Domain 1 CISSP Exam:Security and Risk Management

DOMAIN 1: Security and Risk Management

1 / 203

Which of the following must a company do when creating and managing their security program and policies?

2 / 203

What is a tried-and-true way for organizations to mitigate the risk of technology failure?

3 / 203

What are the five offenses related to cybercrime introduced by The Computer Misuse Act 1990 (U.K.)?

4 / 203

What is the penalty for each violation of COPPA according to the Federal Trade Commission (FTC)?

5 / 203

What is the annual rate of occurrence (ARO)?

6 / 203

Which provision of the USA PATRIOT Act of 2001 absolves an organization from civil penalties associated with violations of the ECPA if the organization is responding to a request of a governmental entity?

7 / 203

Which industry standard is designed to ensure that financial reports are accurate and reliable?

8 / 203

What is the primary objective of a Disaster Recovery Plan (DRP)?

9 / 203

What is the first step in a typical risk assessment process in the context of Security and Risk Management (Risk Identification)?

10 / 203

What organization was established by the Intelligence Reform and Terrorism Prevention Act of 2004 to help prevent terrorist acts against the United States?

11 / 203

What is the penalty for noncompliance with the GLBA Safeguards Rule?

12 / 203

What is the purpose of identifying the classification or sensitivity of a role before recruiting candidates?

13 / 203

What is the maximum fine that can be issued for infringements of the basic principles for processing and consent, data subjects rights, transfer of personal data to a third country, member state law obligations or noncompliance with supervisory authority orders under GDPR?

14 / 203

What is the purpose of risk maturity modeling?

15 / 203

What was the purpose of the Data Protection Act 1998 in the United Kingdom?

16 / 203

What is the importance of evaluating the potential operational impact of a countermeasure?

17 / 203

What is NIST 800-53?

18 / 203

Which of the following offenses is criminalized by The Economic Espionage Act (EEA)?

19 / 203

What does the term timeliness mean as it pertains to availability in the CIA Triad?

20 / 203

What is the purpose of removing access that will no longer be needed during an employees transfer to a different role?

21 / 203

Which of the following control types is related to administrative methods and implemented by people?

22 / 203

What is the first step in the NIST Risk Management Framework?

23 / 203

Which of the following is not included in a well-managed risk-based security programs reporting requirements according to Domain 1?

24 / 203

What is the Budapest Convention, and what is its purpose?

25 / 203

What is a Business Continuity Plan (BCP)?

26 / 203

What is the definition of risk in the context of security and risk management?

27 / 203

Which of the following is true about ISO 31000 principles in the context of Security and Risk Management?

28 / 203

Which industry standard provides guidelines for handling digital evidence, including a four-step process of identification, collection, acquisition, and preservation, across many types of media and scenarios, and covers chain of custody procedures and how to properly exchange evidence between jurisdictions?

29 / 203

Which of the following concepts helps an organization continue essential operations during a security incident and recovery from a disaster as quickly and securely as possible?

30 / 203

What are the four main categories of risk treatment?

31 / 203

Which of the following is a covered entity under HIPAA that processes or facilitates the processing of nonstandard health information and converts it into standard data types?

32 / 203

Which of the following is an example of a personnel-related countermeasure?

33 / 203

Which of the following are included in the scope of a typical BCP?

34 / 203

Which of the following is a senior-level executive within an organization who is generally responsible for all physical security and personnel security matters?

35 / 203

What does Section 209 of the USA PATRIOT Act of 2001 authorize investigators to do?

36 / 203

Which of the following is the senior-level executive within an organization who is responsible for the overall management and supervision of the information security program?

37 / 203

Which of the following organizations is classified as a healthcare clearinghouse under HIPAA?

38 / 203

Which of the following is an effective method for measuring program effectiveness through knowledge retention?

39 / 203

Which of the following control types is typically put in place after a detective control identifies a problem?

