risk Management only practice session

Every question in these sessions is drawn from the Risk Management domain — nothing else.

Related practice questions

Related SY0-701 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SY0-701 exam test about Risk Management?
Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Risk Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Risk Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SY0-701 topics?
Use the topic links above to move to related areas, or go back to the SY0-701 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SY0-701 exam covers. They are not copied from any real exam or dump site.