Browse all practice questions for the CISSP Domain 3 – Risk Identification, Monitoring, and Analysis Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 3 – Risk Identification, Monitoring, and Analysis Practice Test 2026 - Free CISSP Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which step follows after identifying risks during the risk management process?
  • Which of the following best describes "threat modeling"?
  • What role does continuous risk assessment play in cybersecurity?
  • What is the primary purpose of vulnerability scanning?
  • What should Susan track to predict high-risk areas in her organization?
  • What is the annualized loss expectancy for a tornado affecting Atwood Landing's data center?
  • What type of scanning is likely occurring if an outsider is trying to connect using TCP on port 22?
  • What is a likely consequence of a successful denial-of-service attack?
  • What is a control assessment?
  • Which of the following best defines 'zero-day vulnerability'?
  • The primary focus of risk identification is to determine what?
  • What is the role of authorization controls in data security?
  • Which process involves the continuous evaluation of risk management strategies?
  • In the context of software testing, what does "mutation testing" primarily evaluate?
  • What risk management strategy is indicated if Rolando's organization decides to take no action regarding California mudslide risks?
  • What type of log entry is generated when a Windows system is rebooted?
  • What does the term "cyber hygiene" refer to?
  • What is a key benefit of implementing a risk management framework?
  • What is the purpose of an incident response plan in relation to risk management?
  • What type of risks do insider threats represent?
  • Why is using Netflow records beneficial for identifying botnet activity?
  • How can cyber insurance aid in managing risks?
  • Which of the following describes the function of risk analysis?
  • What is the purpose of a Business Impact Analysis (BIA)?
  • What technology should be used to ensure logs can be time sequenced across the infrastructure?
  • After creating a list of assets in a business impact analysis, what should the team do next?
  • Which business impact assessment tool is best for evaluating the effect of a failure on customer confidence?
  • How does a risk management framework assist organizations?
  • What is an example of a qualitative risk assessment technique?
  • When conducting a port scan, what type of devices is most likely discovered if ports 80, 443, 515, and 9100 are responding?
  • What is the purpose of a risk appetite statement?
  • Which of the following is a key step in the risk management process?
  • In risk assessment, what does "impact" refer to?
  • Which entity is responsible for promoting the Security Risk Management framework derived from ISO standards?
  • What is an example of an external risk factor that organizations need to monitor?
  • What protocol is used by Port 22 for administrative connections?
  • What is the potential benefit of engaging third-party security consultants in risk management?
  • What is the primary focus of risk monitoring?
  • What is one major limitation of using automated tools for vulnerability scanning?
  • What is a common tool used for assessing risks in security practices?
  • Which document outlines an organization's strategy for managing risks?
  • How do security policies contribute to risk management?
  • During a penetration test, which potential hazard could lead to an unexpected application shutdown?
  • Which NIST special publication is focused on the assessment of security and privacy controls?
  • What action should be considered the first step after a vulnerability is identified?
  • In terms of risk analysis, what are "threat vectors"?
  • Which system does not natively support syslog events?
  • What does the term "risk tolerance" define?
  • What is the difference between qualitative and quantitative risk assessment?
  • What term best describes the situation when an intrusion detection system reports high-volume inbound traffic without a confirmed security compromise?
  • How can organizations monitor risks effectively?
  • What does the term “control” in risk management typically refer to?
  • What is the significance of external audits in risk monitoring?
  • What risk management strategy involves implementing an intrusion prevention system to block network attacks?
  • What kind of analysis involves breaking a system down into key elements such as trust boundaries and data flow paths?
  • What tool is specifically designed to test a web browser's handling of unexpected data?
  • Which tool aids in documenting and analyzing security incidents for risk identification?
  • What type of attack is indicated by the log entry with the string ../../../etc/passwd?
  • What type of attack is characterized by overwhelming traffic causing service disruption?
  • How can organizations assess their risk appetite?
  • Which method can ensure all Windows systems send identical logging information to a central logging system?
  • What term is used for the testing intended to uncover new bugs after changes in software?
  • What does the acronym SRA stand for in risk management?
  • What is an important outcome of conducting regular audits on risk management practices?
  • Which remediation strategy is not effective for a vulnerability identified by a scanner?
  • What type of vulnerabilities are least likely to be detected by a vulnerability scanner?
  • When should vulnerability scans be conducted for maximum effectiveness?
  • Which type of tool is NOT used for testing the security of applications?
  • Which of the following is generally not a risk associated with penetration testing?
  • What does the term "risk appetite" mean?
  • In the context of security risks, who represents the threat when a hacker exploits a vulnerability?
  • What aspect is primarily analyzed during the assessment of risk in information systems?
  • How can organizations effectively communicate risk management practices?
  • What is the role of education and training in risk mitigation?
  • What message logging standard is widely adopted for enterprise devices such as network devices and Linux systems?
  • Which term describes the likelihood that a specific risk will occur?
  • What is the role of key risk indicators (KRIs) in risk monitoring?
  • During a log review, what type of attack is indicated by repeated invalid login attempts from the same user?
  • What should an organization do with risks that are deemed acceptable?
  • In risk management, what does the term "vulnerability" refer to?
  • What major issue arises if Jim's IT staff do not regularly review backup logs?
  • Which risk assessment approach combines both quantitative and qualitative methods?
  • Nmap is categorized as which type of tool?
  • What type of tool should Alex use to test for format string vulnerabilities in web applications?
  • If Susan discovers services on TCP and UDP 137-139 and TCP 445 and 1433, what type of server is she likely connecting to?
  • What is the main advantage of using a framework like NIST for risk management?
  • After discovering a critical vulnerability, what is Robin's next best action?
  • What is an essential component of a risk management process?
  • Which of the following is NOT a benefit of risk monitoring?
  • What is a primary goal of risk management in organizations?
  • Which regulatory standard is specifically focused on the protection of electronic patient health information?
  • What can be considered a benefit of comprehensive security training for staff?
  • Which element is crucial for understanding the potential impact of identified risks in an organization?
  • What is the role of risk treatment in the risk management process?
  • What term describes an occurrence that violates an organization’s security policy?
  • What does a threat landscape encompass?
  • What risk management strategy is utilized when implementing safeguards to lessen the impact of potential threats?
  • What is the purpose of a risk register?
  • What is the purpose of regression testing in software development?
  • Which of the following methods is considered ineffective for preventing data tampering?
  • What type of risk is associated with legal penalties and non-compliance with regulations?
  • Which document outlines the procedures for identifying, assessing, and treating risks?
  • What does a risk mitigation strategy involve?
  • If Kara's primary concern is preventing eavesdropping attacks, which port should she block?
  • Where is Tom most likely to find information on the approval process for modifications to system security settings?
  • Which formula accurately represents the determination of risk?
  • Which of the following is a common framework used for risk management?
  • What type of risk assessment focuses on identifying the potential impact of a risk?
  • What is the primary purpose of conducting a vulnerability assessment?
  • What concern might arise from a limited port scan?
  • What is the significance of threat intelligence in risk management?
  • What status message indicates a port is accessible with an application accepting connections?
  • When a zero-day vulnerability is reported, what is the best initial action to identify affected systems?
  • What is the primary goal of risk identification in cybersecurity?
  • Which technique is used to control access based on user roles?
  • Which type of logs are critical in ensuring the security compliance of systems in an organization?
  • What service typically uses port 53 for communication?
  • Which tool is typically used to scan services running on TCP port 443?
  • What is one key factor in determining the appropriate risk response strategy?
  • What is the primary benefit of using historical data in risk assessments?
  • What is the first essential step that should be taken prior to conducting a penetration test?
  • Which type of assessment is focused on quantifying loss in terms of monetary value?
  • Which method involves analyzing past incidents to identify future risks?
  • Which of the following is an example of a qualitative assessment tool?
  • What is the objective of a black box penetration test?
  • In a gray box penetration test, what issue will occur if the client provides nonroutable IP addresses for scanning?
  • What type of scan is indicated by the presence of URG, FIN, and PSH flags being set during a penetration test?
  • What should be documented when a risk is accepted in the business continuity planning process?
  • What is the purpose of fuzzers in application security testing?
  • What is inherent risk?
  • What is the ARO of a flood in a 100-year flood plain?
  • What is the term for risks arising from the use of third-party vendors?
  • What type of tool is used to gather information about system services and determine their versions based on banner information?
  • What is the primary function of Metasploit in penetration testing?
  • What is the purpose of a risk register?