40 / 203

What is the goal of the GDPR?

41 / 203

Which is one of the most effective methods of measuring program effectiveness through knowledge retention in security awareness program evaluation?

42 / 203

Which industry-standard certification can be pursued to demonstrate accountability and commitment to security and privacy?

43 / 203

What is one of the key principles of ISO 31000 when it comes to security and risk management?

44 / 203

What is the primary focus of the attacker-centric threat modeling approach?

45 / 203

Which of the following is an open-source threat modeling approach and tool that uses threat models as a risk management tool?

46 / 203

What did the Identity Theft and Assumption Deterrence Act establish?

47 / 203

Which of the following statements is true about ISO 31000:2018?

48 / 203

What is the definition of control assessments (test) when trying to confirm that security controls are implemented as they are documented and that they are operating effectively and as intended?

49 / 203

What is an administrative investigation, as defined for (ISC)2 purposes?

50 / 203

What is the examine method used for in security and risk management?

51 / 203

What should be addressed during an employee orientation program regarding information security?

52 / 203

What is the purpose of PCI DSS?

53 / 203

Who is responsible for the overall management and supervision of the information security program within an organization?

54 / 203

What is the concept of confidentiality in the CIA Triad?

55 / 203

What is the purpose of the Child Pornography Prevention Act (CPPA) of 1996?

56 / 203

What is a potential impact of mergers and acquisitions on resources?

57 / 203

Which of the following is a serious computer offense as defined by the Cybercrime Act 2001 in Australia?

58 / 203

What is the role of a security champion in an organization?

59 / 203

What is the main responsibility of a security professional during onboarding, transfer, and termination processes?

60 / 203

Which model does ISO 28000:2007 rely heavily on to improve the security management system?

61 / 203

What criteria are used to determine the amount of fine on a noncompliant firm as per GDPR?

62 / 203

Which of the following principles form the pillars of information security known as the CIA Triad?

63 / 203

What is the purpose of conducting a threat analysis in risk analysis?

64 / 203

What is a compensating control?

65 / 203

What is the purpose of an asset-centric threat model?

66 / 203

Which of the following refers to the ability and ease of a user to access data when needed?

67 / 203

When is risk acceptance an appropriate risk response?

68 / 203

Which of the following is the primary goal of data integrity?

69 / 203

Which of the following is an example of a detective control?

70 / 203

What is the main purpose of the U.S. Sarbanes–Oxley Act (SOX) of 2002?

71 / 203

What is the maximum length of time that copyrights granted to an individual are protected according to the United States law?

72 / 203

Which of the following is an example of a cybercrime that falls under the category of crimes against people?

73 / 203

Under the HITECH Act, what is the maximum financial penalty for HIPAA compliance violations per violation category per year?

74 / 203

What is the purpose of ISO/IEC 27002?

75 / 203

What is the difference between due care and due diligence in information security?

76 / 203

What was the EU-US Privacy Shield?

77 / 203

What is maximum tolerable downtime (MTD)?

78 / 203

What is the role of a CISSP in protecting intellectual property (IP)?

79 / 203

What is the purpose of implementing data anonymization techniques in accordance with the General Data Protection Regulation (EU)?

80 / 203

Which of the following statements is true about the evaluation of security education activities?

81 / 203

What is the primary purpose of using the software- or system-centric model in threat modeling?

82 / 203

What happens to a (ISC)2 member who knowingly violates the (ISC)2 Code of Ethics?

83 / 203

What does the General Data Protection Regulation (EU) require in terms of accuracy of personal data?

84 / 203

What cabinet-level position was created by the Homeland Security Act?

85 / 203

What are the CIS Critical Security Controls?

86 / 203

What is the main benefit of using the PASTA methodology for dynamic threat analysis?

87 / 203

What is the importance of continual improvement in risk management?

88 / 203

Which of the following is an example of deterrent security controls?

