Courseiva

CCNA Risk Management Questions

40 questions · Risk Management · All types, answers revealed

1
MCQhard

During a merger, you identify two different risk assessment methodologies. What is the best strategy for the ISSMP?

A.Develop a unified risk assessment framework for the combined entity
B.Ignore the methodologies and rely on external audits
C.Force the smaller entity to adopt the larger one's tool
D.Keep both and report separately
AnswerA

A unified framework ensures consistency and comparable risk data.

Why this answer

Harmonizing methodologies allows for a unified risk view across the enterprise, which is essential for consistent governance.

2
MCQeasy

Which of the following is a 'Key Risk Indicator' (KRI) for an organization's email security program?

A.Phishing simulation failure rate
B.Total number of employees
C.Cost of the email license
D.Number of emails received
AnswerA

An increasing failure rate indicates rising risk of compromise.

Why this answer

A KRI provides an early signal of increasing risk exposure. Phishing click-through rates measure effectiveness and exposure.

3
MCQhard

When integrating risk management with the SDLC, which activity represents the most effective 'Shift-Left' approach to mitigate design-level risk?

A.Static Application Security Testing (SAST)
B.Threat Modeling
C.Dynamic Application Security Testing (DAST)
D.Penetration Testing
AnswerB

Threat modeling is the gold standard for identifying design risks early.

Why this answer

Threat modeling during the design phase identifies architectural risks before code is written.

4
MCQmedium

When executive leadership discusses 'Acceptable Risk', they are referring to:

A.Inherent risk before controls
B.Zero risk tolerance
C.The total budget for security
D.Residual risk within the risk appetite
AnswerD

This is the definition of acceptable risk.

Why this answer

Acceptable risk is the remaining risk after controls are applied that remains within the organizational risk tolerance.

5
MCQhard

Your organization is performing a supply chain risk assessment. Which factor is most critical when evaluating a critical software vendor?

A.The vendor's secure software development lifecycle (SSDLC) practices
B.The physical location of their headquarters
C.The number of employees at the vendor
D.The vendor's marketing budget
AnswerA

Assessing how they build software is the highest priority for supply chain security.

Why this answer

Vendor financial stability and their own security development lifecycle (SDL) are paramount for long-term supply chain risk.

6
MCQmedium

A Chief Risk Officer is utilizing the FAIR framework to quantify cyber risk. Which input is required to calculate the Loss Event Frequency?

A.Primary Loss Magnitude and Secondary Loss Magnitude
B.Inherent Risk and Residual Risk
C.Control Strength and Asset Valuation
D.Threat Event Frequency and Vulnerability
AnswerD

Correct, these are the two components of Loss Event Frequency.

Why this answer

FAIR defines Loss Event Frequency as a function of Threat Event Frequency and Vulnerability. Threat Capability and Threat Event Frequency are primary drivers.

7
MCQmedium

When performing a risk assessment on a new SaaS implementation, which document is most useful for understanding the vendor's risk profile?

A.The vendor's sales brochure
B.A SOC 2 Type II report
C.The vendor's stock ticker symbol
D.The vendor's customer list
AnswerB

Provides verified information on control effectiveness.

Why this answer

A SOC 2 Type II report provides an independent auditor's assessment of the vendor's security controls over time.

8
MCQmedium

An ISSMP is reviewing an organizational risk register. Which field is essential for effective risk prioritization?

A.Name of the auditor
B.Asset owner's email address
C.Inherent risk rating
D.Last modified date
AnswerC

The rating allows for comparative prioritization of threats.

Why this answer

Risk Rating (often Impact x Likelihood) is necessary to rank risks for treatment.

9
Multi-Selecthard

When conducting a risk assessment on an IoT ecosystem, which THREE factors are specifically critical?

Select 3 answers
A.The manufacturer's stock price history
B.Device patch management capabilities
C.Physical security of the device endpoints
D.Network isolation and segmentation
E.The aesthetic design of the device
AnswersB, C, D

Many IoT devices are unpatchable.

Why this answer

IoT devices often have poor security (patching challenges), high network exposure, and physical access vulnerabilities.

10
MCQmedium

When evaluating the effectiveness of a risk mitigation strategy, which stakeholder is most critical to involve in the sign-off process?

A.The IT helpdesk manager
B.The external auditor
C.The Business Process Owner
D.The HR department
AnswerC

They own the risk and must accept the residual level.

Why this answer

The Business Process Owner is the ultimate owner of the risk and must accept the residual risk.

