
Certified Information Systems Security Professional
Domain 1Objective 9
1.9 - Understand and Apply Risk Management Concepts CISSP Practice Questions (Page 7)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
16%of the exam
Questions 31–35
- 31
An intrusion detection system (IDS) that alerts security staff to suspicious activity is an example of which type of control?
Select an answer first - 32
Which framework is widely used as a general risk management standard and provides principles and guidelines?
Select an answer first - 33
In a quantitative risk analysis, what does the single loss expectancy (SLE) represent?
Select an answer first - 34
A security manager is reviewing the effectiveness of the organization's firewall rules. The manager wants to verify that the rules are actually working as intended and that no unauthorized changes have been made. Which activity would best achieve this?
Select an answer first - 35
A financial services firm is evaluating the risk of a ransomware attack. They estimate that a successful attack would cause $2 million in direct costs and $1 million in lost business. The annualized rate of occurrence is 0.1 (once every 10 years). What is the annualized loss expectancy (ALE) for this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.