89 / 203

What is jurisdiction in the context of criminal investigations?

90 / 203

What are three categories of countermeasures used in risk mitigation?

91 / 203

Which document serves as detailed instructions for how to implement a control or perform an action?

92 / 203

What is the main difference between a standard and a guideline in regards to information security practice?

93 / 203

What is one of the biggest security-related concerns for regulators, organizations, and users as more personal data goes online?

94 / 203

What is the main role of security governance principles in an organization?

95 / 203

What is the purpose of the U.S. Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003?

96 / 203

What does Section 210 of the USA PATRIOT Act of 2001 update?

97 / 203

Which of the following is an example of a technology-related countermeasure?

98 / 203

What are Minimum Security Requirements (MSRs)?

99 / 203

When considering a merger or acquisition, why is it important for organizations to review the acquired companys information security policies and procedures?

100 / 203

What is the primary purpose of developing processes for the use of alternate sites during a disaster in a continuity plan?

101 / 203

Which of the following is an example of a preventative security control?

102 / 203

What is the primary reason a CISSP should be familiar with legal and regulatory requirements related to information security?

103 / 203

Which of the following entities is considered a covered entity under HIPAA?

104 / 203

What is the difference between statutes and regulations in U.S. law?

105 / 203

What is the primary purpose of privacy regulations like HIPAA, COPPA, and GDPR?

106 / 203

Which of the following is a key aspect of DOMAIN 1: Security and Risk Management?

107 / 203

Which of the following practices is recommended under the General Data Protection Regulation (EU) with regard to data collection?

108 / 203

Who typically leads security governance at a company?

109 / 203

What is risk transference?

110 / 203

What was the purpose of the Safe Harbor agreement?

111 / 203

What does FISMA require of U.S. federal government agencies and non-government organizations that provide information services to these agencies?

112 / 203

What is the maximum length of time a critical business function can remain disabled without threatening the organizations long-term survival?

113 / 203

Which type of SOC audit and compliance report focuses strictly on a companys financial statements and controls that can impact a customers financial statements?

114 / 203

What is the SUNBURST attack?

115 / 203

What should be included in an organizations privacy policy according to DOMAIN 1: Security and Risk Management?

116 / 203

Which of the following is considered the most effective method of measuring the effectiveness of security policies and related information?

117 / 203

Which of the following concepts refers to the measure of the time between when information is expected and when it is available for use?

118 / 203

What is gamification in the context of security awareness?

119 / 203

What is the purpose of the (ISC)2 Code of Ethics Preamble?

120 / 203

What is the reason for the increasing popularity of malware attacks on proprietary commercial off-the-shelf (COTS) software?

121 / 203

During risk evaluation, what do you compare the results of your risk analysis to?

122 / 203

What is the purpose of developing key performance indicators (KPIs)?

123 / 203

Which of the following concepts refers to the ability of a user to meet their needs with available data?

124 / 203

Which of the following is the best definition of compliance according to (ISC)2?

125 / 203

What is the official definition of terrorism according to Section 808 of the USA PATRIOT Act of 2001?

126 / 203

What is the first goal of any BCP when it comes to people?

127 / 203

What is the purpose of threat modeling?

128 / 203

Which of the following is true regarding the U.S. Electronic Communications Privacy Act of 1986 (ECPA)?

129 / 203

What is the basis for determining cost-effectiveness of a countermeasure?

130 / 203

What is Recovery Time Objective (RTO)?

131 / 203

What is Recovery Point Objective (RPO)?

132 / 203

What can help organizations establish expectations with third parties and potentially lead to additional compliance burden on the organization who must enforce them?

133 / 203

What is the recommended minimum frequency for reviewing and updating security awareness, education, and training program content to ensure that it remains relevant?

134 / 203

Which of the following is NOT a component of a standard security awareness program?

135 / 203

What is the difference between SOC 1 and SOC 2 audits?

