
Information Systems Security Management Professional
Domain 3Objective 3
3.3 Conduct Risk Assessments ISSMP Practice Questions (Page 3)
Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
20%of the exam
Questions 11–15
- 11
A company is using a 5x5 qualitative risk matrix. The risk of a data breach is rated as 'Possible' likelihood and 'Major' impact. The risk of a system failure is rated as 'Unlikely' likelihood and 'Severe' impact. Which risk has the higher risk rating?
Select an answer first - 12
In quantitative risk analysis, what does the Annualized Loss Expectancy (ALE) represent?
Select an answer first - 13
After completing a quantitative risk assessment, the CISO needs to present the findings to the board of directors. The board is not familiar with technical risk terminology. Which approach is most effective for communicating the results?
Select an answer first - 14
An organization needs to perform a risk assessment quickly and with limited resources, but it does not require precise monetary values. Which risk assessment approach is most appropriate?
Select an answer first - 15
An organization is calculating the ALE for a potential ransomware attack. The asset value is $1,000,000, the exposure factor is 50%, and the ARO is 0.1. What is the ALE?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.