Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 9

1.9 - Understand and Apply Risk Management Concepts CISSP Practice Questions (Page 4)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
16%of the exam

Questions 16–20

  1. 16expert · hard

    A healthcare organization is required to comply with HIPAA. They have identified a risk that patient data could be exposed through a third-party billing service. The organization's risk assessment shows that the likelihood is moderate and the impact is high. The organization decides to require the third party to sign a business associate agreement (BAA) and to purchase cybersecurity insurance. Which risk response strategies are being applied?

    Select an answer first
  2. 17expert · hard

    A security manager must report to the board of directors on the effectiveness of the risk management program. The board wants to see trends over time. Which reporting approach would best support this?

    Select an answer first
  3. 18foundation · easy

    An organization decides to discontinue a business process because the risk cannot be reduced to an acceptable level. Which risk response strategy is this?

    Select an answer first
  4. 19foundation · easy

    Which risk analysis approach uses monetary values and numerical probabilities to calculate risk?

    Select an answer first
  5. 20foundation · easy

    Which principle is central to continuous improvement in risk management?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.