All questions

CISSP Domain 2 – Information Risk Management Practice Test

Browse all practice questions for the CISSP Domain 2 – Information Risk Management Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Master the CISSP Domain 2 Challenge 2026 – Conquer Information Risk Management Like a Pro! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What do attackers exploit when taking advantage of cross-site scripting vulnerabilities?
  • What is effective risk communication?
  • Why is threat modeling important in risk management?
  • What is the primary purpose of segregation of duties in an organization?
  • What is the significance of business continuity planning?
  • What does a vendor risk assessment evaluate?
  • Quantitative risk analysis is most suitable when assessment results:
  • What is the primary benefit of performing an information asset classification?
  • Which authentication method is effective in preventing authentication replay attacks?
  • What is the MOST important factor to consider in the loss of mobile equipment with unencrypted data?
  • In conducting an initial technical vulnerability assessment, which of the following choices should receive top priority?
  • What is the outcome of an effective risk management program regarding organizational activities?
  • Which factors are considered essential components of a business impact analysis?
  • What is the function of a security policy?
  • How is compliance defined in the context of information security?
  • Which analysis method would be MOST useful in developing recovery time objectives?
  • Why is conducting a vendor risk assessment important?
  • What approach can best assist in measuring organizational risk effectiveness?
  • Which of the following steps in conducting a risk assessment should be performed first?
  • What role does leadership play in risk management?
  • Which framework integrates risk management into an organization’s governance processes?
  • What does the principle of "defense in depth" primarily focus on?
  • Which strategy is most useful for protecting sensitive data during transmission?
  • Which factor BEST demonstrates that a risk management practice is successful?
  • In the context of information security, what is the primary focus of risk mitigation?
  • What does the term "asset" refer to in information security?
  • What does the term "risk mitigation" signify?
  • Compliance in information security ensures adherence to what?
  • Why might an organization decide not to take any action on a denial-of-service vulnerability found by the risk assessment team?
  • What is an important benefit of conducting a formal risk assessment?
  • What does "risk-sharing" involve?
  • When an enterprise is transferring its IT operations to an offshore location, what should the information security manager primarily focus on?
  • What is the first step of performing an information risk analysis?
  • What aspect of risk management does an incident response plan (IRP) specifically address?
  • When performing a qualitative risk analysis, which of the following will BEST produce reliable results?
  • Explain the purpose of a risk management framework.
  • What is the primary objective of a risk management program?
  • What is the key focus of incident response planning?
  • After a risk assessment, what should a bank do to address concerns in regions with high identity theft?
  • What is most important to keep in mind when assessing the value of information?
  • What does information security governance establish?
  • Why is asset classification important to a successful information security program?
  • What is the primary basis for the selection of controls and countermeasures?
  • Which of the following is the primary prerequisite to implementing data classification within an organization?
  • What provides the best defense against the introduction of malware in end-user computers via the internet browser?
  • What does the principle of least privilege entail?
  • When designing security protocols, which of the following should be emphasized?
  • What is the purpose of threat modeling?
  • How is "security posture" best described?
  • What is residual risk?
  • Which of the following would be the MOST relevant factor when defining the information classification policy?
  • What is the primary purpose of a business impact analysis?
  • What is the primary basis for the selection and implementation of products to protect the IT infrastructure?
  • What should be done for previously accepted risk within an organization?
  • What role do policies play in risk management?
  • Which of the following is a preventive measure?
  • Which factor will most influence how controls should be layered?
  • Who is generally responsible for determining the classification of an information asset?
  • Which role is responsible for ensuring that information is classified?
  • There is a delay between the time when a security vulnerability is first published, and the time when a patch is delivered. What should be carried out FIRST to mitigate the risk during this time period?
  • What type of analysis is conducted to determine the potential impact of a disruption on critical functions?
  • How often should a risk assessment typically be conducted?
  • In which phase of the development process should risk assessment be first introduced?
  • Which of the following best describes risk assessment?
  • When performing a quantitative risk analysis, which aspect is MOST important to estimate the potential loss?
  • Logging is an example of which type of defense against systems compromise?
  • What is one of the main objectives of information classification?
  • What should information security managers use risk assessment techniques for?
  • What should an effective information security management program use to allocate resources for mitigating exposures?
  • What mechanism should be used to identify deficiencies that would provide attackers with an opportunity to compromise a computer system?
  • During a risk assessment, what may render a system vulnerable if left unchecked?
  • How is "data loss prevention" (DLP) best described?
  • What is the primary purpose of a business impact analysis (BIA)?
  • What constitutes "critical infrastructure"?
  • What does "data integrity" refer to?
  • Which action could circumvent the control that scans comments for inappropriate disclosures on a social media application?
  • What is the primary aim of implementing security controls?
  • What is the best means to standardize security configuration in similar devices?
  • What is the BEST basis for determining the criticality and sensitivity of information assets?
  • What are risk control assessments used for?
  • Which factor is MOST essential when assessing risk?
  • Why is risk assessment critical in an organization?
  • What could abnormal server communication indicate within an organization?
  • Which practice is crucial for identifying vulnerabilities prior to actioning security controls?
