
EC-CouncilCertified Cybersecurity Technician
Domain 8Objective 2
Risk Management CCT Practice Questions (Page 6)
Part of the Business Continuity and Risk Management domain, which makes up ~8% of our current practice bank.
39questions here
8free pages
8concepts
Questions 26–30
- 26
A healthcare organization is conducting a risk assessment for its new telehealth platform. The risk team needs to quickly categorize risks based on subjective ratings of likelihood and impact, without detailed financial data. Which risk assessment methodology should they use?
Select an answer first - 27
A company has adopted the NIST RMF and is in the 'Monitor' step. The security team has implemented continuous monitoring tools that generate alerts for new vulnerabilities and misconfigurations. What is the primary purpose of this monitoring activity in the context of risk management?
Select an answer first - 28
Why is continuous risk monitoring important in risk management?
Select an answer first - 29
A hospital's patient portal is vulnerable to a ransomware attack. The estimated ALE is $1,200,000. The hospital is considering two options: (1) purchasing cybersecurity insurance with an annual premium of $100,000, or (2) implementing an advanced endpoint detection and response (EDR) solution that costs $150,000 per year and is expected to reduce the ALE by 90%. Which option is more cost-effective based on quantitative analysis?
Select an answer first - 30
A risk manager is updating the organization's risk register after a quarterly review. Which of the following should be included in the risk register for each risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.