11
MCQeasy

When reporting risk to the Board of Directors, which metric is most effective for demonstrating the value of an investment in a new EDR solution?

A.Time taken to deploy the agent
B.Reduction in annualized loss expectancy (ALE)
C.Version number of the security software
D.Number of detected malware incidents
AnswerB

ALE reduction directly correlates to financial risk management.

Why this answer

Risk reduction is best demonstrated by showing the shift in risk posture (heat map movement) or cost-avoidance metrics.

12
MCQeasy

Which of the following best describes the 'Risk Management Framework' (RMF) process step of 'Assess'?

A.Authorize the system
B.Define the boundary
C.Determine the effectiveness of controls
D.Select controls
AnswerC

Assessment evaluates the implementation and effectiveness of selected controls.

Why this answer

In NIST SP 800-37, 'Assess' involves evaluating the controls to determine if they are implemented correctly and effective.

13
MCQmedium

A risk assessment reveals that a legacy system stores PII without encryption. The business cannot replace it. What is the most appropriate risk management action?

A.Avoid the risk
B.Implement compensating controls
C.Transfer the risk
D.Accept the risk
AnswerB

Implementing network segmentation or egress filtering mitigates the risk when encryption is impossible.

Why this answer

Mitigating the risk (compensating controls) is the standard professional approach when avoidance is not feasible.

14
MCQhard

Your organization adopts the NIST CSF 2.0. Which specific function should be assessed to identify gaps in your enterprise risk management program's Governance component?

A.Govern
B.Protect
C.Respond
D.Recover
E.Identify
AnswerA

The Govern function addresses organizational context and risk management strategy.

Why this answer

The 'Govern' function was elevated in CSF 2.0 to encompass enterprise risk management, strategy, and policy.

15
Multi-Selectmedium

Which TWO factors should be used to weigh the 'Impact' in a risk assessment?

Select 2 answers
A.The number of hours the system has been running
B.The font size used in internal memos
C.The replacement cost of the asset
D.The age of the server hardware
E.The criticality of the data or service to business operations
AnswersC, E

A direct financial component of impact.

Why this answer

Impact is generally measured by the potential loss to the business, focusing on availability, confidentiality, and integrity.

16
MCQeasy

Which risk response strategy is being employed when a company purchases cyber insurance?

A.Acceptance
B.Avoidance
C.Mitigation
D.Transference
AnswerD

Insurance is a classic risk transfer mechanism.

Why this answer

Transferring the financial impact of a risk to a third party is risk transference (sharing).

17
MCQhard

In the context of ISO 31000, what is the primary purpose of 'Risk Communication and Consultation'?

A.To inform decision-making by engaging stakeholders
B.To notify the public of breaches
C.To assign blame for security failures
D.To archive risk records for auditing
AnswerA

Stakeholder engagement is critical for alignment and shared understanding of risk.

Why this answer

ISO 31000 emphasizes stakeholder engagement throughout the entire risk management process to ensure transparency and accountability.

18
MCQeasy

What is the primary difference between a 'Risk Assessment' and a 'Vulnerability Assessment'?

A.There is no difference
B.Risk assessment considers business context and impact
C.Risk assessment is only for physical assets
D.Vulnerability assessment is only for executive level
AnswerB

Risk assessments look at the 'so what' for the business.

Why this answer

A vulnerability assessment finds technical flaws; a risk assessment determines the business impact and likelihood of those flaws being exploited.

19
MCQeasy

Which of the following is an example of a detective control in a risk management program?

A.Encryption
B.Firewall rules
C.Disaster recovery plan
D.Security Information and Event Management (SIEM) alerts
AnswerD

SIEM detects anomalies and incidents.

Why this answer

Detective controls, like logs or monitoring, identify that a risk event has occurred.

20
Multi-Selecthard

When presenting a risk treatment plan to the Board of Directors, which THREE elements should be included to ensure executive buy-in?

Select 3 answers
A.A list of all software versions running in the data center
B.Technical logs of the last 100 failed login attempts
C.Cost-benefit analysis of the proposed treatment
D.Impact on business processes if not addressed
E.Clear statement of the residual risk level
AnswersC, D, E

Demonstrates the business value.

Why this answer

Executives need to understand the cost, the risk reduction, and the business impact to approve funding.

21
MCQmedium

You are performing a qualitative risk assessment. Which factor must be prioritized to ensure the assessment is aligned with the organizational risk appetite?

