CISSP SECURITY AND RISK MANAGEMENT PRACTICE TEST |
STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM |
PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100%
CORRECT ANSWERS | VERIFIED SOLUTIONS
This focused practice examination is designed for information security professionals preparing
for Domain 1 of the CISSP certification: Security and Risk Management. As the largest and most
foundational domain of the CISSP Common Body of Knowledge, this section addresses the core
principles of confidentiality, integrity, and availability alongside governance, compliance, legal
and regulatory frameworks, risk management methodologies, business continuity planning, and
professional ethics. Each question reflects the adaptive testing environment's cognitive
complexity, challenging candidates with enterprise security governance scenarios, international
regulatory compliance dilemmas, quantitative and qualitative risk analysis, policy development,
and strategic risk alignment. By working through these advanced questions with detailed answer
rationales, you will systematically identify knowledge gaps and strengthen your command of the
security management principles essential for passing the CISSP examination.
Table of Contents
Confidentiality, Integrity, and Availability
Security Governance Principles
Legal and Regulatory Compliance
Risk Management Concepts and Frameworks
Security Policies, Standards, and Procedures
Business Continuity and Disaster Recovery
Personnel Security and Security Awareness
Professional Ethics
Third-Party and Supply Chain Risk Management
,Question 1
A security manager is presenting to the board of directors about the organization's security
posture. A board member asks why the organization should invest in security controls beyond
what is legally required. Which response best articulates the relationship between compliance
and risk management?
A) Compliance automatically ensures complete security
B) Compliance establishes a minimum baseline, while risk management addresses threats
beyond regulatory scope to protect business objectives
C) Risk management is unnecessary if the organization is fully compliant
D) Compliance is only relevant for government contractors
Correct Answer: B
Compliance provides a minimum security baseline required by law or regulation. Risk
management extends beyond compliance by identifying and mitigating threats to business
objectives that may not be covered by regulations. Organizations that focus solely on compliance
may remain vulnerable to threats outside regulatory scope.
Question 2
During a quantitative risk analysis, the team calculates that a threat event has an Annualized Rate
of Occurrence of 0.2, an Exposure Factor of 60%, and an asset value of $800,000. What is the
Annualized Loss Expectancy?
A) $160,000
B) $96,000
,C) $480,000
D) $800,000
Correct Answer: B
The Single Loss Expectancy is calculated as Asset Value × Exposure Factor ($800,000 × 0.60 =
$480,000). The Annualized Loss Expectancy is SLE × ARO ($480,000 × 0.2 = $96,000). This
represents the expected annual loss from this threat event and guides cost-justification for
controls.
Question 3
A multinational corporation is harmonizing its privacy program across jurisdictions. The legal
team identifies that GDPR requires a lawful basis for processing personal data, while a country
in Asia requires explicit consent for all data processing regardless of legal basis. Which
governance approach best addresses these conflicting requirements?
A) Apply GDPR standards globally since it is the strictest regulation
B) Implement a tiered data handling matrix that applies the most stringent applicable
requirement per jurisdiction
C) Ignore conflicting requirements and follow headquarters' local laws only
D) Process all data in a jurisdiction with no privacy laws
Correct Answer: B
A tiered data handling matrix allows the organization to apply the specific requirements of each
jurisdiction where data subjects reside, meeting the most stringent requirements where they
apply without imposing unnecessary restrictions on data not subject to those laws. Applying
GDPR globally may conflict with local access requirements.
, Question 4
An organization's acceptable use policy states that employees must not use corporate email for
personal communications. An employee forwards a work-related document to their personal
email to work on it during a flight. The employee argues this was necessary for productivity.
What is the appropriate governance response?
A) Terminate the employee for policy violation
B) Recognize the policy gap and implement a secure remote access solution that enables
productivity while maintaining security
C) Ignore the violation since the employee had good intentions
D) Delete the employee's personal email account
Correct Answer: B
When employees circumvent security policies for legitimate business needs, it indicates a policy
gap rather than malicious intent. The governance response should address the root cause by
providing secure alternatives that meet both security and productivity requirements. This
demonstrates security as a business enabler rather than an obstacle.
Question 5
A Chief Privacy Officer is evaluating a vendor that processes customer data on behalf of the
organization. The vendor provides an ISO 27001 certificate but refuses to provide a SOC 2 Type
II report. The organization is subject to regulations requiring assurance of operational control
effectiveness. What should the CPO conclude?
