Courseiva

ISC · domain

Risk Management

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Risk Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

39 questions7 easy17 medium15 hard

Focused practice

Practice Risk Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Risk Management

Risk Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Risk Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Risk Management questions (39)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following is the most appropriate action when an ISSEP identifies a high-risk vulnerability in a system that is currently in production?

Easy
2

An ISSEP is assessing the security of a CI/CD pipeline. Which THREE of the following practices are crucial to ensure the security of the software supply chain?

Hard
3

You are assessing a system that uses 'Homomorphic Encryption' for data processing. What is the primary operational trade-off the system designer must consider?

Hard
4

An organization is deploying a serverless architecture (AWS Lambda). How does the risk of patch management change compared to a traditional IaaS model?

Easy
5

You are assessing an Engineered System that utilizes a Trusted Platform Module (TPM) for secure boot. A scan reveals that the firmware version is outdated and susceptible to a known key-injection vulnerability. Which action should the ISSEP prioritize?

Hard
6

During a risk assessment of an industrial control system (ICS), the engineer identifies that an administrative workstation shares the same VLAN as the PLC network. Which remediation action is most effective from a risk management perspective?

Easy
7

An ISSEP is performing a system-level risk assessment on a cloud-native architecture using the NIST SP 800-37 RMF. During the 'Assess' step, the engineer identifies that an automated security configuration baseline is missing for the container orchestration layer. What is the most appropriate action to maintain RMF compliance?

Medium
8

An ISSEP is evaluating the risk of an API that uses basic authentication over HTTP. What is the most significant risk, and how should it be mitigated?

Medium
9

Which THREE of the following are essential for protecting against 'Man-in-the-Middle' (MitM) attacks in a service-oriented architecture?

Hard
10

You are assessing an Engineered System that uses a micro-segmentation strategy to isolate workloads. An attacker has compromised a single container and is attempting to perform network reconnaissance. What mechanism should block this attempt?

Hard
11

Which TWO of the following are key inputs for a quantitative risk analysis?

Medium
12

Which TWO of the following are critical for an effective 'Continuous Monitoring' (ConMon) program under RMF?

Medium
13

You are evaluating the risk of an Artificial Intelligence (AI) model deployment. The model is susceptible to 'model inversion' attacks, where an attacker can reconstruct sensitive training data. What is the most effective engineering control to prevent this?

Hard
14

Which TWO of the following are essential components of a robust threat modeling process for an engineered system?

Medium
15

An ISSEP is evaluating the security of an OT/ICS environment. Which THREE of the following are considered high-priority mitigation strategies to protect against common ICS cyber threats?

Hard
16

An ISSEP is reviewing the 'Maintain' phase of the RMF for a system that has undergone a significant software update. What is the most critical activity to ensure that the system's security posture remains intact?

Medium
17

An ISSEP is conducting a quantitative risk assessment for a mission-critical database. The Annualized Rate of Occurrence (ARO) is 0.5, and the Single Loss Expectancy (SLE) is $100,000. What is the Annualized Loss Expectancy (ALE)?

Medium
18

You are analyzing a proprietary SCADA system's threat landscape. The system uses a non-standard protocol that prevents the use of traditional deep packet inspection (DPI) tools. Which method provides the most effective risk reduction?

Hard
19

Which TWO of the following are acceptable ways to handle residual risk after implementing security controls in an RMF process?

Medium
20

An ISSEP is performing a supply chain risk assessment for an IOT-based sensor array. Which finding poses the highest systemic risk to the overall system integrity?

Medium
21

You are assessing an Engineered System that uses 'Hardware Security Modules' (HSM). Which THREE of the following are the most critical administrative risks to address in an HSM policy?

Hard
22

An engineering team is designing a new cloud infrastructure. To ensure the system complies with FIPS 140-3, which action must the ISSEP verify during the design phase?

Easy
23

An ISSEP is reviewing the risk of data residency for a system. Why is data residency a significant factor in a cloud-based risk assessment?

Medium
24

Which of the following is the most important document for an ISSEP to review when starting a risk assessment for a new system to ensure that all security requirements are captured?

Medium
25

During the RMF process, which document serves as the primary record for the security controls selected and their implementation status?

Easy
26

You are assessing a system that uses machine learning for fraud detection. The system is experiencing 'concept drift'. What is the risk, and how should it be managed?

Hard
27

You are assessing a system that uses hardware security modules (HSM) for signing code. An attacker is attempting a 'side-channel' attack on the HSM. Which mitigation strategy should be implemented to protect the signing keys?

Hard
28

An ISSEP is assessing the risk of a system that uses 'Secrets Management' services (e.g., HashiCorp Vault). Which THREE of the following are best practices for securing the secrets themselves?

Hard
29

Which of the following is a primary objective of a 'System-Level Risk Assessment'?

Easy
30

A system uses a hardware-based root of trust (RoT) for verifying code execution. An attacker has managed to perform a 'fault injection' attack to bypass the verification. What is the most effective hardware-level defense?

Hard
31

Which TWO of the following statements are true regarding the relationship between the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M)?

Medium
32

An ISSEP is reviewing the security architecture for a system that handles PII. The system uses a centralized database for PII storage. What is the primary risk associated with this design pattern?

Medium
33

Which TWO of the following are common pitfalls when tailoring security controls in an RMF implementation?

Medium
34

An ISSEP is reviewing a cloud-based application that uses a multi-factor authentication (MFA) provider. The provider experiences an outage, and the system is configured to 'fail-open'. What is the security risk?

Medium
35

During a system engineering project, an ISSEP discovers that a vendor-provided API lacks robust authentication. Which risk management strategy is best suited for this vulnerability when the API cannot be updated by the development team?

Easy
36

An ISSEP is conducting a risk assessment for a system that will be hosted in a multi-tenant cloud environment. Which risk is unique to the multi-tenancy model?

Medium
37

You are designing an embedded system for a medical device. The device needs to store encryption keys securely. The hardware does not support a dedicated HSM or TPM. What is the most robust software-based alternative to protect these keys?

Hard
38

You are assessing an Engineered System for cloud-native vulnerabilities. Which THREE of the following are common misconfigurations in containerized environments that an ISSEP should identify?

Hard
39

An ISSEP is performing a threat assessment for a mobile application. What is the biggest risk when using hardcoded API keys for third-party services within the app code?

Medium

Frequently asked questions

What does the Risk Management domain cover on the ISC exam?
Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 39 Risk Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Risk Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issep ISC2-ISSEP risk management Practice Questions