A.The vendor's recommended patch cycle
B.The threat actor's motivation
C.The business impact of asset unavailability
D.The technical complexity of the vulnerability
AnswerC

Aligning risk with business impact ensures the assessment reflects true organizational risk appetite.

Why this answer

The risk appetite, defined by leadership, dictates the tolerance for deviations from security standards.

22
MCQhard

You are integrating an enterprise risk register with a GRC tool (e.g., Archer). Which method provides the most accurate view of 'Residual Risk' to the board?

A.Asset Value multiplied by Threat Frequency
B.Compliance Score subtracted from 100
C.Total Budget divided by Number of Findings
D.Inherent Risk multiplied by Control Gap
AnswerD

This represents the remaining risk exposure after accounting for control deficiencies.

Why this answer

Residual risk is calculated as Inherent Risk minus the effectiveness of current controls (Control Effectiveness).

23
MCQmedium

Which of the following is a 'Leading Indicator' for an enterprise risk management program?

A.Total cost of a data breach
B.Percentage of assets with missing security patches
C.Number of systems compromised
D.Number of security incidents in the last month
AnswerB

A high patch backlog indicates a future vulnerability risk.

Why this answer

A leading indicator predicts future risk, whereas a lagging indicator reports past occurrences.

24
Multi-Selecthard

When assessing the risk of a third-party service provider, which THREE areas should be evaluated?

Select 3 answers
A.Legal and contractual liability clauses
B.Financial viability of the provider
C.Security control maturity (e.g., SOC 2)
D.The vendor's office coffee selection
E.The color of the vendor's logo
AnswersA, B, C

Crucial for risk transfer and accountability.

Why this answer

Supply chain risk management requires a holistic review of security, legal, and operational/financial health.

25
MCQhard

An organization is concerned about 'Cloud Concentration Risk'. What is the best mitigation strategy?

A.Move all data to a private data center
B.Enable two-factor authentication
C.Implement a multi-cloud strategy
D.Increase the number of security analysts
AnswerC

Distributing services across multiple providers mitigates the risk of a single provider failure.

Why this answer

Multi-cloud or hybrid-cloud strategies are the primary methods to reduce concentration risk (dependence on a single provider).

26
MCQeasy

What is the primary function of an 'Exception Process' in a risk management program?

A.To manage temporary deviations from security standards
B.To bypass the change management process
C.To punish non-compliant employees
D.To permanently ignore security policies
AnswerA

This allows for business agility while maintaining risk visibility.

Why this answer

An exception process allows for documented, time-bound deviations from security standards when compliance cannot be met immediately.

27
MCQhard

In the context of risk reporting, what does a 'Risk Heat Map' effectively communicate to the board?

A.The history of past audit findings
B.The exact cost of every security control
C.Technical vulnerability lists
D.The relative prioritization of risks across the enterprise
AnswerD

It provides a clear visual summary of the enterprise risk landscape.

Why this answer

A heat map visualizes the distribution of risks based on likelihood and impact, helping board members prioritize investment.

28
Multi-Selectmedium

Which TWO of the following are primary components of a formal Risk Management policy?

Select 2 answers
A.Detailed technical firewall configuration steps
B.The specific hardware vendors approved for purchase
C.The yearly budget for the IT department
D.Clear identification of roles and responsibilities
E.Defined risk appetite and tolerance levels
AnswersD, E

Governance requires defined accountability.

Why this answer

A risk management policy must define roles/responsibilities and the risk appetite/tolerance.

29
Multi-Selecthard

When building an Enterprise Risk Management (ERM) program, which THREE factors must be considered to ensure integration with the organization?

Select 3 answers
A.Integration with existing business processes
B.Replacing all existing staff with security experts
C.Purchasing the most expensive security tool available
D.Alignment with business strategic objectives
E.Organizational culture and risk appetite
AnswersA, D, E

Seamless operation is key to adoption.

Why this answer

ERM is successful when it aligns with the culture, business goals, and organizational structure.

30
Multi-Selectmedium

Which TWO methods are commonly used to identify new risks in an enterprise environment?

Select 2 answers
A.Threat intelligence feeds
B.The annual holiday party schedule
C.Automated server patching
D.Purchasing more hardware
E.Periodic security risk assessments
AnswersA, E

Provides external context for new threats.

Why this answer

Risk identification is often driven by systematic reviews (audits/assessments) and data-driven analysis (threat intelligence).

