Browse all practice questions for the CISSP Domain 3 – Risk Identification, Monitoring, and Analysis Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 3 Practice Test 2026 – All-in-One Guide to Master Risk Identification, Monitoring, and Analysis course image
All questions

These questions are part of the practice quiz. Start practicing

  • How can cyber insurance aid in managing risks?
  • What tool is specifically designed to test a web browser's handling of unexpected data?
  • Which type of assessment is focused on quantifying loss in terms of monetary value?
  • What major issue arises if Jim's IT staff do not regularly review backup logs?
  • Given the results of a port scan, what is the most likely operating system running on the scanned system?
  • What type of scan is indicated by the presence of URG, FIN, and PSH flags being set during a penetration test?
  • What is the most effective way to provide accountability for identity system usage?
  • What is an example of a qualitative risk assessment technique?
  • What technology should be used to ensure logs can be time sequenced across the infrastructure?
  • What is the primary purpose of vulnerability scanning?
  • What action should be considered the first step after a vulnerability is identified?
  • What is the potential benefit of engaging third-party security consultants in risk management?
  • What is one key factor in determining the appropriate risk response strategy?
  • What is the main advantage of using a framework like NIST for risk management?
  • In the context of risk monitoring, what does "baseline" refer to?
  • Which technique would best help Jim identify compromised systems in a botnet?
  • After completing a port scan, what is the next step a penetration tester should take?
  • What does the term "cyber hygiene" refer to?
  • What is a potential consequence of not properly managing risks?
  • Why would an organization want to implement NTP in its logging infrastructure?
  • Which step follows after identifying risks during the risk management process?
  • Which of the following best describes "threat modeling"?
  • What aspect is primarily analyzed during the assessment of risk in information systems?
  • What is an important outcome of conducting regular audits on risk management practices?
  • What type of tool should Alex use to test for format string vulnerabilities in web applications?
  • If Kara's primary concern is preventing eavesdropping attacks, which port should she block?
  • What is the importance of threat modeling in risk assessment?
  • What can help mitigate brute-force attacks effectively?
  • What is the difference between qualitative and quantitative risk assessment?
  • What is the role of key risk indicators (KRIs) in risk monitoring?
  • What would NOT be a reasonable defense against scanning vulnerabilities?
  • What risk management metric is Tom trying to lower by enabling an application firewall?
  • Which metric might be used to quantify risk?
  • What type of tool is used to gather information about system services and determine their versions based on banner information?
  • Which framework is specifically focused on information security controls?
  • How can organizations assess their risk appetite?
  • After discovering a critical vulnerability, what is Robin's next best action?
  • What is the primary focus of risk monitoring?
  • Which of the following methods is considered ineffective for preventing data tampering?
  • The primary focus of risk identification is to determine what?
  • In the context of software testing, what does "mutation testing" primarily evaluate?
  • What term best describes the situation when an intrusion detection system reports high-volume inbound traffic without a confirmed security compromise?
  • What does a red flag in vulnerability assessments typically indicate?
  • In terms of risk analysis, what are "threat vectors"?
  • What type of attack is characterized by overwhelming traffic causing service disruption?
  • How does threat modeling contribute to risk identification?
  • Which business impact assessment tool is best for evaluating the effect of a failure on customer confidence?
  • What is a primary goal of risk management in organizations?
  • In risk assessment, what does "impact" refer to?
  • Which of the following techniques is primarily quantitative in risk assessment?
  • How does a risk management framework assist organizations?
  • What is the role of education and training in risk mitigation?
  • Which term describes the likelihood that a specific risk will occur?
  • What open source tool can Susan use for vulnerability scanning remotely?
  • Which vulnerability is least likely to be identified by a web vulnerability scanner?
  • Which logging method focuses on tracking specific events on networking devices?
  • Which of the following best defines 'zero-day vulnerability'?
  • What is the purpose of a risk register?
  • Which document outlines an organization's strategy for managing risks?
  • What concern might arise from a limited port scan?
  • What common port does SSH typically use?
  • What is one major limitation of using automated tools for vulnerability scanning?
  • Which of the following is NOT a benefit of risk monitoring?
  • What type of analysis evaluates the likelihood and impact of identified risks?
  • Which method can ensure all Windows systems send identical logging information to a central logging system?
  • What does the term “control” in risk management typically refer to?