136 / 203

If a former employee accuses your organization of creating a hostile work environment, what action should be taken to prevent the destruction of potential evidence?

137 / 203

What mnemonic can be used for quantitative risk rating security threats and what five categories does it represent?

138 / 203

What is the purpose of Section 814 of the USA PATRIOT Act of 2001?

139 / 203

Which framework was developed by ISACA to assess the IT activities of an organization?

140 / 203

What is the importance of candidate screening and background investigations in maintaining information security?

141 / 203

What does the General Data Protection Regulation (EU) require regarding personal data processing?

142 / 203

Which of the following is an example of a cybercrime against property?

143 / 203

What is a nondisclosure agreement (NDA)?

144 / 203

Which of the following statements is true regarding risk management?

145 / 203

Which of the following best describes purpose limitation according to General Data Protection Regulation (EU)?

146 / 203

Which of the following measures should an organization implement to ensure that third parties protect its information from security risks?

147 / 203

What is single loss expectancy (SLE)?

148 / 203

Which of the following organizations would be considered a covered entity under HIPAA requirements?

149 / 203

When merging with or acquiring another organization, what potential risk is created by adding in new systems and platforms?

150 / 203

What is the purpose of Section 816 of the USA PATRIOT Act of 2001?

151 / 203

Which of the following statements best describes the Protect (PR) core function of the NIST Cybersecurity Framework?

152 / 203

Which of the following threats involves a malicious party assuming the identity of another party by falsifying information?

153 / 203

What organization is responsible for setting computer security standards for unclassified, nonmilitary government computer systems according to the U.S. Computer Security Act of 1987?

154 / 203

Which of the following is defined as a notional construct outlining the organizations approach to security, including a list of specific security processes, procedures, and solutions used by the organization?

155 / 203

Who is responsible for executing day-to-day security work?

156 / 203

Which SOC report type abstracts or removes all sensitive details and generally indicates whether an organization has demonstrated each of the five Trust Services principles without disclosing specifics?

157 / 203

What is a vulnerability?

158 / 203

What is the primary objective of a governance committee?

159 / 203

Which of the following is true regarding patents issued by the USPTO?

160 / 203

What is the risk associated with using unlicensed software?

161 / 203

Which of the following is an example of a cybercrime against government?

162 / 203

Which assessment method involves exercising one or more assessment objects under specified conditions to compare actual with expected behavior?

163 / 203

What does Section 202 of the USA PATRIOT Act of 2001 authorize?

164 / 203

Which of the following describes baselines in relation to standards?

165 / 203

What is one potential risk factor to consider when absorbing an unknown IT infrastructure during a merger or acquisition?

166 / 203

Which of the following is one of the most effective methods of measuring program effectiveness through knowledge retention?

167 / 203

What is risk avoidance in regards to security and risk management?

168 / 203

Which of the following is NOT a general approach to threat modeling?

169 / 203

Which of the following is an example of a cybercrime against property?

170 / 203

In a civil investigation where your organization is the plaintiff and you are overseeing the collection of evidence, what is your main objective?

171 / 203

What is annualized loss expectancy (ALE) in a quantitative risk analysis?

172 / 203

Which of the following is an example of a security procedure?

173 / 203

Which of the following is an example of a process-related countermeasure for risk mitigation?

174 / 203

Which of the following are examples of Recovery controls?

175 / 203

Which of the following is true about data breaches?

176 / 203

Which of the following is an example of a property asset?

177 / 203

What is the primary focus of a SOC 1 audit and compliance report?

178 / 203

Which principle for risk management explicitly considers any limitations of available information?

179 / 203

What is a potential security concern related to disgruntled employees during mergers and acquisitions?

180 / 203

What was the primary goal of the Information Technology Act of 2000 in India?

181 / 203

Why should security frameworks be customized to the organization?

182 / 203

Which of the following is NOT a threat modeling methodology discussed in the Security and Risk Management domain?