31
Multi-Selectmedium

Which TWO of the following are common challenges in quantitative risk analysis?

Select 2 answers
A.It is not allowed by regulatory standards
B.The models are too simple to understand
C.High complexity and resource intensity of modeling
D.Quantitative data is always free
E.Difficulty in obtaining accurate, high-quality data
AnswersC, E

Requires specialized skills and significant time.

Why this answer

Quantitative risk analysis suffers from lack of reliable data and the complexity of modeling.

32
MCQhard

You are utilizing a quantitative risk analysis. What is the 'SLE' in the context of an ARO-based calculation?

A.Single Loss Expectancy
B.Security Loss Estimate
C.System Level Exposure
D.Serious Loss Evaluation
AnswerA

Correct definition.

Why this answer

The Single Loss Expectancy (SLE) is the monetary value of a single loss event.

33
Multi-Selectmedium

Which TWO actions are part of the 'Risk Monitoring' process?

Select 2 answers
A.Tracking Key Risk Indicators (KRIs)
B.Hiring new administrative assistants
C.Reviewing effectiveness of existing controls
D.Developing new software from scratch
E.Changing the company name
AnswersA, C

KRIs provide continuous visibility into risk trends.

Why this answer

Monitoring ensures that risks remain within appetite and that mitigation strategies are actually working.

34
MCQmedium

You are managing third-party risk. Which tool or method is most appropriate for a continuous assessment of a cloud service provider (CSP)?

A.Review of the CSP's website
B.Real-time CSPM monitoring
C.One-time penetration test
D.Annual SOC 2 Type II review
AnswerB

CSPM tools offer the continuous visibility required for modern cloud risk management.

Why this answer

Cloud security posture management (CSPM) provides continuous monitoring against compliance and risk frameworks.

35
Multi-Selecthard

Which THREE criteria are essential for establishing a successful 'Risk Committee'?

Select 3 answers
A.Limiting membership to only IT security staff
B.Conducting meetings at midnight for secrecy
C.Representation from multiple business units
D.Explicit mandate and authority from the board
E.Regular cadence of meetings and reporting
AnswersC, D, E

Diverse viewpoints are essential for enterprise risk.

Why this answer

A successful committee needs diverse perspectives, executive support, and a defined mandate.

36
MCQeasy

What is the primary objective of a Business Impact Analysis (BIA)?

A.To calculate the cost of a data breach
B.To identify all system vulnerabilities
C.To determine the impact of disruptions on business operations
D.To configure firewalls for recovery
AnswerC

The BIA focuses on availability and process continuity.

Why this answer

The BIA identifies critical business processes and the impact of their disruption, which informs the BCP/DR plan.

37
MCQmedium

An enterprise is moving to a 'Zero Trust' architecture. How does this impact the risk assessment process?

A.It makes the risk assessment easier
B.It eliminates the need for risk assessment
C.It requires assessing risk at the resource and identity level
D.It only impacts physical security
AnswerC

Zero Trust assumes breach; therefore, risk must be assessed per transaction and per asset.

Why this answer

Zero Trust shifts the focus from network perimeters to identity and device health, requiring a more granular, asset-centric risk assessment.

38
MCQeasy

Which document is the primary source for defining the 'Risk Appetite' of an enterprise?

A.Risk Appetite Statement
B.Security Policy
C.Business Impact Analysis
D.Incident Response Plan
AnswerA

This defines the amount of risk an organization is willing to accept.

Why this answer

The Risk Appetite Statement is the foundational document authorized by the board/senior management.

39
Multi-Selecthard

Which THREE of the following are considered 'Risk Assessment' methodologies?

Select 3 answers
A.NIST SP 800-30
B.FAIR (Factor Analysis of Information Risk)
C.HTML 5.0
D.TCP/IP protocol
E.ISO 27005
AnswersA, B, E

The NIST guide for conducting risk assessments.

Why this answer

Common risk assessment methodologies include NIST RMF, FAIR, and ISO 27005.

40
Multi-Selectmedium

Which TWO of the following are valid responses to a high-risk finding?

Select 2 answers
A.Ask the auditor to leave
B.Delete all enterprise data
C.Purchase insurance (Transference)
D.Implement compensating controls (Mitigation)
E.Ignore the finding until the next budget cycle
AnswersC, D

A standard way to transfer financial impact.

Why this answer

Risk treatment options are generally to mitigate, transfer, avoid, or accept.

Ready to test yourself?

Try a timed practice session using only Risk Management questions.