  • Which formula accurately represents the determination of risk?
  • How can organizations monitor risks effectively?
  • What is the significance of external audits in risk monitoring?
  • Which of the following is NOT a method for risk mitigation?
  • What type of risk is associated with legal penalties and non-compliance with regulations?
  • Which process involves the continuous evaluation of risk management strategies?
  • What term describes an occurrence that violates an organization’s security policy?
  • What type of attack is indicated by the log entry with the string ../../../etc/passwd?
  • What is the first step in the risk management process?
  • Which metric assesses the potential financial loss due to a security breach over a year?
  • What does residual risk entail?
  • What is the purpose of a risk appetite statement?
  • What does the term "risk tolerance" define?
  • Which tool is typically used to scan services running on TCP port 443?
  • Which regulatory standard is specifically focused on the protection of electronic patient health information?
  • What risk management strategy involves implementing an intrusion prevention system to block network attacks?
  • What message logging standard is widely adopted for enterprise devices such as network devices and Linux systems?
  • Which factor is NOT a concern for Jim when designing log management systems?
  • What is a likely consequence of a successful denial-of-service attack?
  • Which service is likely running on TCP port 443?
  • What is the term for risks arising from the use of third-party vendors?
  • In a gray box penetration test, what issue will occur if the client provides nonroutable IP addresses for scanning?
  • What method involves identifying assets, threats, and vulnerabilities in a structured manner?
  • What should an organization do with risks that are deemed acceptable?
  • What is a common tool used for assessing risks in security practices?
  • What protocol is used by Port 22 for administrative connections?
  • Which of the following is a key step in the risk management process?
  • What does the FAIR model stand for in risk management?
  • What port should Kara block to prevent administrative connections to the server?
  • When should vulnerability scans be conducted for maximum effectiveness?
  • Which element is crucial for understanding the potential impact of identified risks in an organization?
  • Which NIST special publication is focused on the assessment of security and privacy controls?
  • Which entity is responsible for promoting the Security Risk Management framework derived from ISO standards?
  • Why is it important to have a documented risk management policy?
  • What is inherent risk?
  • For a realistic penetration test, what type should Saria conduct to persuade management of network vulnerabilities?
  • Which scanning approach focuses specifically on the communication state of TCP connections?
  • Which document outlines the procedures for identifying, assessing, and treating risks?
  • What risk management strategy is utilized when implementing safeguards to lessen the impact of potential threats?
  • What is the primary function of Metasploit in penetration testing?
  • Which method is used to design new software tests and ensure their quality?
  • What type of risk response behavior is Sally recommending by suggesting the purchase of cybersecurity breach insurance?
  • During a log review, what type of attack is indicated by repeated invalid login attempts from the same user?
  • What type of attack involves sending false requests to DNS servers with a forged source IP?
  • What is the annualized rate of occurrence for a tornado at Atwood Landing's data center?
  • What risk management strategy is indicated if Rolando's organization decides to take no action regarding California mudslide risks?
  • What is an example of an external risk factor that organizations need to monitor?
  • What should be documented when a risk is accepted in the business continuity planning process?
  • When addressing an elevation of privilege threat, which control is most appropriate?
  • Which type of logs are critical in ensuring the security compliance of systems in an organization?
  • If Susan discovers services on TCP and UDP 137-139 and TCP 445 and 1433, what type of server is she likely connecting to?
  • What is the annualized loss expectancy for a tornado affecting Atwood Landing's data center?
  • What should Jim do if a vulnerability scanner continues to flag his patched system as vulnerable due to version number discrepancies?
  • What is the purpose of a Business Impact Analysis (BIA)?
  • Which type of scanning is most practical for determining vulnerabilities in web applications?
  • In risk management, what does the term "vulnerability" refer to?
  • What is the ARO of a flood in a 100-year flood plain?
  • In the context of security risks, who represents the threat when a hacker exploits a vulnerability?
  • What role does continuous risk assessment play in cybersecurity?
  • What is an essential component of a risk management process?
  • What role does continuous training play in organizational risk management?
  • Which type of attack involves a user gaining elevated privileges through exploiting system vulnerabilities?
  • What is the purpose of a risk register?
  • What common logging issue is likely when login times differ significantly?
  • What is a control assessment?
  • After creating a list of assets in a business impact analysis, what should the team do next?