  • How can an organization ensure compliance with security baselines for Windows PCs effectively?
  • What is the annualized rate of occurrence for a tornado at Atwood Landing's data center?
  • Which framework is specifically focused on information security controls?
  • What potential issue can arise from improper log handling settings in a system?
  • Which technique would best help Jim identify compromised systems in a botnet?
  • Which attack type shows patterns based on variations of dictionary words?
  • What does residual risk entail?
  • Which of the following is NOT a method for risk mitigation?
  • What is a risk assessment tool used to prioritize risks?
  • Which of the following is a method for monitoring risk trends?
  • When addressing an elevation of privilege threat, which control is most appropriate?
  • In risk management, what does "likelihood" refer to?
  • What is the most effective way to provide accountability for identity system usage?
  • What type of logging should be enabled to analyze network traffic information?
  • What does a red flag in vulnerability assessments typically indicate?
  • What method involves identifying assets, threats, and vulnerabilities in a structured manner?
  • What STRIDE category is indicated by transaction identification issues caused by shared symmetric keys?
  • Which role is responsible for ensuring comprehensive risk assessments are conducted within an organization?
  • What is a potential consequence of not properly managing risks?
  • What is the final step in conducting a quantitative risk analysis?
  • Given the results of a port scan, what is the most likely operating system running on the scanned system?
  • What is the difference between a risk assessment and a risk audit?
  • What would NOT be a reasonable defense against scanning vulnerabilities?
  • Why is it important to have a documented risk management policy?
  • What is the purpose of using key risk indicators in risk management?
  • Which type of attack falsifies an identity to gain unauthorized access?
  • In the context of risk monitoring, what does "baseline" refer to?
  • What open source tool can Susan use for vulnerability scanning remotely?
  • What should Jim do if a vulnerability scanner continues to flag his patched system as vulnerable due to version number discrepancies?
  • What type of attack involves sending false requests to DNS servers with a forged source IP?
  • What can help mitigate brute-force attacks effectively?
  • Which vulnerability is least likely to be identified by a web vulnerability scanner?
  • What common port does SSH typically use?
  • Which type of attack involves a user gaining elevated privileges through exploiting system vulnerabilities?
  • Which stage in the risk management process involves tracking identified risks over time?
  • After completing a port scan, what is the next step a penetration tester should take?
  • For a realistic penetration test, what type should Saria conduct to persuade management of network vulnerabilities?
  • Which metric assesses the potential financial loss due to a security breach over a year?
  • Which of the following techniques is primarily quantitative in risk assessment?
  • What risk management metric is Tom trying to lower by enabling an application firewall?
  • Which factor is NOT a concern for Jim when designing log management systems?
  • What does the FAIR model stand for in risk management?
  • What is the first step in the risk management process?
  • How does threat modeling contribute to risk identification?
  • Which service is likely running on TCP port 443?
  • Why would an organization want to implement NTP in its logging infrastructure?
  • What type of attack is indicated by multiple failed logins with variations of the same password?
  • Which metric might be used to quantify risk?
  • What role does continuous training play in organizational risk management?
  • What is the exposure factor for Atwood Landing's data center in response to a tornado?
  • Which type of scanning is most practical for determining vulnerabilities in web applications?
  • What port should Kara block to prevent administrative connections to the server?
  • How often should organizations conduct risk assessments?
  • What type of risk response behavior is Sally recommending by suggesting the purchase of cybersecurity breach insurance?
  • What common logging issue is likely when login times differ significantly?
  • What is the importance of threat modeling in risk assessment?
  • What type of analysis evaluates the likelihood and impact of identified risks?
  • What kind of impact can a cyber breach have on an organization?
  • Which method is used to design new software tests and ensure their quality?
  • What technique does Allie use to narrow down authentication logs for review?
  • Which logging method focuses on tracking specific events on networking devices?
  • Which logging category would not typically indicate a successful operation in a Windows system?
  • Which scanning approach focuses specifically on the communication state of TCP connections?
  • What factor can significantly influence vulnerability to cyber threats?
  • How can data loss prevention (DLP) solutions assist in risk mitigation?
  • What is a primary objective of risk analysis?
  • Which tool is commonly used for vulnerability scanning?
  • What type of risk management strategy did HAL Systems pursue by stopping public NTP services?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy