- Home
- All questions
- Risk management
CISSP study material: Risk management
98 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 1. A regional insurer is finishing an authorisation package for a new claims platform. Assessors have documented three moderate findings, the system owner has drafted mitigation plans, and the chief information security officer wants the programme manager to sign off so the launch date holds. Who may formally accept the residual risk of operating the platform?
- 2. A federal agency wants to adopt a case-management application that a peer agency already runs under a current authorization to operate. The adopting agency will load its own records into the service and has no appetite for repeating the full assessment. Which authorisation decision fits this situation?
- 3. A shared services division publishes a hardened logging and identity stack that a dozen internal systems will inherit rather than build for themselves. Leadership asks what the authorisation decision covering that published stack must convey to the owners of the inheriting systems.
- 4. A manufacturer is standing up the Risk Management Framework for the first time. The security lead proposes to begin by categorising the first system in scope, while the enterprise architect argues that organisational groundwork must come first. Which activity does the framework place ahead of categorisation?
- 5. A bank is adopting the NIST Cybersecurity Framework 2.0 and the board asks which decisions belong to the Govern function that sits at the centre of the Core. Choose three.
- 6. An agency's authorisation for its payroll system expires every three years, and each renewal consumes a quarter of the security team's capacity while telling leadership little that is new in between. The chief information officer asks how the Risk Management Framework intends approval to be sustained instead.
- 7. A hospital group is chartering an information security continuous monitoring programme. Analysts propose to alert on every configuration change across the estate. The risk officer wants the programme scoped so its output actually drives decisions. Against what should the programme measure what it observes?
- 8. A retailer's risk team has finished assessing a new point-of-sale platform, weighing threats, vulnerabilities, cost against benefit, and the risk remaining once controls are applied. The team lead asks the security architect what the assessment report is entitled to conclude.
- 9. A defence supplier is building a cyber supply chain risk management (C-SCRM) programme guided by NIST SP 800-161 Rev. 1, which applies C-SCRM at several organisational levels. Which artefacts does that guidance expect the programme to produce? Choose three.
- 10. A software firm's leadership expects the NIST Cybersecurity Framework 2.0 to hand them a configuration standard for their cloud estate. The security lead has to reset that expectation before the programme starts. What does the framework itself provide?
- 11. A logistics company has recorded which NIST Cybersecurity Framework 2.0 outcomes it achieves today and, separately, the prioritised outcomes it intends to reach given new contractual requirements and threat trends. The programme manager asks what the organisation should do with the difference between the two.
- 12. A mid-sized utility sits at the Partial Tier under the NIST Cybersecurity Framework 2.0. A consultant urges an immediate push to Adaptive on the grounds that higher is always better. The chief risk officer wants a defensible position. When does moving to a higher Tier make sense?
- 13. A small water utility runs office IT and plant operational technology with one three-person team. It has worked from version 1.0.1 of CISA's Cross-Sector Cybersecurity Performance Goals and is moving to version 2.0. Which changes in 2.0 shape how the team plans its work? Choose two.
- 16. An agency system publishes public transit timetables. A falsified timetable would seriously mislead riders, an outage would merely inconvenience them, and the data is already public. The system owner wants one impact rating covering the whole system. How should the categorisation be performed?
- 17. A university drafts a single blanket handling rule covering every piece of personally identifiable information it holds, from published faculty office numbers to student health records. The privacy officer objects, citing the federal guidance on protecting such information. What does that guidance direct instead?
- 18. During an audit, a system owner claims the mapping of information types to impact categories binds the agency exactly as tightly as the requirement to categorise its systems. The auditor separates the two distinct assignments that legislation placed on the standards body. Which statement is accurate?
- 20. A system owner is documenting, for each security objective, the kinds of compromise that could damage the mission. A colleague has written down only theft of data by an outsider. Which additional forms of compromise does the federal categorisation standard count? Choose three.
- 21. A privacy lead is scoping a programme against the federal guide to protecting personally identifiable information and must set the steering committee's expectations about the guide's actual reach. Which statements correctly describe its scope? Choose two.
- 26. A governance team wants one control catalogue to serve the whole organisation, so that a single register covers every obligation the board tracks. They ask which concerns beyond classic information security the twenty SP 800-53 Rev. 5 families already govern. Choose two.
- 54. An assessment team at a logistics firm has finished a hands-on technical test of the order platform and proposes to drop the document and configuration review to save budget. The chief information security officer resists. Which two statements support keeping the examination work? Choose two.
- 57. A vulnerability scan of a hospital's intranet returns findings ranked by the scanning product's own severity labels. Management proposes to publish that ranked list as the organisation's statement of risk. Which two objections should the assessment lead raise? Choose two.
- 58. Midway through an authorised assessment, a tester judges that a denial-of-service check falling outside the signed document would expose a serious weakness in a customer portal. The engagement is time-boxed and the sponsor who signed is travelling. How should the tester proceed?
- 60. A government contractor runs the same exhaustive assessment procedures against a public brochure website and against a system holding claimant medical records. Auditors report that the programme misapplies its own guidance. Which change brings the programme into line?
- 62. A risk assessment of an acquisition target reports several high-likelihood exposures, and the assessors close their briefing by recommending that the board abandon the deal. The chief risk officer objects to how the assessors framed their role. Which statement explains that objection?
- 63. A security operations centre receives forty incident tickets during one shift, and a new analyst begins working them in the order they arrived. The incident manager wants a defensible handling order the organisation can justify to auditors. Which basis should determine which incident is worked first?
- 66. During an intrusion, an analyst proposes leaving the attacker's access in place and steering the session into an instrumented sandbox to observe their techniques before the incident is shut down. Which action should the incident commander take before that diversion begins?
- 68. Mission owners at a manufacturer keep deferring maintenance windows because downtime costs production, while the technology owners want fixes applied promptly. The chief information security officer needs a framing that settles the standing disagreement about whether patching is worth its cost. Which approach should be adopted?
- 70. An agency tracks the CISA Known Exploited Vulnerabilities catalog. Two vulnerabilities were added to the listing on the same day; one record is flagged as requiring forensic triage under Binding Operational Directive 26-04 and the other carries no such flag. How does that flag affect the two remediation deadlines?
- 72. A vulnerability management team wants to pull the CISA Known Exploited Vulnerabilities catalog into its scanner automatically each morning and to give priority to flaws that attackers have used in ransomware campaigns. Which two published features of the catalog support this? Choose two.
- 74. A product group adopting the Secure Software Development Framework (SSDF) scans dependencies every build and patches reported flaws within days, yet its vulnerability count returns to the same level each release. An architect argues the programme still misses one of the framework's stated objectives. Which objective is the group overlooking?
- 81. A new chief information security officer finds the firm assesses risk once a year at audit time and does nothing with the results until the next audit. She wants to describe, in the vocabulary of NIST SP 800-39, what a complete risk management process should look like. Which set of components should she present?
- 82. The board asks what the output of the risk framing step should actually be, since framing produces no control decisions of its own. What does an organisation produce by framing risk?
- 83. An insurer will cover part of a firm's losses from a data breach in exchange for a premium. Under the risk response vocabulary of NIST SP 800-39, how should this arrangement be classified?
- 84. An enterprise architect is mapping where different risk decisions are made. The organisation sets its overall appetite centrally, designs business processes in each division, and authorises individual systems in a shared service. Which three-tier structure does NIST SP 800-39 use for this?
- 85. A holding company wants to know which risk activities belong at the organisation level rather than being delegated to divisions or system owners. Which activity sits at Tier 1?
- 86. A programme manager asks which risk activities their system team owns, given that the enterprise architecture and the risk tolerance are set elsewhere. Which set of activities belongs at Tier 3?
- 87. A mid-sized agency has no budget for a dedicated risk executive post, and its head asks whether SP 800-39 can therefore not be followed. What is the correct response?
- 88. Two peer organisations in the same sector adopt visibly different risk tolerances, and an auditor asks which one is set at the wrong level. What does NIST SP 800-39 say about this?
- 89. A distinctly risk-averse bank is choosing anti-malware protection. Which two behaviours does NIST SP 800-39 associate with a less risk-tolerant organisation? Choose two.
- 90. A shared hosting platform provides physical, environmental and network controls that thirty tenant systems inherit without implementing them. Who is accountable for developing, assessing and monitoring those inherited controls?
- 91. A firm has completed its risk responses and wants to define what its monitoring programme should establish. According to NIST SP 800-39, which three questions does risk monitoring answer? Choose three.
- 92. A conglomerate lets each subsidiary run its own risk governance while the parent sets only the strategy. An auditor argues this decentralised model breaches NIST SP 800-39. What does the publication actually require?