  • How can an organization ensure compliance with security baselines for Windows PCs effectively?
  • What is the purpose of using key risk indicators in risk management?
  • Which of the following describes the function of risk analysis?
  • What is the final step in conducting a quantitative risk analysis?
  • When a zero-day vulnerability is reported, what is the best initial action to identify affected systems?
  • Which type of attack falsifies an identity to gain unauthorized access?
  • What type of attack is indicated by multiple failed logins with variations of the same password?
  • What is the purpose of fuzzers in application security testing?
  • What is the primary purpose of conducting a vulnerability assessment?
  • How can organizations effectively communicate risk management practices?
  • What kind of impact can a cyber breach have on an organization?
  • What factor can significantly influence vulnerability to cyber threats?
  • What potential issue can arise from improper log handling settings in a system?
  • Which type of tool is NOT used for testing the security of applications?
  • What is the purpose of regression testing in software development?
  • How do security policies contribute to risk management?
  • What status message indicates a port is accessible with an application accepting connections?
  • What type of risks do insider threats represent?
  • What type of vulnerabilities are least likely to be detected by a vulnerability scanner?
  • Which method involves analyzing past incidents to identify future risks?
  • What is the exposure factor for Atwood Landing's data center in response to a tornado?
  • Nmap is categorized as which type of tool?
  • Why is using Netflow records beneficial for identifying botnet activity?
  • What can be considered a benefit of comprehensive security training for staff?
  • Which of the following is a method for monitoring risk trends?
  • What does a threat landscape encompass?
  • What is the first essential step that should be taken prior to conducting a penetration test?
  • What type of risk management strategy did HAL Systems pursue by stopping public NTP services?
  • How can data loss prevention (DLP) solutions assist in risk mitigation?
  • Which of the following is a common framework used for risk management?
  • Which system does not natively support syslog events?
  • Which remediation strategy is not effective for a vulnerability identified by a scanner?
  • What kind of analysis involves breaking a system down into key elements such as trust boundaries and data flow paths?
  • What is a key benefit of implementing a risk management framework?
  • What STRIDE category is indicated by transaction identification issues caused by shared symmetric keys?
  • What does the acronym SRA stand for in risk management?
  • What is the difference between a risk assessment and a risk audit?
  • What does a risk mitigation strategy involve?
  • What is one key responsibility of a security risk analyst within an organization?
  • What is the role of risk treatment in the risk management process?
  • What is the significance of threat intelligence in risk management?
  • Which of the following is generally not a risk associated with penetration testing?
  • Where is Tom most likely to find information on the approval process for modifications to system security settings?
  • What is the objective of a black box penetration test?
  • What type of risk assessment focuses on identifying the potential impact of a risk?
  • What does the term "risk appetite" mean?
  • What is the primary benefit of using historical data in risk assessments?
  • Which attack type shows patterns based on variations of dictionary words?
  • What is the primary goal of risk identification in cybersecurity?
  • When conducting a port scan, what type of devices is most likely discovered if ports 80, 443, 515, and 9100 are responding?
  • What technique does Allie use to narrow down authentication logs for review?
  • During a penetration test, which potential hazard could lead to an unexpected application shutdown?
  • Which tool is commonly used for vulnerability scanning?
  • Which of the following is an example of a qualitative assessment tool?
  • Which logging category would not typically indicate a successful operation in a Windows system?
  • What is a risk assessment tool used to prioritize risks?
  • Which role is responsible for ensuring comprehensive risk assessments are conducted within an organization?
  • In risk management, what does "likelihood" refer to?
  • What term is used for the testing intended to uncover new bugs after changes in software?
  • What is a primary objective of risk analysis?
  • Which technique is used to control access based on user roles?
  • Which stage in the risk management process involves tracking identified risks over time?
  • What should Susan track to predict high-risk areas in her organization?
  • What is the purpose of an incident response plan in relation to risk management?
  • What type of scanning is likely occurring if an outsider is trying to connect using TCP on port 22?
  • What type of logging should be enabled to analyze network traffic information?
  • What service typically uses port 53 for communication?
  • Which tool aids in documenting and analyzing security incidents for risk identification?
  • Which risk assessment approach combines both quantitative and qualitative methods?
  • What type of log entry is generated when a Windows system is rebooted?
  • What is the role of authorization controls in data security?
  • How often should organizations conduct risk assessments?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy