Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 3Objective 1

3.1 Develop and Manage a Risk Management Program ISSMP Practice Questions (Page 2)

Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
12concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    Which of the following is a key output of organizational risk analysis?

    Select an answer first
  2. 7foundation · easy

    What is the purpose of countermeasures and mitigating controls in risk management?

    Select an answer first
  3. 8expert · medium

    A hospital is evaluating risk treatments for a legacy patient records system that has a known critical vulnerability. The vulnerability could lead to a data breach with an estimated impact of $5 million and a likelihood of 20% per year. The hospital is considering two options: (1) patching the system at a cost of $100,000, which would reduce the likelihood to 2%, and (2) purchasing cyber insurance with a premium of $150,000 per year that covers the full impact. The hospital's risk appetite allows for a maximum annual loss of $500,000 from data breaches. Which option should the hospital choose?

    Select an answer first
  4. 9application · medium

    A healthcare organization is updating its risk management program. The previous asset inventory is two years old and known to be incomplete. The risk manager needs to ensure that the new risk analysis is based on a reliable inventory. What is the most effective first step?

    Select an answer first
  5. 10application · medium

    A logistics company is evaluating two risk treatment options for a high-impact risk: implementing an advanced intrusion detection system (IDS) at a cost of $200,000 per year, or purchasing cyber insurance with an annual premium of $50,000. The risk analysis estimates that the annualized loss expectancy (ALE) without treatment is $500,000. The IDS is expected to reduce the ALE by 80%. Which option should the company choose based on cost-benefit analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.