  • What constitutes an insider threat?
  • Describe the role of continuous improvement in risk management.
  • What is the purpose of an audit trail?
  • What role does threat intelligence play in risk management?
  • Which of the following is an essential element when determining the necessity of a business impact analysis update?
  • What is the main goal of risk management programs?
  • What is the main reason for performing risk assessment on a continuous basis?
  • What is "access control"?
  • If an information security manager finds that employees are not complying with the access control policy for the data center, what should be the first step to address this?
  • Risk assessment should be repeated at regular intervals because:
  • What is an incident response plan (IRP)?
  • What action should be taken when a security audit reveals weakness in controls?
  • A business unit intends to deploy a new technology in violation of existing security standards. What immediate action should an information security manager take?
  • What is a "security framework"?
  • Which risk scenario is best assessed using qualitative risk assessment techniques?
  • Who is the BEST source for determining the value of information assets within an organization?
  • Retention of business records should primarily be based on what criterion?
  • What is the primary purpose of a risk register?
  • What does Opportunities Cost reflect in an organization?
  • In which area are data owners PRIMARILY responsible for establishing risk mitigation?
  • What assessment should be conducted to evaluate the need for remedial action for an insecure mail server?
  • What document outlines the rules and guidelines governing data classification within an organization?
  • Which type of risk response involves accepting the risk without taking any specific actions?
  • Define "third-party risk management".
  • The use of insurance to manage risk is an example of what type of response?
  • What is the difference between technical controls and physical controls?
  • How does risk prioritization aid decision-making?
  • What does a network vulnerability assessment expect to identify?
  • What is an essential step to take when a new security risk is identified?
  • Phishing is best mitigated by which of the following?
  • What defines a "security control"?
  • What is the BEST strategy for risk management?
  • Which of the following is an example of a risk treatment option?
  • What is the best resolution when security standards conflict with business objectives?
  • When evaluating information security strategies, what factor is crucial for aligning with business objectives?
  • Which strategy is most effective for risk mitigation prioritization?
  • What is cyber insurance designed to help organizations with?
  • What is the best approach to ensure adherence to an organization's security policies?
  • What is the term used when risk is formally accepted?
  • What is the reasonable expectation to have of a risk management program?
  • What would be the best approach to prevent a successful brute force attack on an administrative account?
  • What approach should organizations use to prioritize their information security controls?
  • Which type of attack is best mitigated by using a strong password?
  • What is the primary goal of risk management?
  • What is the primary reason for classifying information resources according to sensitivity and practicality?
  • What is the reasonable approach to determine control effectiveness?
  • Which role is PRIMARY responsible for determining the information classification levels for a given information asset?
  • Ongoing tracking of remediation efforts to mitigate identified risks is BEST accomplished using which approach?
  • What practice supports the needs of risk management in an organization?
  • What does risk transference typically involve?
  • A project manager is developing a portal and requests a public internet protocol address. What should the security manager do first?
  • What is compliance management concerned with?
  • What is a "security baseline"?
  • What is the role of data owners in a risk management process?
  • What is the result of effective risk communication among stakeholders?
  • Which process facilitates the identification of critical business functions to prioritize during recovery planning?
  • What is the primary objective of risk management processes?
  • What does a breach refer to in risk management?
  • What is a key benefit of conducting regular security audits?
  • What is a "vulnerability"?
  • What are administrative controls typically associated with?
  • What is the best way to assess aggregate risk derived from a chain of linked system vulnerabilities?
  • Who is responsible for determining if an IT risk has been reduced to an acceptable level?
  • When informed of a targeted attack by skilled hackers, what should the information security manager do first?
  • What is essential for maintaining a good security posture?
  • Which of the following is an example of risk mitigation?
  • How are IT-related risk management activities most effectively conducted?
  • Which of the following types of risk is assessed using quantitative risk assessment techniques?
  • Which key components must be assessed in an effective risk analysis?
  • What is the most appropriate use of gap analysis?
  • What should be prioritized when selecting security controls?
  • What is a risk mitigation strategy?
  • What role does information classification play in risk management?
  • What is the focus of security awareness training?
  • What type of access does the principle of least privilege advocate for?
  • Why is continuous monitoring important in risk management?
  • Which program element should be implemented FIRST in asset classification and control?
  • Which aspect is vital to consider when assessing the effectiveness of security controls?
  • Which of the following would be MOST relevant in a cost-benefit analysis of a two-factor authentication system?
  • What method is crucial for linking security requirements to business objectives?
  • Which outcome is most likely if risk is transferred to a third party?
  • Which framework can organizations use to assess and mitigate risks effectively?
  • After completing a full IT risk assessment, who is in the best position to decide which mitigating controls should be implemented?
  • What is the best method to provide a new user with their initial password for email system access?
  • During which phase of a development project is it MOST appropriate to assess the risk of a new application system?
  • What is the purpose of risk monitoring and review?
  • When a proposed system change violates an existing security standard, how should the conflict be resolved?
  • Define "risk tolerance".
  • Define "threat" in the context of risk management.
  • Which of the following should be continuously monitored to ensure ongoing risk management?
