mediumMultiple Select
ISC2 CC Risk Identification Practice Question
Which THREE of the following are key objectives of a security risk management program?
⚠ Common exam trap
Many exam-takers confuse specific security controls (like IDS or encryption) with the overarching objectives of risk management; candidates often pick controls because they sound security-related, but the question asks for key objectives, not implementations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess risks
The three key objectives of a security risk management program are to identify risks (B), assess risks (A), and mitigate risks (E). Identifying risks means discovering and documenting threats, vulnerabilities, and potential adverse events that could affect the organization's assets. Assessing risks involves analyzing the likelihood and impact of those identified risks, often through qualitative or quantitative methods, to determine their severity and priority. Mitigating risks means applying controls, such as administrative, technical, or physical safeguards, to reduce risk to an acceptable level. Options C and D are not key objectives of risk management itself; implementing intrusion detection systems and encrypting all data at rest are specific security controls or countermeasures that may be selected during risk mitigation, not the overarching objectives of the program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assess risks
Why this is correct
Assessing risks identifies, analyses and evaluates threats and vulnerabilities against organisational assets, establishing the likelihood and impact baseline that every subsequent treatment decision depends on. Without this evaluation step, risk cannot be prioritised or mitigated meaningfully, making it a foundational objective of any security risk management programme.
- ✓
Identify risks
Why this is correct
Identifying risks is a core objective because a risk management programme cannot prioritise or treat exposures it has not catalogued. Systematic discovery of threats, vulnerabilities and asset exposures establishes the baseline inventory that every subsequent assessment, mitigation and monitoring activity depends upon, satisfying the stem's requirement for a key programme objective.
- ✗
Implement intrusion detection systems
Why it's wrong here
Deploying intrusion detection is a detective control, whereas risk management objectives concern identifying, assessing, prioritising and treating risk. It is tempting because IDS is a recognised security capability, and it would be correct if the question asked which control supports threat detection within an environment.
- ✗
Encrypt all data at rest
Why it's wrong here
Encrypting all data at rest is a technical safeguard, not a risk management objective; the programme aims to identify, assess, treat and monitor risk to acceptable levels. It is tempting because encryption is a common compliance control, and it would be the right answer to a question asking for a data protection measure.
- ✓
Mitigate risks
Why this is correct
Mitigating risks is a core objective, since risk management must reduce identified exposures to acceptable levels through controls, transfer or avoidance. This satisfies the stem's requirement for key objectives by addressing treatment, complementing identification and assessment rather than merely documenting threats.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.