Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 9

1.9 - Understand and Apply Risk Management Concepts CISSP Practice Questions (Page 1)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
16%of the exam

Questions 1–5

  1. 1foundation · easy

    A firewall configured to block unauthorized inbound traffic is an example of which type of control?

    Select an answer first
  2. 2application · medium

    A company's risk management process is currently ad hoc, with no formal risk assessment methodology and inconsistent reporting. The CISO wants to improve the maturity of the risk management program. Which initiative would be the most effective first step?

    Select an answer first
  3. 3application · medium

    A CISO needs to report the organization's top risks to the board of directors. The board is not technical and is primarily interested in the potential financial impact and the likelihood of occurrence. Which format would be most effective for this report?

    Select an answer first
  4. 4expert · hard

    A security analyst is performing a quantitative risk assessment for a data center. The facility has a server room with equipment valued at $5 million. A fire could destroy the entire room. Historical data shows a fire occurs once every 20 years. The cost of a fire suppression system is $250,000. What is the annualized loss expectancy (ALE) for the fire risk?

    Select an answer first
  5. 5application · easy

    A security operations center (SOC) wants to track the organization's risk posture over time. They have implemented a SIEM that collects logs from all critical systems. Which metric would be most useful for measuring the effectiveness of the incident response process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.