Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 8Objective 2

Risk Management CCT Practice Questions (Page 3)

Part of the Business Continuity and Risk Management domain, which makes up ~8% of our current practice bank.

39questions here
8free pages
8concepts

Questions 11–15

  1. 11expert · hard

    A risk analyst is comparing two risks. Risk X has a high likelihood and low impact. Risk Y has a low likelihood and high impact. The organization has a low risk appetite and wants to prioritize risks that could cause catastrophic damage. Which risk should be prioritized?

    Select an answer first
  2. 12expert · hard

    A risk manager is preparing a risk report for the board of directors. The report should highlight the most critical risks and the status of mitigation efforts. Which of the following is the most effective way to present this information?

    Select an answer first
  3. 13foundation · easy

    Which risk management framework is commonly used by U.S. federal agencies to manage information security risk?

    Select an answer first
  4. 14expert · hard

    A company has identified a risk of a data breach due to a third-party vendor's insecure data handling practices. The vendor is critical to operations and cannot be easily replaced. The company is considering the following responses: (1) require the vendor to implement additional security controls, (2) purchase cyber insurance to cover potential losses, (3) terminate the contract and find a new vendor, (4) accept the risk because the vendor is essential. Which combination of responses represents the most appropriate risk treatment strategy?

    Select an answer first
  5. 15foundation · easy

    What is a key characteristic of qualitative risk assessment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.