  • What should the information security manager do when the IT function claims a business impact analysis update is unnecessary for a new application?
  • Which strategy is MOST effective in minimizing risk within an organization?
  • The information classification scheme should:
  • Which measure would be MOST effective in mitigating insider threats to confidential information?
  • Which method is the most cost-effective for identifying new vendor vulnerabilities?
  • Which of the following is the MOST usable deliverable of an information security risk analysis?
  • What type of vulnerability is identified when access to all employee accounts can be gained by changing the employee's ID in the URL?
  • What is the primary purpose of a security audit?
  • What policy governs how a company's breakthrough technology should be protected?
  • In the context of regulatory compliance, what is the main role of risk assessment?
  • How does cyber insurance benefit organizations?
  • In risk management, what type of risk is referred to as the potential for loss or damage?
  • Which of the following could be a significant consequence of not managing risk effectively?
  • What is a key benefit of using external vulnerability reporting sources?
  • Which group is in the best position to perform a risk analysis for a business?
  • When dealing with a low probability but high impact risk like a natural disaster, what is the most effective risk treatment strategy?
  • What is the primary purpose of conducting risk analysis within a security program?
  • In a business impact analysis, the value of an information system should consider?
  • To maintain data privacy in compliance with regulations, what is key to develop within an organization?
  • What is the purpose of a risk assessment?
  • What is the BEST technique for selecting security controls on a limited budget?
  • What is the purpose of risk communication?
  • What is the key factor for ensuring the overall effectiveness of a risk management program?
  • Which of the following actions is not typically part of risk acceptance?
  • What technique MOST clearly indicates whether specific risk-reduction controls should be implemented?
  • What method is MOST effective at preventing insider security attacks?
  • What does the concept of "risk-sharing" aim to achieve?
  • What is an effective way to communicate risk management policies within an organization?
  • What is the key benefit of establishing a risk management culture within an organization?
  • Which of the following is most essential for a risk management program to be effective?
  • An operating system noncritical patch to enhance system security cannot be applied due to application conflict. What is the best solution?
  • Which output is crucial in presenting the results of a risk assessment?
  • When should risk assessment be performed for optimum effectiveness?
  • What does the term "risk transference" mean?
  • What is the primary reason for implementing a risk management program?
  • What is the purpose of conducting a risk analysis?
  • How often should risk assessments be conducted?
  • Which control is considered key for preventing unauthorized access to sensitive data?
  • Which situation presents the greatest information security risk for an organization with multiple processing locations?
  • What is the PRIMARY goal of a corporate risk management program?
  • What is a "transition plan" in risk management?
  • What could be a potential consequence of not regularly reassessing accepted risks?
  • What approach is used to determine the likelihood and impact of identified risks?
  • In assessing business risks, which dimension should be prioritized?
  • What is the PRIMARY reason for initiating a policy exception process?
  • Which action should be prioritized when an organization identifies a new significant cybersecurity threat?
  • What activity should an information security manager perform FIRST when assessing the potential impact of new privacy legislation on the organization?
  • What is the primary consideration when assessing new technologies for potential security risks?
  • In what scenario should an organization most likely conduct penetration testing?
  • What is the difference between inherent risk and residual risk?
  • What should an organization do after determining the residual risk?
  • What is the primary goal of an effective risk management program?
  • What is a primary benefit of using baselines in an organization’s security strategy?
  • What is a critical outcome of effective risk communication?
  • What is an acceptable use policy (AUP)?
  • Who should be assigned as data owner for sensitive customer data used only by the sales department and stored in a central database?
  • What is the purpose of conducting a risk analysis?
  • What is a key consideration in a risk management approach?
  • What is the MOST important consideration when conducting a risk assessment?
  • What is the main distinction between a policy and a standard?
  • In risk management, what is the purpose of a business impact analysis?
  • What is the primary goal of security awareness training?
  • Which type of information would an information security manager expect to have the lowest level of security in a publicly traded, multinational enterprise?
  • Which document primarily governs the safety measures for sensitive organizational technology?
  • Why is it important to engage stakeholders in the risk management process?
  • For risk management, how should the value of a physical asset be evaluated?
  • If an organization must comply with industry regulatory requirements that have high implementation costs, what should the information security manager do FIRST?
  • What is risk appetite?
  • Which process involves systematically identifying security weaknesses?
  • Which privacy legislation focuses primarily on the protection of children's online personal data?
  • What is the best method for calculating the impact of losing network connectivity for 18 to 24 hours?
  • Which of the following is critical for ensuring the continued effectiveness of security controls?
  • Temporarily deactivating some monitoring processes may not be acceptable to the information security manager if:
  • Differentiate between quantitative and qualitative risk assessment.
  • What type of analysis is crucial for understanding risks in an organization’s IT environment?
  • What is typically the first step taken to initiate a risk management process?
  • What are security metrics used for?
  • Who should primarily provide direction on the impact of new regulatory requirements that may lead to major system changes?
  • Risk acceptance is an aspect of which risk management component?
  • Which approach is essential when developing a risk management strategy?
  • Which practice would BEST mitigate the risk of data leakage in an organization?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy