Certified Information Systems Security Professional CISSP Exam Questions & Answers

Practice 125 free Certified Information Systems Security Professional CISSP exam questions with answers and community-discussed explanations. Each question has its own page where you can reveal the correct answer and debate it in the comments.

All 125 questions

  1. Q1 The Fellowship of the Ring has various teams (hobbits, elves, dwarves, men) working in concert towards a common goal: the destruction of…
  2. Q2 ThorTeaches.com has recently implemented a new backup system for all data stored on servers and computers. As the IT security manager, it…
  3. Q3 ThorTeaches.com has recently experienced a major power outage that disrupted business operations for several days. Kundai has been asked to review the…
  4. Q4 Which of the following is a PRIMARY security concern when implementing multi-layered network protocols?
  5. Q5 As part of an in-depth security audit, you need to verify that a critical system component adheres to its defined security baseline…
  6. Q6 Different network devices work at specific OSI model layers because they carry out different types of functionality. A basic bridge works at…
  7. Q7 ThorTeaches has moved to using DevOps. Which of these project management approaches are best suited for DevOps?
  8. Q8 During a meeting with your company's clients, you discuss the importance of secure communication and ask what encryption algorithm they use for…
  9. Q9 A multinational corporation is developing information handling procedures. Which of the following is the BEST approach to ensuring compliance with different international…
  10. Q10 ThorTeaches.com has experienced a natural disaster that has caused significant damage to your main data center and disrupted your operations. You are…
  11. Q11 Which of the following is the primary reason to use Kerberos?
  12. Q12 You are reviewing evidence from a forensic investigation and need to ensure only the most relevant information is presented in court. During…
  13. Q13 Melissa is the new IT Security Manager of a global corporation. Her predecessor started implementing the ISO/IEC 7498-1 (OSI) model, but she…
  14. Q14 All the following are principles defined by the Organisation for Economic Co-operation and Development (OECD) Guidelines on the Protection of Privacy and…
  15. Q15 After joining ThorTeaches.com, how would you determine what is acceptable use of the internet?
  16. Q16 After conducting a thorough audit of your organization’s security processes, you are now preparing for an external audit by a third-party assessor.…
  17. Q17 You are an IT Security Manager at a data-intensive organization that needs to strike a balance between performance and data protection. Your…
  18. Q18 As the IT Manager of a rapidly growing software company, you've noticed inconsistencies in the quality of software releases, resulting in unforeseen…
  19. Q19 Indiana Jones keeps a detailed journal of his archaeological finds but only shares limited information with certain colleagues. This practice primarily falls…
  20. Q20 As the Chief Information Security Officer (CISO) of a multinational corporation, you are overseeing the implementation of a new company-wide security framework.…
  21. Q21 You are the Chief Information Security Officer (CISO) of a tech-driven organization that has implemented a DevOps model. The current structure is…
  22. Q22 Carl is a security architect working on migrating bare-metal computing to the cloud to reduce the organization's system footprint. He needs to…
  23. Q23 A communications medium consisting of interwoven, insulated copper wires is called __________.
  24. Q24 Esther is the head of IT security at a large corporation. She has recently discovered that one of the servers has been…
  25. Q25 Our networking department is recommending we use a baseband solution for an implementation. Which of these is a KEY FEATURE of those?
  26. Q26 Which of the following cannot be outsourced during a disaster?
  27. Q27 What is the primary goal of a DRP (Disaster Recovery Plan)?
  28. Q28 A company is implementing a personnel security policy that mandates periodic job rotations for employees in sensitive positions. What is the PRIMARY…
  29. Q29 Which of the following is the MOST important factor in the effectiveness of a SOAR (Security Orchestration, Automation, and Response) system?
  30. Q30 Suobo is the IT director of a rapidly growing tech startup. Given the scale and speed of your company's growth, his CEO…
  31. Q31 Your security team has completed a penetration test and identified several exploitable vulnerabilities. To ensure a comprehensive remediation plan, what should be…
  32. Q32 Which of the following is the HIGHEST priority for internal audits?
  33. Q33 ThorTeaches.com has recently experienced a data breach due to a malware attack that was able to bypass your current security measures. As…
  34. Q34 In the most secure scenario, which of the following environments would you include within an isolated network? (Choose all that apply.)
