
Information Systems Security Management Professional
Domain 3Objective 1
3.1 Develop and Manage a Risk Management Program ISSMP Practice Questions (Page 5)
Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
20%of the exam
Questions 21–25
- 21
What does the scope of an organizational risk program define?
Select an answer first - 22
A retail company has implemented a new endpoint detection and response (EDR) solution as a risk treatment for malware. Six months later, the risk manager needs to verify that the treatment is effective. What is the most appropriate action?
Select an answer first - 23
What is the purpose of risk monitoring and reporting?
Select an answer first - 24
In a cost-benefit analysis of a risk treatment, the 'benefit' is typically measured as:
Select an answer first - 25
Why is it important to document risk and issue treatments?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.