Skip to main content

Security and Risk Management

Domain 01 Practice Set: 01

CISSP DOMAIN 01: Security and Risk Management (Assessment Mode)

Domain 1 of the CISSP exam covers Security and Risk Management, which is a broad area encompassing various aspects of information security, including concepts related to governance, risk management, compliance, law, ethics, and security education.  

Domain 01: Practice Set 01

 
Disclaimer: The practice exam questions provided are representative of the certification exam, but not the actual questions you will see on the certification exam. Practice exams are for self-assessment.

Page : 1/11

1. Which of the following is a PRIMARY goal of information security governance?
2. Which of the following scenarios BEST illustrates the concept of a "Man in the Middle" (MitM) attack?
3. Which of the following best exemplifies ethical behavior in information security?
4. What does the term "Due Diligence" refer to in the context of information security?
5. If different user groups with different security access levels need to access the same information, which of the following actions should management take?

Page : 2/11

6. Which of the following best describes a Security Policy?
7. What is the primary purpose of the "Data Owner" role in information security?
8. What is the primary function of a Security Information and Event Management (SIEM) system?
9. Which of the following best defines "Social Engineering"?
10. What is the primary goal of the CIA Triad in information security?

Page : 3/11

11. Which of the following is an example of a physical security control?
12. What is the primary purpose of implementing the principle of least privilege?
13. What principle is primarily concerned with ensuring that data is only accessible to those authorized to view it?
14. In the context of risk management, what is the significance of "Risk Appetite" in determining an organization's security investment?
15. Which of the following incidents would MOST likely trigger the activation of a Disaster Recovery Plan (DRP)?

Page : 4/11

16. Your organization is implementing an information classification program. Which of the following is the primary reason for classifying information?
17. Which of the following best describes the concept of "Separation of Duties"?
18. Which of the following is a key benefit of implementing an effective Security Awareness Training program?
19. What is the primary goal of an information security governance program?
20. Your organization has identified a risk with a high impact but low likelihood. Which of the following is the MOST appropriate risk response?

Page : 5/11

21. In the context of information security, what does "Confidentiality" aim to prevent?
22. Who is ultimately responsible for making sure data is classified and protected?
23. Who has the primary responsibility of determining the classification level for information?
24. What is the PRIMARY purpose of risk management in information security?
25. An organization is evaluating its incident response plan (IRP) and aims to align it with best practices. Which of the following is a critical element that should be included to enhance the effectiveness of the IRP?

Page : 6/11

26. Which of the following is a key component of a "Security Awareness Program"?
27. What should management consider the most when classifying data?
28. Which of the following scenarios exemplifies the concept of "Defense in Depth"?
29. Which of the following BEST describes the purpose of risk analysis in an organization's security and risk management process?
30. A company is planning to expand its operations internationally and is concerned about the varied data protection laws in different countries. What is the most effective strategy for managing these legal and regulatory compliance risks?

Page : 7/11

31. Which of the following best describes the primary purpose of implementing security governance within an organization?
32. Which of the following best describes the purpose of risk management in an organization's security strategy?
33. Which of the following best describes the term "Third-Party Risk"?
34. What is the primary purpose of a Business Impact Analysis (BIA)?
35. Which of the following best describes the concept of 'integrity' in the context of information security?

Page : 8/11

36. What is the primary purpose of encryption in cybersecurity?
37. In the context of access control, what does the term "Authentication" refer to?
38. What is the main goal of an Incident Response Plan (IRP)?
39. What is the primary goal of compliance in the context of information security?
40. Which group causes the most risk of fraud and computer compromises?

Page : 9/11

41. Which of the following BEST describes the goal of a Risk Appetite Statement?
42. In the context of information security frameworks, what is the primary goal of ISO/IEC 27001?
43. Which of the following is NOT a primary objective of implementing security controls based on the CIA Triad?
44. What role does an Incident Response Team play in an organization's security posture?
45. What is the primary purpose of conducting a vulnerability assessment?

Page : 10/11

46. What does 'availability' in the CIA Triad refer to?
47. Which of the following is an essential element of effective information security governance?
48. Which of the following best describes the purpose of compliance with legal and regulatory requirements in information security?
49. What is the main difference between qualitative and quantitative risk assessment?
50. What is the primary objective of a Data Classification Policy?

Page : 11/11

51. Which of the following best exemplifies the concept of "Tailgating" in a physical security context?
CISSP Practice Test, Quiz & Flashcards

More practice question and flash cards

Risk & Security Management

Domain_01_CISSP Practice Set 01

Asset Security

Domain_02_CISSP Practice Set 01

Security Architecture & Engineering

Domain_03_CISSP Practice Set 01

Communication & Network Security

Domain_04_CISSP Practice Set 01

Identity & Access Management

Domain_05_CISSP Practice Set 01

Domain 01: Mindmaps, Flashcards and more…

Learn More

CISSP Practice Sets Status

CISSP practice sets and Questions counter

5

CISSP Practice Sets

250

Questions

5.8

Test Submited by Users