  35. Q35 An information system contains an embedded system, which must be accounted for as part of a threat model. Which of the following…
  36. Q36 What is the main role of the CAB in the company's IT security practices?
  37. Q37 A recent change in the system baseline forced a modification of system log generation and collection. A system administrator has reported that…
  38. Q38 __________ is/are the strongest form of secure coding practice(s).
  39. Q39 Your organization wants to incorporate DevOps practices to improve efficiency in application development and deployment. Which of the following would be the…
  40. Q40 Which of the following has functionality and ability to provide the AAA functionality for other protocols and services because it has a…
  41. Q41 You are the Chief Information Security Officer (CISO) of a large technology firm that is about to undergo extensive legal proceedings. You…
  42. Q42 Which of the following is code that has been put through a compiler and is unreadable to humans?
  43. Q43 Which of the following is the LEAST effective way to evaluate and apply security governance principles?
  44. Q44 Where would be a good place for us not to implement defense in depth?
  45. Q45 What is the primary purpose of implementing a security incident and event management (SIEM) system in an organization?
  46. Q46 Leilani chose Security Assertion Markup Language (SAML) for our federated identity management (FIdM). Which type of Single Sign-On (SSO) is that?
  47. Q47 ThorTeaches.com has recently implemented a CI/CD (Continuous Integration/Continuous Deployment) pipeline for their software development process. However, security concerns have been raised about…
  48. Q48 Which of the following is the FIRST thing a security consultant should consider when evaluating the security controls of a client's organization?
  49. Q49 Your organization requires employees to authenticate using a combination of a password, a physical security token, and a fingerprint scan. What type…
  50. Q50 By implementing a layered defense strategy across our organization, what do we improve?
  51. Q51 A security consultant has been tasked with identifying exploitable vulnerabilities within an internally developed application as part of a broader security evaluation.…
  52. Q52 A financial institution has implemented a Zero-Trust Architecture to secure its network infrastructure. In this model, which component is PRIMARILY responsible for…
  53. Q53 ThorTeaches.com is implementing a new security system and needs to decide on a method for controlling access to sensitive information. Which of…
  54. Q54 An enterprise organization is deploying a cloud-based customer portal and wants users to log in using their existing corporate credentials. Which of…
  55. Q55 Your organization is implementing an authentication system that uses biometrics to provide high-security access for executives who manage highly sensitive data. The…
  56. Q56 When we release our software as open source, we do what?
  57. Q57 What type of water sprinkler system keeps pipes empty and doesn’t release water until a certain temperature is met and a “delay…
  58. Q58 During a vendor security audit, you find evidence that the vendor is violating data protection policies by improperly storing customer credit card…
  59. Q59 __________ refers to confirming that the parameter values being received by an application are within defined limits before they are processed by…
  60. Q60 We are working on our incident management plans. In which phase would we write our procedures?
  61. Q61 Which of the following is the BEST approach to full disclosure in the event of a security breach?
  62. Q62 Which of these is not really a methodology but describes the phases of the software development lifecycle?
  63. Q63 Which of the following is NOT a principle of Privacy by Design (PbD)?
  64. Q64 Which of the following devices typically works at the application layer and acts as a protocol translator for different environments?
  65. Q65 Which of the following is the process of teaching a skill or set of skills that will enable the trainees to perform…
  66. Q66 We keep our backup data for as long as the information is usable or if we are required to by law, standards,…
  67. Q67 As part of a security control assessment, which of the following sources of data would provide the MOST direct insight into the…
  68. Q68 All the following are weaknesses of Kerberos except __________.
  69. Q69 Which two security controls are used to prevent unauthorized access to sensitive information?
  70. Q70 Which of the following secure design principles states that the more complex a system is, the more difficult it is to understand…
  71. Q71 In which of the following types of law systems do lawmakers and scholars attempt to discover the truth of law?
  72. Q72 You are the Chief Information Security Officer (CISO) of a multinational corporation. Your company has been seeing an increase in phishing attempts…
  73. Q73 What do we often uncover in our vulnerability scans?
  74. Q74 The HR department at ThorTeaches.com has approached you with a request to create an access control system for their employee records. What…
  75. Q75 Which of the following is a type of access control that would be used to deter fraud by constraining the combination of…
  76. Q76 Despite being one of the founding members, even Tyler Durden's authority and actions in the Fight Club are constantly verified and evaluated.…
  77. Q77 Which of the following is the MOST effective detective control for detecting unauthorized access to a company's financial records?
  78. Q78 In order to ensure the safety of our customer's personal information, we need to regularly assess the strength of our security systems.…
  79. Q79 What type of access control model is based on the concept of a trusted third party for authentication?
  80. Q80 What is the MOST effective way to reduce security risks associated with SSO (Single Sign-On)?
  81. Q81 Which of the following represents a Level 2 merchant according to the Payment Card Industry Data Security Standard (PCI DSS)?
