CISSP Security and Risk Management 5 — Questions and Answers
Question 1: Which type of security policy provides the highest-level direction and is signed by executive leadership to express management commitment to security?
- Baseline policy
- Procedure
- Standard
- Organizational (master) security policy (Correct answer)
Correct answer: Organizational (master) security policy
The organizational or master security policy is the top-level document that expresses executive commitment and sets the strategic direction for the entire security program.
Question 2: In the context of security governance, which committee typically has responsibility for approving major security investments and accepting residual risk at the enterprise level?
- IT steering committee
- Change advisory board
- Security operations center
- Executive management / board of directors (Correct answer)
Correct answer: Executive management / board of directors
Ultimate risk ownership and acceptance authority rests with executive management or the board, who are accountable for organizational outcomes.
Question 3: Which attack surface analysis technique involves systematically identifying all entry points where untrusted data enters a system?
- Penetration testing
- Attack surface mapping / threat surface analysis (Correct answer)
- Vulnerability scanning
- Red teaming
Correct answer: Attack surface mapping / threat surface analysis
Attack surface mapping catalogs all points where an adversary could interact with a system, enabling prioritized hardening of the most exposed areas.
Question 4: The Gramm-Leach-Bliley Act (GLBA) primarily requires which type of organization to protect customer financial information?
- Healthcare providers
- Federal government agencies
- Financial institutions (Correct answer)
- Educational institutions
Correct answer: Financial institutions
GLBA mandates that banks, insurance companies, and other financial institutions implement safeguards to protect the privacy of consumer financial information.
Question 5: Which risk analysis approach assigns probability and impact using descriptive scales, is faster to perform, and is well-suited when hard data is unavailable?
- Quantitative analysis
- Monte Carlo simulation
- Qualitative analysis (Correct answer)
- Annualized loss expectancy calculation
Correct answer: Qualitative analysis
Qualitative analysis uses descriptive ratings (e.g., High/Medium/Low) based on expert opinion, making it faster but more subjective than quantitative methods.
Question 6: A security awareness program is MOST effective when it:
- Is conducted once during employee onboarding only
- Focuses exclusively on technical staff and IT personnel
- Uses role-based, continuous training tied to real threats employees face (Correct answer)
- Relies solely on written policies distributed annually
Correct answer: Uses role-based, continuous training tied to real threats employees face
Effective security awareness programs are ongoing, tailored to different roles, and use realistic scenarios relevant to each employee's actual work environment.
Question 7: Which concept describes the combination of policies, procedures, standards, and guidelines that collectively define how security is managed across an organization?
- Security architecture
- Security posture
- Security governance framework (Correct answer)
- Defense in depth
Correct answer: Security governance framework
A security governance framework integrates all security management elements—policies, processes, roles, and metrics—to ensure consistent, accountable security decision-making.
Which type of security policy provides the highest-level direction and is signed by executive leadership to express management commitment to security?