
Information Systems Security Management Professional
Domain 3Objective 1
3.1 Develop and Manage a Risk Management Program ISSMP Practice Questions (Page 4)
Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
20%of the exam
Questions 16–20
- 16
Which of the following best describes a primary objective of an organizational risk management program?
Select an answer first - 17
When recommending a risk treatment option, what should be included in the recommendation?
Select an answer first - 18
Which of the following is a risk treatment option?
Select an answer first - 19
A risk management program is most likely to be considered successful when it:
Select an answer first - 20
A financial services firm is establishing its risk management program. The board has expressed a low tolerance for risks that could affect customer data confidentiality, but a higher tolerance for risks that could affect internal operational efficiency. The CISO needs to translate these preferences into actionable guidance for risk owners. What should the CISO do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.