Courseiva

CISSP · domain

Security and Risk Management

Security and Risk Management covers core principles like the CIA triad, risk management strategies, business impact analysis (BIA), and legal/regulatory compliance. The exam tests these concepts through scenario-based questions that require applying definitions and frameworks to real-world situations, such as selecting appropriate risk responses or identifying breach notification requirements.

69 questions17 easy35 medium17 hard

Focused practice

Practice Security and Risk Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security and Risk Management

You must be able to apply CIA triad principles, choose correct risk responses, interpret BIA metrics, and identify regulatory breach notification timelines. The most important thing is to accurately match definitions to scenarios, especially distinguishing RTO, RPO, and MTD.

CIA triad: confidentiality, integrity, availability and their security controls.

Risk response strategies: mitigate, transfer, avoid, accept.

Business impact analysis metrics: RTO, RPO, MTD, and their definitions.

GDPR breach notification: 72-hour reporting to supervisory authority.

Watch out for

Common Security and Risk Management exam traps

  • ▸Confusing risk response strategies, e.g., selecting 'accept' when the scenario requires reducing risk through controls.
  • ▸Mixing up BIA metrics: RTO is recovery time, RPO is data loss tolerance, MTD is maximum downtime.
  • ▸Forgetting that GDPR requires breach notification within 72 hours, not other regulations like HIPAA or SOX.

Question index

All Security and Risk Management questions (69)

Click any question to see the full explanation, or start a practice session above.

1

A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?

Medium
2

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

Medium
3

Which component of the CIA triad ensures that information is not disclosed to unauthorized individuals, entities, or processes?

Easy
4

During a business impact analysis (BIA), which metric represents the maximum amount of time a business process can be disrupted before causing significant harm to the organization?

Medium
5

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

Hard
6

Which document is mandatory, high-level, and sets the direction for security within an organization?

Easy
7

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

Hard
8

Which TWO of the following are lawful bases for processing personal data under the GDPR? (Select two)

Medium
9

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

Medium
10

A company's disaster recovery plan includes an agreement with another company to provide backup computing facilities in case of a disaster. The agreement allows the second company to use the facilities for its own operations if needed. This arrangement is best described as:

Hard
11

Which of the following is the correct order of the ISC2 Code of Ethics canons from highest to lowest priority?

Easy
12

Under GDPR, which TWO of the following are valid lawful bases for processing personal data?

Hard
13

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

Medium
14

A security manager is calculating the annual loss expectancy (ALE) for a server valued at $50,000. The exposure factor (EF) is 40%, and the annual rate of occurrence (ARO) is 0.5. What is the ALE?

Medium
15

An organization is implementing a new access control system. The security team wants to ensure that users cannot deny having performed an action. Which security principle is being addressed?

Medium
16

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

Easy
17

Which of the following is an example of a security policy?

Easy
18

Under GDPR, which of the following is a valid lawful basis for processing personal data?

Medium
19

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

Medium
20

Which component of the AAA framework is responsible for determining what resources a user can access and what actions they can perform?

Easy
21

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

Medium
22

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

Hard
23

An organization is implementing a BCP. After completing the BIA, which of the following is the next logical step in the planning process?

Medium
24

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

Medium
25

A company is implementing a risk management program. They have identified a critical server with an asset value of $50,000. The exposure factor due to a potential threat is 40%, and the annual rate of occurrence is 2. What is the Annualized Loss Expectancy (ALE)?

Medium
26

Which of the following is the correct order of priority for the ISC2 Code of Ethics Canons?

Medium
27

A company uses a qualitative risk analysis matrix where likelihood ranges from 1 to 5 and impact ranges from 1 to 5. A risk with a likelihood of 4 and an impact of 5 would fall into which risk level if the matrix defines high risk as scores above 15, medium as 10-15, and low as below 10?

Hard
28

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

Easy
29

Which document provides detailed step-by-step instructions for performing a specific security task?

Easy
30

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

Hard
31

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

Hard
32

A security manager is choosing a risk response for a high-impact, high-likelihood risk. Which TWO responses are most appropriate? (Select TWO)

Medium
33

Under the ISC2 Code of Ethics, which canon has the highest priority?

Easy
34

Which type of risk remains after management has implemented controls to mitigate the identified risks?

Easy
35

In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?

Medium
36

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

Hard
37

According to the ISC2 Code of Ethics, which of the following canons has the highest priority when resolving an ethical dilemma?

Easy
38

An organization wants to avoid a particular risk entirely by not engaging in the activity that creates the risk. Which risk response strategy is being used?

Medium
39

An organization's security policy requires that all data at rest must be encrypted. Which security principle is primarily being addressed?

Easy
40

An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?

Hard
41

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

Medium
42

Which of the following is a key requirement under the GDPR regarding personal data breaches?

Medium
43

Which TWO of the following are examples of risk response strategies?

Easy
44

A company is implementing PCI DSS compliance. Which THREE requirements are part of the PCI DSS? (Select THREE)

Hard
45

Under the GDPR, which THREE of the following are rights of data subjects? (Select THREE.)

Hard
46

Which TWO of the following are examples of non-repudiation controls? (Select two)

Medium
47

A security administrator is reviewing the organization's security policy framework. The administrator needs to identify the document that provides detailed, step-by-step instructions for configuring a new server securely. Which type of document should the administrator reference?

Easy
48

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

Hard
49

Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?

Medium
50

Which of the following is a key difference between a policy and a guideline in information security governance?

Medium
51

A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)

Medium
52

Which of the following is the PRIMARY purpose of the confidentiality principle in the CIA triad?

Easy
53

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

Hard
54

A security auditor is reviewing an organization's governance framework. Which TWO of the following are commonly used frameworks for IT governance and security management?

Medium
55

Which of the following is a key objective of a business impact analysis (BIA)?

Medium
56

An organization is implementing a new governance framework to align IT with business goals. Which framework is specifically designed for IT service management?

Easy
57

An organization's security team is drafting a document that defines the organization's intent to protect information assets and assigns responsibilities to the information security manager. The document must align with ISO/IEC 27001 requirements and be approved by executive management. Which type of document is being created?

Medium
58

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

Hard
59

A security analyst is evaluating the risk of a data breach in a healthcare organization. The asset value of the patient database is $500,000, and the exposure factor is 0.2. The annual rate of occurrence is estimated at 0.1. What is the annualized loss expectancy (ALE)?

Medium
60

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

Medium
61

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

Hard
62

Which THREE of the following are key components of a disaster recovery plan for a hot site? (Select three)

Hard
63

Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?

Medium
64

A security team is performing a quantitative risk analysis for a server valued at $100,000. The exposure factor is 0.4 and the annual rate of occurrence is 2. What is the annualized loss expectancy (ALE)?

Medium
65

An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?

Medium
66

Which THREE of the following are valid risk response strategies?

Medium
67

A company is implementing a hot site as a disaster recovery option. Which of the following best describes a hot site?

Medium
68

An organization is implementing a new access control system. They want to ensure that users are who they claim to be, that actions can be traced to individuals, and that access rights are managed appropriately. Which framework encompasses all three of these goals?

Medium
69

Which of the following is the primary purpose of the CIA triad in information security?

Easy

Frequently asked questions

What does the Security and Risk Management domain cover on the CISSP exam?
You must be able to apply CIA triad principles, choose correct risk responses, interpret BIA metrics, and identify regulatory breach notification timelines. The most important thing is to accurately match definitions to scenarios, especially distinguishing RTO, RPO, and MTD.
How many questions are in this domain?
This page lists all 69 Security and Risk Management questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security and Risk Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp security risk Practice Questions