ISC2 CISSP Risk Management And Threat Modeling Practice Test

 

1 Security and Risk Management • 25 original questions

This CISSP practice test focuses on risk management and threat modeling through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

VanArsdel Energy is revising controls for its e-commerce application. A review highlights Security and privacy control assessments. The incident response manager must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The decision affects 64 business processes and has a named executive risk owner.

  1. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.

Correct answer: A

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while minimizing irreversible action until facts and authority are established.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while minimizing irreversible action until facts and authority are established.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

D: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 2

An auditor asks Northwind Health to demonstrate how it handles Continuous monitoring and measurement in the clinical records environment. The security governance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The decision affects 81 business processes and has a named executive risk owner.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous monitoring and measurement while preserving evidence needed for later review.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous monitoring and measurement while preserving evidence needed for later review.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 3

After a business change, Coho Insurance discovers that Internal and external risk reporting is not handled consistently for the remote access service. The IAM architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The decision affects 7 business processes and has a named executive risk owner.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  4. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Internal and external risk reporting without granting broader privilege than the business need requires.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Internal and external risk reporting without granting broader privilege than the business need requires.

C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

D: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 4

  1. Datum Analytics is preparing a security decision for the customer identity platform. The decision involves Continuous improvement and risk maturity modeling. The application security architect must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The decision affects 24 business processes and has a named executive risk owner.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  5. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous improvement and risk maturity modeling without creating a new single point of failure.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous improvement and risk maturity modeling without creating a new single point of failure.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 5

During a risk workshop for the data analytics lake, the team identifies Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI as the deciding issue. The incident response manager is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The decision affects 41 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI while ensuring that emergency access cannot become permanent access.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 6

A control owner at City Power proposes a quick technical fix for Threat modeling concepts and methodologies in the branch-office network. The security governance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The decision affects 58 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: D

Why: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. It directly addresses Threat modeling concepts and methodologies while allowing independent verification of the control outcome.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

B: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. It directly addresses Threat modeling concepts and methodologies while allowing independent verification of the control outcome.

Learning point: Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations. Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations.

Question 7

Tailspin Logistics is standardizing security across several business units. The industrial control network raises a question about Threat and vulnerability identification. The IAM architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The decision affects 75 business processes and has a named executive risk owner.

  1. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while accounting for third-party and lifecycle dependencies.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while accounting for third-party and lifecycle dependencies.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 8

During a business continuity exercise, Alpine Sports asks the application security architect to address Risk analysis, assessment, and scope for its research data repository. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The decision affects 92 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while maintaining the organization’s stated risk appetite.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

B: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while maintaining the organization’s stated risk appetite.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 9

Fabrikam Manufacturing is revising controls for its payment processing service. A review highlights Risk response and treatment including cyber insurance. The incident response manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The decision affects 18 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance while meeting the business objective with the least unnecessary operational complexity.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 10

An auditor asks Trey Research to demonstrate how it handles Preventive, detective, and corrective controls in the software delivery pipeline. The security governance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The decision affects 35 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls while keeping the control sustainable for normal operations.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

C: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls while keeping the control sustainable for normal operations.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 11

After a business change, Margie Travel discovers that Security and privacy control assessments is not handled consistently for the AI-assisted customer service platform. The IAM architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The decision affects 52 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while ensuring the decision can be repeated consistently across business units.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while ensuring the decision can be repeated consistently across business units.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 12

Wide World Importers is preparing a security decision for the global collaboration platform. The decision involves Continuous monitoring and measurement. The application security architect must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The decision affects 69 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous monitoring and measurement while preserving clear accountability and audit evidence.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous monitoring and measurement while preserving clear accountability and audit evidence.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Continuous monitoring and measurement in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 13

During a risk workshop for the e-commerce application, the team identifies Internal and external risk reporting as the deciding issue. The incident response manager is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The decision affects 86 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Internal and external risk reporting while protecting sensitive data throughout the change.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

B: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Internal and external risk reporting in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Internal and external risk reporting while protecting sensitive data throughout the change.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 14

A control owner at Litware Services proposes a quick technical fix for Continuous improvement and risk maturity modeling in the clinical records environment. The security governance lead must address the control objective while preserving availability of the critical business service. What should happen FIRST? The decision affects 12 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous improvement and risk maturity modeling while preserving availability of the critical business service.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Continuous improvement and risk maturity modeling while preserving availability of the critical business service.

