Loading questions…

Security+ Risk Management Practice Questions

Practice Risk Management questions for the CompTIA Security+. Every question includes a full explanation of why the correct answer is right and why the tempting distractors are wrong.

26 questions available · medium difficulty · Security+ · Free, no registration required

Sample Risk Management Questions with Answers

10 example questions with full explanations. Use the interactive practice above to work through the complete set.

Question 1medium

A financial services company identifies that a critical database server experiences a complete failure approximately twice per year. Each failure results in $15,000 in recovery costs, lost productivity, and regulatory fines. The security team is evaluating whether to invest $18,000 in a redundant failover system. Based purely on quantitative risk analysis, what is the Annual Loss Expectancy (ALE), and does the investment make financial sense?

  • A.ALE = $7,500; the investment does not make financial sense because it exceeds the ALE
  • B.ALE = $15,000; the investment does not make financial sense because it exceeds the ALE
  • C.ALE = $30,000; the investment makes financial sense because it is less than the ALE
  • D.ALE = $30,000; the investment does not make financial sense because ALE must exceed the control cost by at least 20%

Correct answer: C

ALE is calculated as SLE × ARO. Here, SLE = $15,000 and ARO = 2 failures per year, so ALE = $15,000 × 2 = $30,000. Since the redundant failover system costs $18,000 annually and the expected loss without it is $30,000, the investment saves $12,000 per year and therefore makes financial sense. Option A incorrectly divides SLE by ARO. Option B uses SLE alone as ALE. Option D arrives at the correct ALE but applies a fabricated '20% rule' that does not exist in standard risk management frameworks.

Question 2medium

After a ransomware attack, a hospital's incident response team discovers that patient records were encrypted for 18 hours before systems were restored from backups. During that time, staff reverted to paper-based processes. The hospital's documented recovery objectives state that electronic health record (EHR) systems must be restored within 4 hours and that no more than 1 hour of patient data can be lost. Which combination of recovery objectives was VIOLATED?

  • A.RTO was violated, but RPO was not, because backups successfully restored the data
  • B.RPO was violated, but RTO was not, because patient data was ultimately recovered
  • C.Neither RTO nor RPO was violated because staff used paper-based workarounds during the outage
  • D.Both RTO and RPO were violated

Correct answer: D

RTO (Recovery Time Objective) defines how quickly systems must be restored — the hospital's RTO is 4 hours, but restoration took 18 hours, so RTO was violated. RPO (Recovery Point Objective) defines the maximum acceptable data loss window — the hospital's RPO is 1 hour, but if backups were not taken within the last hour before the attack, data from that gap is lost, violating RPO. Option A incorrectly assumes backup restoration alone satisfies RPO regardless of when backups were taken. Option B confuses ultimate data recovery with RPO compliance. Option C incorrectly treats paper workarounds as meeting either objective.

Question 3medium

A retail company processes credit card transactions and stores customer purchase history in a cloud environment. During a vendor risk review, the security team discovers that the cloud provider's contract lacks a clause allowing the company to inspect the provider's security controls or audit their compliance posture. Which contract provision should the security team require to address this gap?

  • A.A right-to-audit clause permitting the company to assess the provider's security practices
  • B.A Service Level Agreement (SLA) defining uptime guarantees and penalty clauses
  • C.A data retention policy specifying how long the provider must store transaction records
  • D.A mutual non-disclosure agreement (NDA) to protect shared proprietary information

Correct answer: A

A right-to-audit clause grants the contracting organization the contractual authority to inspect, test, or commission third-party audits of a vendor's security controls and compliance posture — directly addressing the identified gap. An SLA (Option B) governs availability and performance metrics but does not provide audit access.Bdata retention policy (Option C) addresses how long data is kept, not the ability to verify security controls. An NDA (Option D) protects confidential information exchanged between parties but does not grant inspection rights.

Question 4medium

A security analyst is reviewing the organization's backup strategy. The current approach takes a full backup every Sunday night and differential backups each weekday night. On Thursday morning, the primary file server fails. To restore the server to its Wednesday night state, which backup sets must the analyst use?

  • A.Sunday's full backup plus Monday's, Tuesday's, and Wednesday's differential backups
  • B.Sunday's full backup and Wednesday's differential backup only
  • C.Sunday's full backup and Wednesday's incremental backup only
  • D.Only Wednesday's differential backup, because it contains all changes since Sunday

Correct answer: B

A differential backup captures all changes made since the last full backup, meaning Wednesday's differential already contains everything changed since Sunday. To restore, the analyst only needs Sunday's full backup and the most recent differential (Wednesday's) — just two backup sets. Option A describes the restoration process for incremental backups, which each capture only changes since the last backup of any type, requiring all incremental sets. Option C incorrectly labels the backup type; the scenario specifies differential, not incremental. Option D is incorrect because the full backup is always required as the baseline before applying any differential.

Question 5medium

A healthcare organization operating under HIPAA is replacing hard drives from decommissioned workstations that stored protected health information (PHI). The drives are standard magnetic HDDs. The IT team suggests simply deleting the files and reformatting the drives before donating them to a local school. The security officer rejects this plan. Which data destruction method would be MOST appropriate for the magnetic drives while still allowing the hardware to be reused?

  • A.Physical destruction by shredding the drives, rendering them unusable
  • B.Degaussing the drives using a strong magnetic field to erase all data
  • C.Overwriting the drives using a multi-pass wiping tool that meets DoD 5220.22-M standards
  • D.Cryptographic erasure by deleting the encryption keys used to protect the PHI

Correct answer: C

Overwriting (disk wiping) using a validated multi-pass method renders data unrecoverable on magnetic HDDs while keeping the hardware functional and reusable — making it the best fit for donation. Physical shredding (Option A) is thorough but destroys the drive, making donation impossible. Degaussing (Option B) effectively destroys data on magnetic drives but also damages the drive's servo tracks, typically rendering it non-functional and unsuitable for reuse. Cryptographic erasure (Option D) is effective when data was pre-encrypted, but the scenario does not indicate the drives used full-disk encryption, so simply deleting keys would not protect unencrypted PHI residue.

Question 6medium

A healthcare organization has implemented strict access controls and encryption on its patient database, but the security team acknowledges that some probability of unauthorized access still remains after all controls are applied. What term best describes this remaining level of risk?

  • A.Inherent risk
  • B.Risk appetite
  • C.Risk tolerance
  • D.Residual risk

Correct answer: D

Residual risk is the risk that remains after security controls have been applied to reduce inherent risk. In this scenario, even after implementing access controls and encryption, some risk still exists — that is the residual risk. Inherent risk is the level of risk before any controls are applied. Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance is the acceptable variance around that risk appetite — neither describes the leftover risk after controls are implemented.

Question 7medium

A company's legal team has determined that operating in a particular foreign market exposes the organization to regulatory penalties that outweigh any potential profit. As a result, leadership decides to withdraw from that market entirely. Which risk management strategy is the organization applying?

  • A.Risk avoidance
  • B.Risk transfer
  • C.Risk acceptance
  • D.Risk mitigation

Correct answer: A

Risk avoidance involves eliminating the risk entirely by choosing not to engage in the activity that creates the risk. Withdrawing from the market removes the regulatory exposure completely, which is the defining characteristic of avoidance. Risk transfer shifts the financial impact to a third party (e.g., insurance). Risk acceptance means acknowledging the risk and proceeding without additional controls. Risk mitigation involves implementing controls to reduce the likelihood or impact of the risk, not eliminating the activity itself.

Question 8medium

After a ransomware incident, a financial services firm conducts a qualitative risk assessment of its remaining systems. The security team rates each system's risk as High, Medium, or Low based on asset criticality and threat likelihood — without assigning specific dollar values. A separate team also calculates exact monetary loss estimates using ALE for the most critical systems. Which statement BEST describes the difference between these two approaches?

  • A.Qualitative assessments are more precise because they use structured rating scales, while quantitative assessments are subjective estimates.
  • B.Qualitative assessments use descriptive categories to rank risk, while quantitative assessments express risk in measurable financial terms.
  • C.Quantitative assessments are only suitable for compliance-driven environments, while qualitative assessments apply to all risk scenarios.
  • D.Both approaches produce the same result but differ only in the time required to complete the assessment.

Correct answer: B

Qualitative risk assessments categorize risk using descriptive labels (High/Medium/Low) based on expert judgment about likelihood and impact, without assigning precise monetary values. Quantitative assessments, such as calculating ALE (Annual Loss Expectancy = SLE × ARO), express risk in concrete financial terms, enabling cost-benefit analysis of controls. Option A incorrectly reverses the characteristics — quantitative methods are more precise, not qualitative ones. Option C is incorrect because both methods are applicable across many environments. Option D is false; the two approaches produce different types of outputs and serve different analytical purposes.

Question 9medium

A retail company's vulnerability scanner identifies a web application flaw with a CVSS score of 9.4. The security team validates the finding, determines it affects a customer-facing payment portal, and schedules remediation. According to vulnerability management best practices, what should the team do NEXT after validating and prioritizing this finding?

  • A.Archive the vulnerability in the risk register and reassess it during the next quarterly review cycle.
  • B.Apply the vendor-supplied patch directly to the production payment portal without additional testing to minimize exposure time.
  • C.Treat the vulnerability by applying the patch or implementing a compensating control, then verify remediation and report the outcome.
  • D.Immediately shut down the payment portal until a patch is available from the vendor.

Correct answer: C

The vulnerability management lifecycle proceeds through four phases: identify, evaluate (validate and prioritize), treat, and report. After validating the high-severity finding (CVSS 9.4), the next step is treatment — applying a patch, deploying a compensating control (such as a WAF rule), verifying the fix worked, and then reporting the remediation to stakeholders. Option A is incorrect because archiving without action ignores an actively exploitable critical vulnerability. Option B is dangerous because patching production directly without testing can introduce outages or regressions; patches should be tested in a staging environment first. Option D (shutting down the portal) is an overly drastic response and would harm business operations when less disruptive treatments are available.

Question 10medium

An organization is deciding between disaster recovery site options. After a business impact analysis, the team determines that their core transaction processing system can tolerate no more than four hours of downtime, but replicating live data continuously to an off-site location is cost-prohibitive. Which DR site type BEST balances these constraints?

  • A.Hot site, because it provides the lowest possible RTO through real-time data replication.
  • B.Cold site, because it minimizes cost while still allowing recovery within the four-hour window.
  • C.Cloud DR with active-active configuration, because it eliminates the need for any recovery time objective planning.
  • D.Warm site, because it provides pre-installed infrastructure and periodic data synchronization that can meet a moderate RTO without the cost of continuous replication.

Correct answer: D

A warm site has pre-configured hardware, software, and networking already in place, with data synchronized periodically (e.g., daily backups or near-real-time replication at intervals). This allows recovery within a few hours, meeting the four-hour RTO without incurring the high cost of a hot site's continuous real-time replication.Ahot site (Option A) would meet the RTO but is eliminated by the cost constraint stated in the scenario.Acold site (Option B) provides only basic physical space and power — hardware must be procured and configured after a disaster, making a four-hour recovery essentially impossible. Option C is incorrect because an active-active cloud configuration carries its own significant costs and complexity, and no DR architecture makes RTO planning irrelevant.