🇺🇸 Certified Information Systems Security Professional (CISSP) · flashcards

Certified Information Systems Security Professional (CISSP) Security and Risk Management Flashcards

72 question-and-answer cards covering Security and Risk Management as it is examined in Certified Information Systems Security Professional (CISSP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

72Cards in deck
24Free preview
17Syllabus topics
~201Chars per answer
FreePrice

24 sample cards from the Security and Risk Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. List the three control categories by type (the nature of the control).

    Administrative/Managerial (policies, procedures, training), Technical/Logical (firewalls, encryption, access controls), and Physical (fences, locks, guards, CCTV).

  2. Name the six (or seven) control functions and their purpose.

    Preventive (stop incidents), Detective (identify incidents), Corrective (fix after an incident), Deterrent (discourage), Recovery (restore), Compensating (alternative when primary isn't feasible), and Directive (mandate/guide behavior).

  3. Give an example distinguishing a deterrent control from a preventive control.

    A warning sign or visible camera is a deterrent (discourages action); a locked door or firewall is preventive (physically/technically stops the action).

  4. What is a compensating control?

    An alternative control put in place when the primary/intended control is not feasible or cost-effective, providing a comparable level of protection (e.g., increased monitoring when MFA can't be deployed).

  5. Name four common threat modeling methodologies and what each focuses on.

    STRIDE (threat categories, Microsoft), PASTA (risk/attacker-centric, 7 stages), DREAD (risk rating/scoring), and Trike/VAST (risk management and scalable enterprise modeling).

  6. What does STRIDE stand for and what security property does each threat violate?

    Spoofing (authentication), Tampering (integrity), Repudiation (non-repudiation), Information disclosure (confidentiality), Denial of service (availability), Elevation of privilege (authorization).

  7. What does the DREAD threat-rating model evaluate?

    Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability — used to rate/prioritize the severity of threats.

  8. What is supply chain risk management (SCRM) concerned with in security?

    Managing risks introduced by third parties, vendors, suppliers, and hardware/software providers — including ensuring minimum security requirements via contracts (SLA, SLR), assessments, and addressing risks like counterfeit components or compromised code.

  9. Define the third-party agreement terms SLA, MOU/MOA, and BPA.

    SLA = Service Level Agreement (measurable performance/uptime commitments); MOU/MOA = Memorandum of Understanding/Agreement (less formal intent to cooperate); BPA = Business Partner Agreement (terms of a partnership).

  10. What is a Business Impact Analysis (BIA) and what is its primary purpose?

    A BIA identifies critical business functions and the impact of their disruption over time, prioritizing recovery and quantifying potential losses — it is the foundation of BCP/DRP.

  11. Define RTO, RPO, MTD, and WRT.

    RTO = Recovery Time Objective (max acceptable downtime to restore a function); RPO = Recovery Point Objective (max acceptable data loss measured in time); MTD = Maximum Tolerable Downtime; WRT = Work Recovery Time (time to verify/restore data after systems are up). RTO + WRT ≤ MTD.

  12. What is the relationship between RTO and MTD?

    RTO must be less than or equal to the MTD. The RTO plus the Work Recovery Time (WRT) must not exceed the Maximum Tolerable Downtime.

  13. What does MTBF and MTTR measure?

    MTBF = Mean Time Between Failures (average operational time before a device fails, reliability); MTTR = Mean Time To Repair (average time to restore a failed component).

  14. What is the first/most important step in business continuity planning according to ISC2?

    Obtaining senior management's support, commitment, and funding (project scope and planning) — without executive buy-in the BCP cannot succeed.

  15. List the main phases of the BCP process per CISSP.

    1) Project scope and planning, 2) Business Impact Analysis (BIA), 3) Continuity planning (recovery strategy and provisions/processes), and 4) Approval and implementation (plus testing, training, and maintenance).

  16. Differentiate Business Continuity Planning (BCP) from Disaster Recovery Planning (DRP).

    BCP is strategic and broad — keeping the whole business operating during/after a disruption; DRP is tactical and focused — restoring IT systems/operations at the affected site after a disaster. DRP is a subset of BCP.

  17. What is the difference between a quantitative and qualitative impact assessment within a BIA?

    Quantitative impact estimates measurable financial loss (revenue, fines, recovery costs); qualitative impact estimates non-monetary effects (reputation, customer confidence, morale, legal/strategic harm).

  18. Define the maximum tolerable downtime (MTD) and give example ranges by criticality.

    MTD is the longest a function can be unavailable before unacceptable harm. Examples: Critical ≈ minutes–hours; Urgent ≈ 24 hours; Important ≈ 72 hours; Normal ≈ 7 days; Nonessential ≈ 30 days.

  19. Compare the major disaster recovery site types: hot, warm, cold, and what about mobile/cloud.

    Hot site = fully equipped, near-instant failover (most expensive); Warm site = hardware/connectivity but data must be loaded (hours–days); Cold site = empty space with power/HVAC, no equipment (cheapest, slowest); Mobile/cloud = portable or provider-hosted alternatives.

  20. What are reciprocal agreements as a recovery strategy and their key drawback?

    A mutual aid agreement where two organizations agree to host each other's operations during a disaster; cheap but problematic due to capacity, confidentiality, compatibility, and enforceability concerns.

  21. List the BCP/DRP test types from least to most disruptive.

    1) Read-through/checklist review, 2) Structured walk-through/tabletop, 3) Simulation, 4) Parallel test (recovery site runs alongside production), 5) Full-interruption test (primary shut down — most disruptive/risky).

  22. What is the difference between a parallel test and a full-interruption test?

    In a parallel test the recovery site is brought up and operates alongside the still-running primary (no production disruption); in a full-interruption test the primary is shut down and operations fully shift to recovery — the most realistic but highest risk.

  23. Why must BCP/DRP plans be regularly tested and maintained?

    To validate that the plan works, identify gaps/outdated assumptions, train personnel, meet RTO/RPO objectives, and keep the plan current with organizational, technological, and personnel changes.

  24. What governance role does senior management hold regarding the BCP, and who typically owns/maintains it?

    Senior management is ultimately responsible and accountable (sign-off, funding, support); a BCP coordinator/team develops and maintains it day-to-day. Management approval is required to make the plan official.

What this deck covers

The Security and Risk Management deck follows the Certified Information Systems Security Professional (CISSP) Security and Risk Management syllabus — 5 chapters and 17 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 14.4 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 201 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Security and Risk Management flashcards FAQ

How many Security and Risk Management flashcards are in this Certified Information Systems Security Professional (CISSP) deck?

72 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Security Professional (CISSP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 72-card deck is free inside the Examius app.

What do the Security and Risk Management cards cover?

They follow the Certified Information Systems Security Professional (CISSP) Security and Risk Management syllabus — 5 chapters and 17 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.