C: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Continuous improvement and risk maturity modeling in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 15

Humongous Insurance is standardizing security across several business units. The remote access service raises a question about Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI. The IAM architect needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The decision affects 29 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Identify the security property the business requirement depends on, then select controls that directly protect that property.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI without replacing governance with a technology-only shortcut.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI without replacing governance with a technology-only shortcut.

D: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Risk frameworks such as ISO, NIST, COBIT, SABSA, and PCI in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 16

During a post-incident improvement program, Woodgrove Bank asks the application security architect to address Threat modeling concepts and methodologies for its customer identity platform. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The decision affects 46 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. It directly addresses Threat modeling concepts and methodologies while keeping the process defensible to auditors and business owners.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. It directly addresses Threat modeling concepts and methodologies while keeping the process defensible to auditors and business owners.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Threat modeling concepts and methodologies in this scenario.

Learning point: Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations. Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations.

Question 17

Relecloud Systems is revising controls for its data analytics lake. A review highlights Threat and vulnerability identification. The incident response manager must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The decision affects 63 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while minimizing irreversible action until facts and authority are established.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while minimizing irreversible action until facts and authority are established.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 18

An auditor asks Contoso Financial to demonstrate how it handles Risk analysis, assessment, and scope in the branch-office network. The security governance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The decision affects 80 business processes and has a named executive risk owner.

  1. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while preserving evidence needed for later review.

Option review:

A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while preserving evidence needed for later review.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 19

After a business change, Lucerne Publishing discovers that Risk response and treatment including cyber insurance is not handled consistently for the industrial control network. The IAM architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The decision affects 6 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance without granting broader privilege than the business need requires.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance without granting broader privilege than the business need requires.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 20

Lamna Healthcare is preparing a security decision for the research data repository. The decision involves Preventive, detective, and corrective controls. The application security architect must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The decision affects 23 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls without creating a new single point of failure.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls without creating a new single point of failure.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 21

During a risk workshop for the payment processing service, the team identifies Security and privacy control assessments as the deciding issue. The incident response manager is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The decision affects 40 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while ensuring that emergency access cannot become permanent access.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Security and privacy control assessments while ensuring that emergency access cannot become permanent access.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Security and privacy control assessments in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 22

A control owner at Consolidated Messenger proposes a quick technical fix for Threat and vulnerability identification in the software delivery pipeline. The security governance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The decision affects 57 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while allowing independent verification of the control outcome.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Threat and vulnerability identification in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Threat and vulnerability identification while allowing independent verification of the control outcome.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 23

Proseware Labs is standardizing security across several business units. The AI-assisted customer service platform raises a question about Risk analysis, assessment, and scope. The IAM architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The decision affects 74 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while accounting for third-party and lifecycle dependencies.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk analysis, assessment, and scope while accounting for third-party and lifecycle dependencies.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Risk analysis, assessment, and scope in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 24

During a quarterly security review, Southridge Media asks the application security architect to address Risk response and treatment including cyber insurance for its global collaboration platform. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The decision affects 91 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.

Correct answer: B

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance while maintaining the organization’s stated risk appetite.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Risk response and treatment including cyber insurance while maintaining the organization’s stated risk appetite.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

D: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Risk response and treatment including cyber insurance in this scenario.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Question 25

Adventure Works is revising controls for its e-commerce application. A review highlights Preventive, detective, and corrective controls. The incident response manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The decision affects 17 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: D

Why: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Preventive, detective, and corrective controls in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. It directly addresses Preventive, detective, and corrective controls while meeting the business objective with the least unnecessary operational complexity.

Learning point: Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result. Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk.

Popular posts

img