A) ISO 27001 is sufficient for all regulatory requirements
B) ISO 27001 certifies the design of the ISMS but does not provide the operational effectiveness
testing that a SOC 2 Type II report provides
STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM |
PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100%
CORRECT ANSWERS | VERIFIED SOLUTIONS
This focused practice examination is designed for information security professionals preparing
for Domain 1 of the CISSP certification: Security and Risk Management. As the largest and most
foundational domain of the CISSP Common Body of Knowledge, this section addresses the core
principles of confidentiality, integrity, and availability alongside governance, compliance, legal
and regulatory frameworks, risk management methodologies, business continuity planning, and
professional ethics. Each question reflects the adaptive testing environment's cognitive
complexity, challenging candidates with enterprise security governance scenarios, international
regulatory compliance dilemmas, quantitative and qualitative risk analysis, policy development,
and strategic risk alignment. By working through these advanced questions with detailed answer
rationales, you will systematically identify knowledge gaps and strengthen your command of the
security management principles essential for passing the CISSP examination.
Table of Contents
Confidentiality, Integrity, and Availability
Security Governance Principles
Legal and Regulatory Compliance
Risk Management Concepts and Frameworks
Security Policies, Standards, and Procedures
Business Continuity and Disaster Recovery
Personnel Security and Security Awareness
Professional Ethics
Third-Party and Supply Chain Risk Management
,Question 1
A security manager is presenting to the board of directors about the organization's security
posture. A board member asks why the organization should invest in security controls beyond
what is legally required. Which response best articulates the relationship between compliance
and risk management?
A) Compliance automatically ensures complete security
B) Compliance establishes a minimum baseline, while risk management addresses threats
beyond regulatory scope to protect business objectives
C) Risk management is unnecessary if the organization is fully compliant
D) Compliance is only relevant for government contractors
Correct Answer: B
Compliance provides a minimum security baseline required by law or regulation. Risk
management extends beyond compliance by identifying and mitigating threats to business
objectives that may not be covered by regulations. Organizations that focus solely on compliance
may remain vulnerable to threats outside regulatory scope.
Question 2
During a quantitative risk analysis, the team calculates that a threat event has an Annualized Rate
of Occurrence of 0.2, an Exposure Factor of 60%, and an asset value of $800,000. What is the
Annualized Loss Expectancy?
A) $160,000
B) $96,000
,C) $480,000
D) $800,000
Correct Answer: B
The Single Loss Expectancy is calculated as Asset Value × Exposure Factor ($800,000 × 0.60 =
$480,000). The Annualized Loss Expectancy is SLE × ARO ($480,000 × 0.2 = $96,000). This
represents the expected annual loss from this threat event and guides cost-justification for
controls.
Question 3
A multinational corporation is harmonizing its privacy program across jurisdictions. The legal
team identifies that GDPR requires a lawful basis for processing personal data, while a country
in Asia requires explicit consent for all data processing regardless of legal basis. Which
governance approach best addresses these conflicting requirements?
A) Apply GDPR standards globally since it is the strictest regulation
B) Implement a tiered data handling matrix that applies the most stringent applicable
requirement per jurisdiction
C) Ignore conflicting requirements and follow headquarters' local laws only
D) Process all data in a jurisdiction with no privacy laws
Correct Answer: B
A tiered data handling matrix allows the organization to apply the specific requirements of each
jurisdiction where data subjects reside, meeting the most stringent requirements where they
apply without imposing unnecessary restrictions on data not subject to those laws. Applying
GDPR globally may conflict with local access requirements.
, Question 4
An organization's acceptable use policy states that employees must not use corporate email for
personal communications. An employee forwards a work-related document to their personal
email to work on it during a flight. The employee argues this was necessary for productivity.
What is the appropriate governance response?
A) Terminate the employee for policy violation
B) Recognize the policy gap and implement a secure remote access solution that enables
productivity while maintaining security
C) Ignore the violation since the employee had good intentions
D) Delete the employee's personal email account
Correct Answer: B
When employees circumvent security policies for legitimate business needs, it indicates a policy
gap rather than malicious intent. The governance response should address the root cause by
providing secure alternatives that meet both security and productivity requirements. This
demonstrates security as a business enabler rather than an obstacle.
Question 5
A Chief Privacy Officer is evaluating a vendor that processes customer data on behalf of the
organization. The vendor provides an ISO 27001 certificate but refuses to provide a SOC 2 Type
II report. The organization is subject to regulations requiring assurance of operational control
effectiveness. What should the CPO conclude?
A) ISO 27001 is sufficient for all regulatory requirements
B) ISO 27001 certifies the design of the ISMS but does not provide the operational effectiveness
testing that a SOC 2 Type II report provides