← All CISSP Flashcard Decks

Security and Risk Management Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Risk Management flashcards as text
  1. Which governance framework uses a RACI matrix and focuses on aligning IT processes with business goals using 37 IT processes across five domains?

    Answer: COBIT 2019

    COBIT (Control Objectives for Information and Related Technologies) provides a governance framework with process models and uses RACI charts to define accountability.

  2. An organization decides to discontinue a product line because the regulatory compliance cost exceeds potential profit. This represents which risk response?

    Answer: Risk avoidance

    Risk avoidance eliminates the risk entirely by ceasing the activity that creates the risk exposure.

  3. Which legal concept holds that an organization can be found liable if it fails to implement security controls that a 'reasonable person' would consider adequate?

    Answer: Due care / Due diligence

    Due care (doing the right thing) combined with due diligence (proving you did it) form the legal standard that organizations must meet to avoid negligence claims.

  4. A Recovery Time Objective (RTO) differs from a Recovery Point Objective (RPO) in that RTO defines:

    Answer: The maximum tolerable downtime before a system must be restored

    RTO specifies the maximum acceptable length of time a system can be offline, while RPO defines the maximum acceptable amount of data loss.

  5. Which privacy principle requires that personal data collected for one specified purpose should not be used for a different, incompatible purpose?

    Answer: Purpose limitation

    Purpose limitation, a core GDPR principle, restricts use of personal data to the original stated purpose unless new consent is obtained.

  6. A company's Single Loss Expectancy (SLE) for a server failure is $200,000 and the Annualized Rate of Occurrence (ARO) is 0.25. What is the Annualized Loss Expectancy (ALE)?

    Answer: $50,000

    ALE = SLE × ARO = $200,000 × 0.25 = $50,000, representing the expected annual loss from this specific threat.

  7. Which personnel security control requires that critical roles be filled by two or more employees to prevent knowledge concentration and ensure continuity?

    Answer: Cross-training / succession planning

    Cross-training and succession planning ensure that at least two people can perform each critical function, reducing single points of failure in human resources.