Free CISSP Security and Risk Management practice test questions
8 questions from this domain with answers and explanations - different from the samples on the main (ISC)² CISSP page. Sign up free to practice the full set.
-
How is risk most commonly expressed?
- AA count of the vulnerabilities a scanner reports each month
- BA function of likelihood (a threat exploiting a vulnerability) and impactCorrect
- CThe total monetary value of all assets an organization owns
- DThe number of security controls currently deployed enterprise-wide
✓ Correct answer: BRisk is formally defined as a function of likelihood and impact: the probability that a threat will exploit a vulnerability, combined with the resulting business impact. This risk equation, Risk equals Likelihood times Impact, underlies both qualitative and quantitative risk assessment, including ALE calculations, and lets management compare and prioritize risks using a common framework rather than raw counts or static asset values.
Why the other options are wrong- AA raw vulnerability count is an input to risk, not the accepted expression of risk itself.
- CAsset value alone is only one factor (impact); it omits likelihood and threat.
- DThe quantity of deployed controls describes coverage, not the level of risk.
-
Which TWO statements about the (ISC)2 Code of Professional Ethics canons are correct? (Choose TWO)
- AThe canons are listed with no particular priority order at all, and each carries fully equal weight
- BThe first canon is to protect society, the common good, necessary public trust and confidence, and the infrastructureCorrect
- CThe canons are applied in order, so a higher canon takes precedence over a lower one when they conflictCorrect
- DActing honorably and loyally toward one paying client always outweighs the duty to protect society
✓ Correct answer: B, CThe (ISC)2 Code of Ethics lists four canons in a specific priority order, so when canons conflict, a higher-listed canon takes precedence over a lower one rather than all four carrying equal weight. The first and highest canon is to protect society, the common good, necessary public trust and confidence, and the infrastructure, placing duty to the public above duty to any single client or employer.
Why the other options are wrong- AThe canons are ordered by priority, not equal and unordered, so higher canons take precedence when they conflict.
- DClient loyalty is subordinate to canon one; protecting society always outweighs favoring a single client.
-
A security manager is designing a separation-of-duties scheme to reduce fraud risk in financial transactions. Which TWO controls reinforce separation of duties and detect collusion? (Choose TWO)
- AMandatory vacation policies that rotate someone else into the dutiesCorrect
- BGranting a single administrator full end-to-end control to simplify audits
- CJob rotation that periodically reassigns sensitive responsibilitiesCorrect
- DDisabling all logging to reduce storage costs
✓ Correct answer: A, CMandatory vacations force another employee to perform the absent person's tasks, exposing hidden manipulation or fraud. Job rotation periodically moves people through sensitive roles so no individual permanently controls a process and irregularities become visible. Both are administrative controls that complement strict separation of duties.
Why the other options are wrong- BConcentrating end-to-end control in one person violates separation of duties and increases fraud risk.
- DDisabling logging removes the audit trail needed to detect fraud, directly undermining accountability.
-
During threat modeling, an analyst rates threats by Damage, Reproducibility, Exploitability, Affected users, and Discoverability to produce a numeric risk ranking. Which model is being used?
- ADREADCorrect
- BSTRIDE
- CPASTA
- DATT&CK
✓ Correct answer: ADREAD is a risk-rating model whose five categories spell its name and produce a numeric score used to prioritize threats. It is commonly paired with STRIDE, which categorizes the type of threat. DREAD focuses on quantifying severity rather than identifying threat categories.
Why the other options are wrong- BSTRIDE categorizes threats (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) but does not produce a numeric DREAD-style score.
- CPASTA is a seven-stage, risk-centric threat-modeling process, not a five-factor scoring acronym.
- DMITRE ATT&CK is a knowledge base of adversary tactics and techniques, not a scoring model.
-
An organization acquires software from a vendor and wants assurance that the delivered package was not altered between the vendor's build system and its own deployment, and that it genuinely originated from that vendor. Which control BEST provides this integrity and authenticity guarantee?
- AVerify a digital code signature on the package against the vendor's trusted public keyCorrect
- BConfirm the file download completed successfully without any HTTP transfer errors
- CCheck that the file size matches the figure quoted in the marketing brochure
- DScan the package with antivirus and, if it reports clean, assume it is authentic
✓ Correct answer: AA digital signature binds a cryptographic hash of the package to the vendor's private key; verifying it with the vendor's trusted public key proves the artifact is unaltered (integrity) and truly came from that vendor (authenticity), and it supports non-repudiation. This defends against tampering anywhere along the supply chain. Plain hashes only help if the published hash itself is authenticated, which signatures provide.
