TechNuggets Academy

Security and Risk Management

Free ISC2 Certified Information Systems Security Professional (CISSP) practice — 6 questions on Security and Risk Management, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security and Risk Management
A risk assessment values a data center at $2,000,000. A flood scenario has an exposure factor of 40% and an annualized rate of occurrence of 0.5. What is the Annualized Loss Expectancy (ALE) for this risk?
SLE = AV × EF = $2,000,000 × 0.40 = $800,000. ALE = SLE × ARO = $800,000 × 0.5 = $400,000, correctly combining both loss magnitude and frequency into an annualized figure.
Question 2 of 6 · Security and Risk Management
A CISSP-certified professional discovers that following her employer's instructions to suppress disclosure of a public safety vulnerability would conflict with the ISC2 Code of Ethics. According to the Code's canon hierarchy, which principle takes precedence in resolving this conflict?
The ISC2 Code of Ethics lists its four canons in priority order, and 'Protect society, the commonwealth, and the infrastructure' is the first and highest canon, taking precedence over duties to employers or the profession when conflicts arise.
Question 3 of 6 · Security and Risk Management
A multinational organization is drafting incident response and liability contracts for a subsidiary operating in a civil law jurisdiction such as France or Germany. Which characteristic of civil law systems should most influence the security team's legal risk assessment?
Civil law systems, prevalent in continental Europe, are based on comprehensive codified statutes; judges apply the code rather than being bound by precedent, meaning contracts must be drafted to align tightly with statutory text rather than relying on case law interpretation.
Question 4 of 6 · Security and Risk Management
A Business Impact Analysis determines that a critical order-processing system has a Maximum Tolerable Downtime (MTD) of 8 hours. The BC/DR team sets a Recovery Time Objective (RTO) of 6 hours and allocates 2 additional hours for post-restoration data verification and reconciliation before the system resumes full production use. What does this 2-hour allocation represent?
Work Recovery Time (WRT) is the time needed after systems are technically restored (RTO) to verify data integrity and reconcile transactions before full production resumes. MTD = RTO + WRT, so 8 hours = 6 hours (RTO) + 2 hours (WRT).
Question 5 of 6 · Security and Risk Management
A US-based cloud provider processes personal data of EU residents on behalf of an EU data controller, and the provider is not covered by the EU-US Data Privacy Framework adequacy decision. Which mechanism should the organization implement to lawfully transfer this personal data outside the EEA under GDPR?
In the absence of an adequacy decision, GDPR Article 46 permits transfers using appropriate safeguards, with Standard Contractual Clauses being the most commonly used and Commission-approved mechanism for controller-to-processor international transfers.
Question 6 of 6 · Security and Risk Management
An organization outsources payroll processing to a third-party vendor and includes an indemnification clause requiring the vendor to cover financial losses resulting from a data breach caused by vendor negligence. Which risk treatment strategy does this arrangement BEST represent, and what risk typically remains with the organization regardless of this clause?
Indemnification clauses shift financial liability for losses to the vendor, which is a classic example of risk transfer. However, regulators and the public typically hold the data controller (the originating organization) accountable for breach notification duties, fines, and reputational harm — this residual risk cannot be contractually transferred away.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →