Courseiva
mediumMultiple Select

ISC2 CC Risk Identification Practice Question

Which THREE of the following are key objectives of a security risk management program?

⚠ Common exam trap

Many exam-takers confuse specific security controls (like IDS or encryption) with the overarching objectives of risk management; candidates often pick controls because they sound security-related, but the question asks for key objectives, not implementations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess risks

The three key objectives of a security risk management program are to identify risks (B), assess risks (A), and mitigate risks (E). Identifying risks means discovering and documenting threats, vulnerabilities, and potential adverse events that could affect the organization's assets. Assessing risks involves analyzing the likelihood and impact of those identified risks, often through qualitative or quantitative methods, to determine their severity and priority. Mitigating risks means applying controls, such as administrative, technical, or physical safeguards, to reduce risk to an acceptable level. Options C and D are not key objectives of risk management itself; implementing intrusion detection systems and encrypting all data at rest are specific security controls or countermeasures that may be selected during risk mitigation, not the overarching objectives of the program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assess risks

    Why this is correct

    Assessing risks identifies, analyses and evaluates threats and vulnerabilities against organisational assets, establishing the likelihood and impact baseline that every subsequent treatment decision depends on. Without this evaluation step, risk cannot be prioritised or mitigated meaningfully, making it a foundational objective of any security risk management programme.

  • ✓

    Identify risks

    Why this is correct

    Identifying risks is a core objective because a risk management programme cannot prioritise or treat exposures it has not catalogued. Systematic discovery of threats, vulnerabilities and asset exposures establishes the baseline inventory that every subsequent assessment, mitigation and monitoring activity depends upon, satisfying the stem's requirement for a key programme objective.

  • ✗

    Implement intrusion detection systems

    Why it's wrong here

    Deploying intrusion detection is a detective control, whereas risk management objectives concern identifying, assessing, prioritising and treating risk. It is tempting because IDS is a recognised security capability, and it would be correct if the question asked which control supports threat detection within an environment.

  • ✗

    Encrypt all data at rest

    Why it's wrong here

    Encrypting all data at rest is a technical safeguard, not a risk management objective; the programme aims to identify, assess, treat and monitor risk to acceptable levels. It is tempting because encryption is a common compliance control, and it would be the right answer to a question asking for a data protection measure.

  • ✓

    Mitigate risks

    Why this is correct

    Mitigating risks is a core objective, since risk management must reduce identified exposures to acceptable levels through controls, transfer or avoidance. This satisfies the stem's requirement for key objectives by addressing treatment, complementing identification and assessment rather than merely documenting threats.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.