1.0 Security and Risk Management CISSP Practice Quiz
128 exam-style questions covering 16% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regional bank's risk committee is rebuilding its information security program after a regulator's MRA letter. The CISO asks for guidance on professional ethics that balances business objectives, compliance, and security. What should be recommended?
- A. Escalate the issue through appropriate channels while protecting affected parties and preserving professional integrity
- B. Accept hospitality from a vendor during a tool selection without disclosing it
- C. List CISSP on the resume before passing the certification exam
- D. Hide an audit finding from the board because it would be politically awkward
Professional ethics require security professionals to act honorably, protect society, and follow lawful and responsible processes. This is the correct answer.
A children's hospital network is rewriting its security policies after a state attorney general inquiry. The security leader must make a risk-based decision involving professional ethics. What is the best course of action?
- A. Document the ethical concern, seek guidance from approved governance channels, and avoid retaliatory or deceptive behavior
- B. Represent qualifications and certifications you have not legitimately earned
- C. Withhold a control deficiency from senior leadership to avoid embarrassment
- D. Follow a directive that requires unlawful conduct because it came from a manager
A documented escalation path helps address ethics issues without creating additional misconduct. This is the correct answer.
A pharmaceutical manufacturer is integrating two acquired subsidiaries into a single security governance model. An internal assessment finds that current practices for professional ethics are inconsistent. Which action should the security professional prioritize?
- A. Post confidential investigation evidence publicly before raising it through internal channels
- B. Follow the ISC2 Code of Professional Ethics when a business request conflicts with public trust or lawful conduct
- C. Take a vendor's gift during an active procurement without notifying compliance
- D. Hold out as certified in roles for which the credential has not been issued
The ISC2 ethical canons prioritize protecting society, acting honorably, providing diligent service, and advancing the profession. This is the correct answer.
A defense contractor is updating its risk management process to align with revised CMMC requirements. A board review identifies a gap in professional ethics. Which recommendation best aligns with CISSP-level practice?
- A. Permit gifts from bidders during a control selection with no disclosure log
- B. Separate personal benefit from professional security recommendations when evaluating vendors or controls
- C. Misstate professional credentials on a public profile or pitch
- D. Avoid documenting a critical finding because it would damage executive reputations
Conflicts of interest can undermine professional judgment and must be disclosed or avoided. This is the correct answer.
A research university is reconciling federal grant security requirements with its decentralized IT culture. A security manager must advise executives about professional ethics. Which response is most appropriate?
- A. Misrepresent training, education, or certifications when bidding for engagements
- B. Ask counsel or the ethics office for guidance when legal duty and business pressure appear to conflict
- C. Withhold a material finding from the audit committee due to public-relations concerns
- D. Treat 'follow orders' as overriding the legal and ethical duty to refuse
Complex ethical issues should be resolved through qualified governance channels. This is the correct answer.
A federal civilian agency is preparing its annual FISMA reporting and authorization-to-operate review. A cross-functional team is evaluating professional ethics. Which decision provides the strongest governance-aligned outcome?
- A. Carry out a manager's directive that clearly violates law or regulation
- B. Publicly tweet incident details before contacting management or counsel
- C. Use the organizational code of ethics to guide employee conduct while still respecting higher legal and professional obligations
- D. Receive expensive vendor swag during the RFP and not declare the conflict
Organizational codes help translate ethical expectations into workplace behavior, but they do not override law or professional responsibility. This is the correct answer.
A regional utility is briefing its board on cyber risk to operational technology and customer billing systems. The CISO asks for guidance on professional ethics that balances business objectives, compliance, and security. What should be recommended?
- A. Skip internal escalation and go straight to social media with sensitive evidence
- B. Allow tool-selection committee members to accept undisclosed vendor gifts
- C. Protect confidential information while reporting unethical conduct through authorized channels
- D. Claim memberships in professional bodies the candidate does not actually hold
Ethical reporting should minimize unnecessary disclosure while still enabling appropriate action. This is the correct answer.
A multinational logistics provider is reconciling security obligations across thirty-plus jurisdictions. A security manager must advise executives about professional ethics. Which response is most appropriate?
- A. Bury a regulator-relevant finding because publicly acknowledging it is uncomfortable
- B. Comply with leadership instructions that would require breaking the law
- C. Disclose confidential findings to the press before using the established reporting chain
- D. Refuse to conceal material security risk from stakeholders who have a legitimate need to know
Ethical practice requires honest and responsible communication about risks that can affect the organization or the public. This is the correct answer.
Key Terms in This Domain
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- ISC2 Code of Professional Ethics: Mandatory ethical canons all CISSPs must uphold
- NIST Risk Management Framework: NIST SP 800-37 lifecycle for managing information system risk
- ISO 27001: International standard for an information security management system (ISMS)
- HSM: Hardware Security Module: tamper-resistant key management device
- OWASP Top 10: Top web application security risks (e.g., injection, broken access control)
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- Due Diligence: Ongoing effort to investigate, assess, and verify controls and risks
- Risk: Likelihood of a threat exploiting a vulnerability and resulting impact
- Risk Acceptance: Acknowledge and tolerate risk without further mitigation
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/security-and-risk-management/
<a href="https://quizbuffet.com/isc2-cissp/security-and-risk-management/">CISSP (ISC2) Security and Risk Management practice quiz on QuizBuffet</a>
Other CISSP Domains
- 2.0 Asset Security
- 3.0 Security Architecture and Engineering
- 4.0 Communication and Network Security
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.