Courseiva

CISSP · topic practice

Security and Risk Management practice questions

Security and Risk Management covers core principles like the CIA triad, risk management strategies, business impact analysis (BIA), and legal/regulatory compliance. The exam tests these concepts through scenario-based questions that require applying definitions and frameworks to real-world situations, such as selecting appropriate risk responses or identifying breach notification requirements.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security and Risk Management

What the exam tests

What to know about Security and Risk Management

You must be able to apply CIA triad principles, choose correct risk responses, interpret BIA metrics, and identify regulatory breach notification timelines. The most important thing is to accurately match definitions to scenarios, especially distinguishing RTO, RPO, and MTD.

CIA triad: confidentiality, integrity, availability and their security controls.

Risk response strategies: mitigate, transfer, avoid, accept.

Business impact analysis metrics: RTO, RPO, MTD, and their definitions.

GDPR breach notification: 72-hour reporting to supervisory authority.

Watch out for

Common Security and Risk Management exam traps

  • ▸Confusing risk response strategies, e.g., selecting 'accept' when the scenario requires reducing risk through controls.
  • ▸Mixing up BIA metrics: RTO is recovery time, RPO is data loss tolerance, MTD is maximum downtime.
  • ▸Forgetting that GDPR requires breach notification within 72 hours, not other regulations like HIPAA or SOX.

Practice set

Security and Risk Management questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are data subject rights under the GDPR? (Select THREE)

During a business impact analysis (BIA), the recovery point objective (RPO) for a critical database is determined to be 2 hours. What does this mean?

A company is recovering from a ransomware attack. Which THREE of the following are key considerations when restoring data from backups to ensure integrity and minimal downtime?

A security analyst is evaluating risks using a qualitative matrix. The likelihood is rated as 'high' and the impact as 'medium'. What is the overall risk level typically assigned in a 3x3 matrix?

Which governance framework is specifically designed to help organizations manage and protect their information assets by providing a comprehensive set of controls based on a risk management approach?

A security officer is developing a risk management plan. Which TWO of the following are valid risk response strategies? (Select TWO.)

Question 7easymulti select
Study the full AAA explanation →

Which THREE of the following are elements of the AAA framework in security?

According to the ISC2 Code of Ethics, which TWO canons are listed in the correct order of priority (highest to lowest)?

A multinational corporation operates in the European Union and the United States. The legal team asks the security manager to ensure that personal data transferred from the EU to the US is protected according to GDPR requirements. Which mechanism is specifically designed to enable such transfers while ensuring an adequate level of data protection?

Question 10easymultiple choice
Study the full AAA explanation →

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

Which of the following is an example of a security policy?

Under GDPR, which of the following is a valid lawful basis for processing personal data?

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

Which of the following is a key objective of a business impact analysis (BIA)?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security and Risk Management sessions

Start a Security and Risk Management only practice session

Every question in these sessions is drawn from the Security and Risk Management domain — nothing else.

Related practice questions

Related CISSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISSP exam test about Security and Risk Management?
You must be able to apply CIA triad principles, choose correct risk responses, interpret BIA metrics, and identify regulatory breach notification timelines. The most important thing is to accurately match definitions to scenarios, especially distinguishing RTO, RPO, and MTD.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security and Risk Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Security and Risk Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISSP topics?
Use the topic links above to move to related areas, or go back to the CISSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISSP exam covers. They are not copied from any real exam or dump site.