CISSP Security and Risk Management 4 — Questions and Answers
Question 1: Which governance framework uses a RACI matrix and focuses on aligning IT processes with business goals using 37 IT processes across five domains?
- ITIL v4
- COBIT 2019 (Correct answer)
- ISO/IEC 27001
- NIST CSF
Correct answer: COBIT 2019
COBIT (Control Objectives for Information and Related Technologies) provides a governance framework with process models and uses RACI charts to define accountability.
Question 2: An organization decides to discontinue a product line because the regulatory compliance cost exceeds potential profit. This represents which risk response?
- Risk mitigation
- Risk transference
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by ceasing the activity that creates the risk exposure.
Question 3: Which legal concept holds that an organization can be found liable if it fails to implement security controls that a 'reasonable person' would consider adequate?
- Strict liability
- Due care / Due diligence (Correct answer)
- Respondeat superior
- Vicarious liability
Correct answer: Due care / Due diligence
Due care (doing the right thing) combined with due diligence (proving you did it) form the legal standard that organizations must meet to avoid negligence claims.
Question 4: A Recovery Time Objective (RTO) differs from a Recovery Point Objective (RPO) in that RTO defines:
- The maximum acceptable data loss measured in time
- The maximum tolerable downtime before a system must be restored (Correct answer)
- The point in time to which systems must be recovered
- The cost threshold for activating disaster recovery
Correct answer: The maximum tolerable downtime before a system must be restored
RTO specifies the maximum acceptable length of time a system can be offline, while RPO defines the maximum acceptable amount of data loss.
Question 5: Which privacy principle requires that personal data collected for one specified purpose should not be used for a different, incompatible purpose?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Accuracy
Correct answer: Purpose limitation
Purpose limitation, a core GDPR principle, restricts use of personal data to the original stated purpose unless new consent is obtained.
Question 6: A company's Single Loss Expectancy (SLE) for a server failure is $200,000 and the Annualized Rate of Occurrence (ARO) is 0.25. What is the Annualized Loss Expectancy (ALE)?
- $50,000 (Correct answer)
- $200,000
- $800,000
- $25,000
Correct answer: $50,000
ALE = SLE × ARO = $200,000 × 0.25 = $50,000, representing the expected annual loss from this specific threat.
Question 7: Which personnel security control requires that critical roles be filled by two or more employees to prevent knowledge concentration and ensure continuity?
- Mandatory vacations
- Job rotation
- Cross-training / succession planning (Correct answer)
- Background screening
Correct answer: Cross-training / succession planning
Cross-training and succession planning ensure that at least two people can perform each critical function, reducing single points of failure in human resources.
Which governance framework uses a RACI matrix and focuses on aligning IT processes with business goals using 37 IT processes across five domains?