CompTIA SecurityX Practice Questions: Risk Management

5 free, exam-style CompTIA SecurityX (CAS-005) practice questions covering Risk Management, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

25 Questions · 50 minutes

Start Quiz 🚀
🏆

Mock SecurityX Exam

85 Questions · 165 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

50 Questions · 100 minutes

Start Quiz 🚀

Risk Management practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. Which framework is MOST commonly used for enterprise risk management?

  • A.NIST CSF✓ Correct
  • B.MITRE ATT&CK
  • C.ISO 27001
  • D.PCI DSS
Explanation: NIST Cybersecurity Framework (CSF) is widely adopted for risk management. Learn more.

Q2. What is the PRIMARY purpose of a Business Impact Analysis (BIA)?

  • A.Identifying critical systems✓ Correct
  • B.Penetration testing
  • C.Network segmentation
  • D.Log analysis
Explanation: A BIA identifies essential functions for disaster recovery planning. Learn more.

Q3. What does risk appetite define for an organization?

  • A.The amount and type of risk leadership is willing to accept✓ Correct
  • B.The list of open TCP ports
  • C.The number of firewall rules allowed
  • D.The encryption key length only
Explanation: Risk appetite is a leadership-level statement of acceptable risk in pursuit of business objectives. Learn more.

Q4. What is the main value of a control gap assessment?

  • A.Identify differences between current controls and required controls✓ Correct
  • B.Assign IP addresses faster
  • C.Replace incident response
  • D.Increase screen brightness
Explanation: A gap assessment compares current control maturity against standards, requirements, or desired states. Learn more.

Q5. Which metric measures how often a loss event is expected to occur in a year?

  • A.ARO✓ Correct
  • B.RTO
  • C.RPO
  • D.MTTR
Explanation: Annualized rate of occurrence estimates how frequently a risk event may happen per year. Learn more.

More CompTIA SecurityX practice topics

Keep studying CompTIA SecurityX

Full CompTIA SecurityX practice exam · CompTIA SecurityX study guide · All CompTIA practice questions

Last updated