Why the other options are wrong- BA successful HTTP transfer says nothing about whether the content was tampered with or who produced it.
- CFile size is not a cryptographic integrity check and can match while the contents are maliciously altered.
- DAntivirus only flags known malware patterns; a clean scan proves neither integrity nor vendor authenticity.
-
A board adopts a written statement that the organization will not accept any cyber risk that could result in regulatory sanction, while tolerating minor operational risks. This statement is BEST described as the organization's what?
- ARisk appetiteCorrect
- BRisk register
- CResidual risk calculation
- DBusiness impact analysis
✓ Correct answer: ARisk appetite expresses, at the governance level, how much risk the organization is willing to take in pursuit of objectives. It guides treatment decisions and tolerance thresholds. Declaring zero tolerance for sanction-level risk while accepting minor operational risk is an appetite statement.
Why the other options are wrong- BA risk register is the catalog of identified risks and their treatments, not a tolerance statement.
- CResidual risk is a measured amount after controls, not a board-level appetite.
- DA BIA quantifies impact of disruptions to functions, not the willingness to take risk.
-
After analysis, management decides the residual risk from a rarely used legacy interface is below the organization's risk appetite and formally signs off on leaving it in place with no new controls. Which risk treatment has been chosen?
- ARisk acceptanceCorrect
- BRisk mitigation
- CRisk transference
- DRisk avoidance
✓ Correct answer: AWhen the residual risk sits below the defined risk appetite and management documents a decision to take no further action, the treatment is acceptance. The key markers are the informed, documented sign-off by an accountable owner and the absence of any new safeguard.
Why the other options are wrong- BMitigation would add or strengthen controls to reduce the risk, but the scenario states no new controls are applied.
- CTransference shifts financial impact to a third party (such as insurance or a contract), which is not happening here.
- DAvoidance would eliminate the activity or interface entirely, whereas here it is deliberately kept in place.
-
A security manager is documenting the organization's control set for auditors. Which TWO of the following are administrative (management) controls rather than technical or physical controls? (Choose TWO)
- AA mandatory annual security awareness training programCorrect
- BFull-disk encryption enforced on all laptops
- CA background screening policy for new hiresCorrect
- DBiometric turnstiles at the data center entrance
- EAn intrusion prevention system at the perimeter
✓ Correct answer: A, CAdministrative (management) controls are policies, procedures, and people-focused practices such as training, screening, and separation of duties. CISSP classifies controls into administrative, technical (logical), and physical categories. Encryption and IPS are technical; biometric turnstiles are physical.
Why the other options are wrong- BFull-disk encryption is a technical (logical) control enforced by software and hardware.
- DBiometric turnstiles are a physical control restricting bodily access to a facility.
- EAn intrusion prevention system is a technical control operating on network traffic.
How Security and Risk Management is tested
This domain holds 172 of the 1,117 questions in the CISSP bank, about 15%. The mix is 145 single-answer multiple choice and 27 multiple-response, so it is worth practising the formats as well as the content.
Once you have a few attempts recorded, CertGrid scores every domain separately and points you at the weakest one, so you can drill Security and Risk Management on its own rather than re-running full-length mocks.
Other CISSP exam domains
- Asset Security109 questions
- Security Architecture and Engineering141 questions
- Communication and Network Security138 questions
- Identity and Access Management138 questions
- Security Assessment and Testing130 questions
- Security Operations157 questions
- Software Development Security132 questions
- All CISSP practice questions1,117 total
- Security and Risk Management study notesKey concepts
- Security practice examsAll Security
CISSP Security and Risk Management FAQ
How many CISSP practice questions are there on Security and Risk Management?
CertGrid has 172 CISSP practice questions mapped to Security and Risk Management, which is about 15% of the 1,117-question CISSP bank. Every one carries a full explanation covering why the right answer is right and why each wrong option is wrong.
Can I practice only the Security and Risk Management domain?
Yes. Inside CertGrid you can run a focused drill on a single exam objective rather than the whole bank, and the app picks your weakest domain automatically once you have attempts to measure. The button on this page starts a Security and Risk Management drill directly.
How is Security and Risk Management tested on the CISSP exam?
In this bank the domain is made up of 145 single-answer multiple choice and 27 multiple-response questions, and it accounts for roughly 15% of the practice pool. Mapping follows the current published exam objectives; CertGrid is an independent practice platform and these are not official exam questions.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by ISC2. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.