183 / 203

What is the maximum fine for GDPR infringements issued to controllers and processors under Articles 8, 11, 25–39, 42, 43?

184 / 203

What is the criminal offense associated with altering, damaging, or destroying a protected computer or its information, or preventing authorized use of the computer or information, such that it results in an aggregate loss of $1,000 or more during a one-year period?

185 / 203

What is the purpose of control assessments via interview?

186 / 203

What is the biggest security concern in a divestiture?

187 / 203

What actions should an organization take when an employee is involuntarily terminated?

188 / 203

What is transborder data flow?

189 / 203

Which of the following statements is true regarding dynamic risk management using ISO 31000 principles?

190 / 203

What is the purpose of measuring the security-effectiveness of a security control during the selection and implementation process?

191 / 203

What is a noncompete agreement?

192 / 203

What should an organization do when considering using third-party hardware, software, or services?

193 / 203

What is ALE in quantitative risk analysis and how is it measured?

194 / 203

What is the first step in NIST 800-154s four major steps for data-centric system threat modeling?

195 / 203

What is a trademark according to the USPTO?

196 / 203

What was the aim of the Data Protection Directive?

197 / 203

What is the first stage in the U.K. National Cyber Security Centres 12 principles for establishing and maintaining effective control of the supply chain?

198 / 203

Which of the following statements is true about supply chain risk management frameworks?

199 / 203

What is ITAR?

200 / 203

What is the importance of risk management in information security?

201 / 203

What is the purpose of security governance in an organization?

202 / 203

Who is responsible for the overall management and supervision of the information security program in an organization?

203 / 203

Which of the following agreements is designed to restrict an employee from directly competing with the organization during their employment and for a fixed time after employment?

Your score is

🔒 Hands-On Cybersecurity Course + INTERNSHIP 🔒

Visit to Cyber Course 

 

Welcome to our CISSP Practice Questions for Domain 1: Security and Risk Management.

This section is designed to help you understand and master the concepts related to security governance, risk management, and compliance.

Our free practice questions will prepare you for the CISSP exam by covering essential topics such as security policies, risk analysis, and business continuity planning.

Key Topics Covered

Our questions cover:

  • Security policies
  • Risk analysis
  • Business continuity planning

We also provide a free Anki deck to help you reinforce your learning. Don’t forget to check our Domain 2: Asset Security and Domain 3: Security Architecture and Engineering pages for comprehensive coverage of the CISSP exam.

For more detailed information, visit the official ISC² website.

 

Share the Post:

Related Posts

RSS  
  • Discover How to Work Remotely and Travel!
    Have you ever dreamed about working from beautiful places like Thailand or Japan, but weren’t sure if it’s possible? I’m here to share my adventures and some tips on how to make working remotely while exploring the world a reality.  Who Am I? My name is Josh, and I’m all about creating helpful content on […]
  • Why Contract Work in IT Can Be a Good Start for Your Career
    Hey buddies! Are you curious about what it’s like to work in IT and cyber security? Well, you’re in luck because today we’re diving into the world of contract work and how it might just be the jumpstart your career needed! Getting Into the World of Contract Work in IT Josh, an expert in IT […]
  • Is Cyber Security a Career That Will Last Forever?
    Hey everyone! Have you ever wondered if choosing a career in cyber security is a good idea for the long haul? Well, let’s dive into this topic with the help of Josh Maor’s insights, and find out why cyber security might just be one of the smartest career choices out there. What Is Cyber Security? […]
IT Course

The Affordable, Hands-On Josh Madakor IT Course that gets Results!

Ready to get started your journey?
Cyber Course

The Affordable, Hands-On Cyber Security that gets Results!

Ready to get started your journey?

JOIN OUR

NEWSLETTER

Sign up for our free newsletters.

by joining 8000+ others in my weekly newsletter 

where you’ll get a dose of my thoughts on self-improvement, career,

and life!