Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

CISSP SECURITY AND RISK MANAGEMENT PRACTICE TEST | STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED SOLUTIONS

Document preview thumbnail
Preview 4 out of 65 pages

CISSP SECURITY AND RISK MANAGEMENT PRACTICE TEST | STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED SOLUTIONS

Content preview

CISSP SECURITY AND RISK MANAGEMENT PRACTICE TEST |
STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM |
PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100%
CORRECT ANSWERS | VERIFIED SOLUTIONS

This focused practice examination is designed for information security professionals preparing
for Domain 1 of the CISSP certification: Security and Risk Management. As the largest and most
foundational domain of the CISSP Common Body of Knowledge, this section addresses the core
principles of confidentiality, integrity, and availability alongside governance, compliance, legal
and regulatory frameworks, risk management methodologies, business continuity planning, and
professional ethics. Each question reflects the adaptive testing environment's cognitive
complexity, challenging candidates with enterprise security governance scenarios, international
regulatory compliance dilemmas, quantitative and qualitative risk analysis, policy development,
and strategic risk alignment. By working through these advanced questions with detailed answer
rationales, you will systematically identify knowledge gaps and strengthen your command of the
security management principles essential for passing the CISSP examination.

Table of Contents
Confidentiality, Integrity, and Availability
Security Governance Principles
Legal and Regulatory Compliance
Risk Management Concepts and Frameworks
Security Policies, Standards, and Procedures
Business Continuity and Disaster Recovery
Personnel Security and Security Awareness
Professional Ethics
Third-Party and Supply Chain Risk Management

,Question 1

A security manager is presenting to the board of directors about the organization's security

posture. A board member asks why the organization should invest in security controls beyond

what is legally required. Which response best articulates the relationship between compliance

and risk management?

A) Compliance automatically ensures complete security

B) Compliance establishes a minimum baseline, while risk management addresses threats

beyond regulatory scope to protect business objectives

C) Risk management is unnecessary if the organization is fully compliant

D) Compliance is only relevant for government contractors

Correct Answer: B

Compliance provides a minimum security baseline required by law or regulation. Risk

management extends beyond compliance by identifying and mitigating threats to business

objectives that may not be covered by regulations. Organizations that focus solely on compliance

may remain vulnerable to threats outside regulatory scope.

Question 2

During a quantitative risk analysis, the team calculates that a threat event has an Annualized Rate

of Occurrence of 0.2, an Exposure Factor of 60%, and an asset value of $800,000. What is the

Annualized Loss Expectancy?

A) $160,000

B) $96,000

,C) $480,000

D) $800,000

Correct Answer: B

The Single Loss Expectancy is calculated as Asset Value × Exposure Factor ($800,000 × 0.60 =

$480,000). The Annualized Loss Expectancy is SLE × ARO ($480,000 × 0.2 = $96,000). This

represents the expected annual loss from this threat event and guides cost-justification for

controls.

Question 3

A multinational corporation is harmonizing its privacy program across jurisdictions. The legal

team identifies that GDPR requires a lawful basis for processing personal data, while a country

in Asia requires explicit consent for all data processing regardless of legal basis. Which

governance approach best addresses these conflicting requirements?

A) Apply GDPR standards globally since it is the strictest regulation

B) Implement a tiered data handling matrix that applies the most stringent applicable

requirement per jurisdiction

C) Ignore conflicting requirements and follow headquarters' local laws only

D) Process all data in a jurisdiction with no privacy laws

Correct Answer: B

A tiered data handling matrix allows the organization to apply the specific requirements of each

jurisdiction where data subjects reside, meeting the most stringent requirements where they

apply without imposing unnecessary restrictions on data not subject to those laws. Applying

GDPR globally may conflict with local access requirements.

, Question 4

An organization's acceptable use policy states that employees must not use corporate email for

personal communications. An employee forwards a work-related document to their personal

email to work on it during a flight. The employee argues this was necessary for productivity.

What is the appropriate governance response?

A) Terminate the employee for policy violation

B) Recognize the policy gap and implement a secure remote access solution that enables

productivity while maintaining security

C) Ignore the violation since the employee had good intentions

D) Delete the employee's personal email account

Correct Answer: B

When employees circumvent security policies for legitimate business needs, it indicates a policy

gap rather than malicious intent. The governance response should address the root cause by

providing secure alternatives that meet both security and productivity requirements. This

demonstrates security as a business enabler rather than an obstacle.

Question 5

A Chief Privacy Officer is evaluating a vendor that processes customer data on behalf of the

organization. The vendor provides an ISO 27001 certificate but refuses to provide a SOC 2 Type

II report. The organization is subject to regulations requiring assurance of operational control

effectiveness. What should the CPO conclude?

A) ISO 27001 is sufficient for all regulatory requirements

B) ISO 27001 certifies the design of the ISMS but does not provide the operational effectiveness

testing that a SOC 2 Type II report provides

Document information

Uploaded on
August 3, 2026
Number of pages
65
Written in
2026/2027
Type
Exam (elaborations)
Contains
Unknown
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
111
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions