Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified in Cybersecurity

Domain 1Objective 2

1.2 - Understand the Risk Management Process CC Practice Questions (Page 5)

Part of the Security Principles domain, which accounts for 26% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–21 in this domain), expect 3–4 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
26%of the exam

Questions 21–25

  1. 21application · medium · select all that apply

    A risk assessment team is analyzing the risk of a ransomware attack on a company's file servers. Which of the following factors should be considered when assessing this risk? (Select all that apply.)

    Select an answer first
  2. 22application · medium · select all that apply

    A company has identified a risk of a data breach due to weak passwords. The company has a moderate risk tolerance. Which of the following are appropriate risk treatment options? (Select all that apply.)

    Select an answer first
  3. 23application · medium

    A startup company is developing a new mobile app. The CEO states that the company can tolerate a moderate level of risk to achieve rapid growth, but cannot accept any risk that could result in a data breach of customer information. During a risk assessment, the team identifies a potential vulnerability in the app's authentication mechanism that could lead to unauthorized access to user data. The likelihood is assessed as medium and the impact as high. What should the company do with this risk?

    Select an answer first
  4. 24expert · hard

    A healthcare organization is implementing a risk management process for the first time. The organization has a limited budget and needs to comply with regulations that require regular risk assessments. The risk management team is deciding whether to conduct a qualitative or quantitative risk assessment. Which approach is most appropriate for this organization?

    Select an answer first
  5. 25application · medium

    A software development company is considering using a third-party cloud provider to host its application. The company's risk assessment identifies that the cloud provider could suffer a service outage, causing downtime for the application. The company decides to sign a contract with the provider that includes financial penalties for downtime. Which risk treatment option is the company using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.