- 93. An assessment team reports that the organisation has no vulnerabilities because every system passed its scans. The risk executive disagrees. On what grounds, according to NIST SP 800-39?
- 94. A consultancy is asked to document the risk assessment methodology it will use for a client. Which four elements does NIST SP 800-30 expect that methodology to contain?
- 95. An assessor plans to score likelihood and impact on ordinal bands of low, moderate and high, with no monetary values attached. Under NIST SP 800-30, which assessment approach is this?
- 96. Two teams assess the same platform. One begins by cataloguing adversaries and their methods; the other begins by listing the data the platform holds and what its loss would cost. In SP 800-30 terms, what differs between them?
- 97. A risk model is being documented for a new programme. Which items does NIST SP 800-30 list as the typical risk factors such a model works with? Choose three.
- 98. A data centre loses power when a contractor cuts a feeder cable during unrelated works. Under the threat source taxonomy in NIST SP 800-30, how is this best classified?
- 99. An assessor is criticised for writing narratives that chain several events together instead of listing weaknesses individually. Why does NIST SP 800-30 favour the narrative form?
- 100. After a company hardens its externally facing portal, its attackers stop probing that portal and begin targeting a supplier with weaker controls instead. What does NIST SP 800-30 call this response?
- 101. Two identical systems are assessed. One sits in a coastal flood plain; the other is air-gapped in an inland facility. Under NIST SP 800-30, what is the correct name for these site characteristics?
- 102. An assessor records a single number for the likelihood that ransomware will damage a claims platform. A reviewer says the estimate has skipped a step. Which three-step approach does NIST SP 800-30 expect?
- 103. An assessment covers two events: a targeted intrusion by a criminal group, and a transformer failure in the building. The team uses the same estimation basis for both. Why is that wrong under NIST SP 800-30?
- 104. A programme wants its risk assessments to show trends over several years and to survive a change of assessor. Which two properties does NIST SP 800-30 name for this, and what does each mean? Choose two.
- 105. An assessor insists on pairing every catalogued threat with every catalogued vulnerability before estimating likelihood. What does NIST SP 800-30 say about this practice?
- 106. The same missing patch is rated critical on an internet-facing payment gateway and low on an isolated laboratory host. A reviewer objects that a vulnerability should have one severity. What does NIST SP 800-30 say?
- 107. A risk register records impact only as the cost of restoring service after an outage. Under NIST SP 800-30, what is missing from that definition of impact?
- 108. An assessor adds SQL injection to the risk register of a system that stores everything in flat files and runs no database engine. Why does NIST SP 800-30 treat this as an error?
- 109. A system was assessed as adequately controlled at authorisation four years ago and has not been reassessed since, on the grounds that nothing about it has changed. What does NIST SP 800-30 say about that reasoning?
- 110. A large agency uses one lightweight method for early-stage projects and a more rigorous one for operational systems holding sensitive data. Is this consistent with NIST SP 800-30?
- 111. A team says it has adopted the NIST Cybersecurity Framework because it has mapped its controls to the Core's subcategories. Which two further components does CSF 2.0 provide that they have not used? Choose two.
- 112. A newcomer to CSF 2.0 asks why the Govern Function is drawn at the centre of the wheel rather than as the first step in a sequence. What is the reason?
- 113. An assessor treats the CSF Core as a checklist and reports the organisation as non-compliant because it addressed subcategories out of order. What is wrong with this reading?
- 114. A retailer wants to show its board where its cybersecurity posture stands today and where it intends to be after a two-year programme. Which CSF 2.0 artefacts express these two things?
- 115. A regional hospital group wants a starting point for its CSF Target Profile that reflects health-sector expectations rather than being built from scratch. Which CSF 2.0 artefact is designed for that?
- 116. A team has written both a Current and a Target Profile and asks what comes next in the CSF 2.0 profile cycle. Which step follows?
- 117. An assessor finds risk practices that management has approved but that are not written as organisation-wide policy, and supplier risk that is recognised but never formally acted on. Which CSF Tier does this describe?
- 118. A supplier assurance lead wants to reach the CSF Tier at which supplier risk is acted on through written agreements, governance bodies and monitoring, with risk practices expressed as formal policy. Which Tier is that?
- 119. Which two characteristics does CSF 2.0 associate with Tier 4, Adaptive, rather than with Tier 3? Choose two.
- 120. A consultancy proposes replacing a client's existing risk methodology with the CSF Tiers, presenting them as a maturity model to be climbed. What is wrong with this proposal?
