
Certified in Cybersecurity
Domain 1Objective 2
1.2 - Understand the Risk Management Process CC Practice Questions (Page 4)
Part of the Security Principles domain, which accounts for 26% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–21 in this domain), expect 3–4 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
26%of the exam
Questions 16–20
- 16
How does risk tolerance influence risk management decisions?
Select an answer first - 17
A retail company is evaluating the risk of a data breach from a point-of-sale (POS) system. The company has a moderate risk tolerance and is considering four treatment options: (1) accept the risk, (2) mitigate by upgrading the POS software, (3) transfer by purchasing cyber insurance, or (4) avoid by discontinuing the use of POS systems and switching to manual transactions. The cost of mitigation is $200,000, the insurance premium is $50,000 per year, and the potential loss from a breach is estimated at $1 million. The likelihood of a breach is medium. Which treatment option is most aligned with the company's risk tolerance and cost-effectiveness?
Select an answer first - 18
A university is conducting a risk assessment for its research data. The assessment identifies three risks: a ransomware attack on the research servers (likelihood: medium, impact: high), a power outage in the data center (likelihood: low, impact: medium), and a data breach due to a lost laptop (likelihood: high, impact: high). The university has limited budget for risk treatment. Which risk should be treated first?
Select an answer first - 19
Which risk treatment option is being used when an organization decides to stop a business activity because the risk is too high?
Select an answer first - 20
A hospital stores patient records in an on-premises data center. A risk assessment identifies that a fire in the data center could destroy all patient records, with a low likelihood but very high impact. The hospital has a low risk tolerance for loss of patient data. Which risk treatment option would best address this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.