Objective 1.2CC

1.2 Understand the risk management process.

Objective 1.2 sits in Security Principles, which carries 26% of the Certified in Cybersecurity exam. The questions below are original, written from the official objective title above, and each explanation cites the ISC2 page it rests on.

Objective title verbatim from the official objectives. ISC2 exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-2Security PrinciplesEasy

In the NIST Risk Management Framework, who decides that a system is authorized to operate?

The system administratorAdministrators implement and run controls; they do not accept organizational risk.
A senior officialCorrect · your answerCorrect. Authorization is a senior official's risk-based call.
An external auditorAn auditor can assess controls, the right role for the Assess step, not the operate decision.
The software vendorVendors supply the technology and carry no authority over the buyer's risk.

Correct.

Concept

Accepting residual risk is a business judgment, so frameworks place the operate decision with someone accountable for the organization rather than with whoever built or checked the system.

Why B

The RMF's Authorize step has a senior official make a risk-based decision to authorize the system to operate.

#rmf#authorize#risk

Now you: objective 1.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-2Security PrinciplesModerate

A new HR system is onboarding, and the security team rates the impact level of the information it stores and transmits. Which RMF step is this?

Sample question 2 of 3

1-2Security PrinciplesModerate

With a payroll system categorized, the team now picks a set of controls matched to the assessed risk. Which RMF step are they in?

Sample question 3 of 3

1-2Security PrinciplesModerate

Controls are deployed and documented. Next, the team must confirm they are in place, operating as intended, and producing results. Which step is that?

Full Certified in Cybersecurity question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Principles