
Certified in Cybersecurity
Domain 1Objective 2
1.2 - Understand the Risk Management Process CC Practice Questions (Page 1)
Part of the Security Principles domain, which accounts for 26% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–21 in this domain), expect 3–4 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
26%of the exam
Questions 1–5
- 1
What is the primary purpose of the risk management process?
Select an answer first - 2
Which risk treatment option involves implementing controls to reduce the likelihood or impact of a risk?
Select an answer first - 3
A small law firm wants to implement a risk management process for its client data. The firm has never performed a formal risk assessment. Which of the following is the first step the firm should take?
Select an answer first - 4
A government agency is assessing the risk of a cyberattack on its critical infrastructure. The agency has a very low risk tolerance for any disruption to its services. The risk assessment team is considering two scenarios: a ransomware attack that could encrypt data and disrupt services for days (likelihood: low, impact: very high) and a phishing attack that could lead to credential theft (likelihood: high, impact: medium). The agency has a limited budget and must choose which risk to address first. Which risk should be prioritized?
Select an answer first - 5
A manufacturing company is planning to implement a new IoT-based monitoring system for its production line. The system will collect real-time data from sensors and transmit it to a cloud platform. During the risk identification phase, which of the following is the most important risk to consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.