Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 9

1.9 - Understand and Apply Risk Management Concepts CISSP Practice Questions (Page 2)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
16%of the exam

Questions 6–10

  1. 6application · medium

    A company's security policy requires that all employees use multi-factor authentication (MFA) to access the corporate network. To enforce this, the IT department implements a system that blocks access if MFA is not completed. Additionally, they display a warning banner that states unauthorized access is prohibited and will be prosecuted. Which combination of control types does this scenario represent?

    Select an answer first
  2. 7foundation · easy

    What is the primary purpose of a risk report?

    Select an answer first
  3. 8foundation · easy

    What is the primary purpose of a control assessment?

    Select an answer first
  4. 9expert · hard

    An organization is preparing for an external audit of its security controls. The auditor will assess whether the controls are operating effectively. Which type of evidence would be most persuasive to the auditor?

    Select an answer first
  5. 10expert · medium

    A security team is implementing continuous monitoring for a cloud-based application. They want to detect misconfigurations that could lead to data exposure. Which approach would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.