- 121. A team complains that the CSF 2.0 document tells them what outcomes to reach but never how to reach them. Where does CSF 2.0 direct them for the how?
- 122. A governance review finds a documented risk tolerance but no statement of risk appetite. What does CSF 2.0 expect under its Risk Management Strategy category?
- 123. During a CSF-aligned review, a manager argues that a proposal to move a service to a managed provider is an opportunity, not a risk, and so has no place in the risk discussion. How does CSF 2.0 treat this?
- 124. A CSF 2.0 assessment finds that cybersecurity plays no part in hiring, induction or performance management, and that no executive is accountable for cyber risk. Which two Govern outcomes are unmet? Choose two.
- 125. A firm signs a supplier before any security review, intending to assess the supplier once the service is live. Which CSF 2.0 supply chain expectation does this breach most directly?
- 126. An incident response plan lists only internal teams. The organisation's payroll, identity and hosting all sit with third parties. Which CSF 2.0 supply chain outcome does the plan miss?
- 127. A manufacturer argues that CSF 2.0 cannot apply to its plant floor because the framework was written for office information technology. What does CSF 2.0 actually say about its scope?
- 128. A programme schedules Govern, Identify, Protect, Detect, Respond and Recover as six sequential annual workstreams. Why does this conflict with CSF 2.0?
- 129. A small logistics firm believes the NIST Cybersecurity Framework is meant only for critical infrastructure operators. What changed with version 2.0 that answers this?
- 130. Under CSF 2.0, which category sits within the Identify Function and carries the work of feeding lessons learned back into the programme?
- 131. A continuity coordinator has interviewed process owners about outage impacts and tolerable downtime. Which two further steps complete the business impact analysis under NIST SP 800-34? Choose two.
- 132. A system owner states that claims processing can be unavailable for no more than 36 hours before the harm to the business becomes unacceptable, counting every kind of impact. Which measure has been stated?
- 133. An architect proposes a recovery time objective of 36 hours for a process whose maximum tolerable downtime is also 36 hours, arguing the two should match. Why does NIST SP 800-34 disagree?
- 134. A business owner accepts losing up to fifteen minutes of transactions in a disaster but insists service must return within four hours. Which two objectives has the owner stated, and to which does the fifteen minutes belong? Choose two.
- 135. A continuity coordinator finds the achievable recovery time objective is twelve hours while the maximum tolerable downtime, fixed by regulation, is six. Management will not fund a faster solution this year. What does NIST SP 800-34 direct?
- 136. A coordinator beginning a business impact analysis asks which existing artefact gives the starting point for judging outage consequences. Under NIST SP 800-34, what is it?
- 137. A project team plans to conduct its business impact analysis after the system goes live, when real usage data will be available. What does NIST SP 800-34 recommend instead?
- 138. Two divisions of the same firm choose different recovery solutions for systems with similar impact levels, and an auditor asks which one is wrong. What does NIST SP 800-34 say about the choice?
- 139. A low-impact reporting system has a generous recovery time objective and a small budget. Which recovery approach does NIST SP 800-34 describe as proportionate?
- 140. An agency must analyse both its continuity of operations functions and one of its information systems. Which pairing of analysis type to subject does NIST SP 800-34 describe?
- 141. A business impact analysis shows that a single air-conditioning unit failing would take down a computer room within an hour. The team proposes documenting a recovery procedure for that outage. What does NIST SP 800-34 prefer?
- 142. A study group is planning revision time in proportion to the CISSP exam outline. Which domain carries the largest average weight, and roughly what share is it?
- 143. A small water utility asks whether adopting CISA's Cross-Sector Cybersecurity Performance Goals will make it fully secure. How should the goals be characterised?
- 144. A team that adopted the first version of CISA's performance goals is reviewing what changed in version 2.0. Which two changes were made? Choose two.
- 145. An organisation with a mature enterprise risk programme is told it must discard that programme to adopt NIST SP 800-39. Is that correct?
- 146. A control is implemented centrally by a hosting platform, but each tenant system adds its own configuration on top of the inherited part. In the vocabulary of the Risk Management Framework, how is such a control described?
- 147. A programme adopting the Risk Management Framework wants to know what Revision 2 added beyond the earlier system-level focus. Which change does it describe?
- 148. A team reads SP 800-30 as guidance for assessing individual systems only. What does the publication actually say about where risk assessment applies?