  82. Q82 Water and gas lines should have shutoff values and positive drains. What is a positive drain?
  83. Q83 You are a cybersecurity consultant hired by a multinational corporation to strengthen its security posture. After conducting a network security audit, you…
  84. Q84 We are using Service Organization Control (SOC) reports. We want the report to be only released when signing an NDA, and it…
  85. Q85 In addition to export restrictions on certain cryptographic algorithms and materials imposed by the Wassenaar Arrangement, which of the following should also…
  86. Q86 Which of the following is the FIRST step in implementing micro-segmentation?
  87. Q87 In which legal standard does the preponderance of the evidence play a significant role?
  88. Q88 As we prepare for budget season, our management team is considering allocating additional resources toward improving ThorTeaches.com's security measures. In order to…
  89. Q89 What causes an overwhelmingly majority of all data leak breaches?
  90. Q90 We need to physically store sensitive data in a secure way. Which of these could be an option that can be both…
  91. Q91 Jonathan’s workstation is overloaded with electrical connections into a small number of outlets. He is daisy-chaining power strips to service all his…
  92. Q92 In software acceptance testing, what is the purpose of compliance acceptance testing?
  93. Q93 We have had a breach, and an attacker gained access to some of our servers and workstations. We are planning to use…
  94. Q94 Which type of DLP solution is primarily concerned with both data at rest and data in use?
  95. Q95 We are discussing our risk responses, and we are considering not issuing our employees laptops. What type of risk response would that…
  96. Q96 If we are wanting to implement governance standards and control frameworks focused on internal risk analysis, which of these could we implement?
  97. Q97 In building our comprehensive Business Continuity Plan (BCP), we would probably build all these plans, EXCEPT which?
  98. Q98 What is the MOST important aspect of information security?
  99. Q99 You are the Chief Information Security Officer (CISO) at a multinational corporation. The company collaborates with several contractors and business partners, giving…
  100. Q100 Which of the following is the FASTEST way to detect vulnerabilities in code?
  101. Q101 Which of the following is the MOST effective way to protect a database management system (DBMS) against unauthorized access?
  102. Q102 Which of the following is a method for automatically changing the password on service accounts?
  103. Q103 We have had some tapes go missing from our inventory. We are unsure if they were stolen or just misplaced. Which of…
  104. Q104 As the Head of IT Security for ThorTeaches.com, you are responsible for evaluating the potential risks of allowing employees to BYOD (Bring…
  105. Q105 Acme, Inc. is acquiring SeCloud, LLC, a small cloud security company. Before finalizing the acquisition, Acme wants to ensure SeCloud’s information systems…
  106. Q106 What is the fastest way to securely access cloud data?
  107. Q107 Which of the following is a form of social engineering, typically practiced in person or over the phone, in which the attacker…
  108. Q108 As part of your organization's security protocol, you need to define asset handling requirements. Which of the following is the LEAST LIKELY…
  109. Q109 Which of the following elements of the technical audit report is targeted toward readers who may not be able to devote more…
  110. Q110 An auditor reviewing an organization’s security policies finds that security logs are not retained for the required period under regulatory guidelines. What…
  111. Q111 Which of these hackers would you hire to do penetration testing?
  112. Q112 Which of the following is NOT a key component of an incident management plan?
  113. Q113 Your company is in the process of implementing a robust Network Access Control (NAC) system to strengthen its defenses against unauthorized access.…
  114. Q114 A hybrid cloud has been created to host sensitive sales data for your organization. The public side is used for potential customers…
  115. Q115 Victoria is the IT security manager at a large corporation that has recently implemented IPSec to secure its network communications. She has…
  116. Q116 As the IT security manager at a large financial institution, you have recently implemented a new authentication system for employees’ access to…
  117. Q117 The IT department needs to find a technology solution to help automate tasks and boost efficiency. What technology could be used to…
  118. Q118 Which of the following is the MOST effective way to secure access to cloud services through a CASB (Cloud Access Security Broker)?
  119. Q119 You are the Chief Information Security Officer (CISO) at a large multinational corporation. Your corporation is currently revamping its IT systems, requiring…
  120. Q120 Security starts at the top of the organization with a policy document that is implemented through __________. (Choose all that apply.)
  121. Q121 You are the Chief Information Security Officer (CISO) of a major hospital. Recently, your hospital has seen an uptick in attempted ransomware…
  122. Q122 Which authentication method would use something you are expected to have?
  123. Q123 You are the newly appointed Chief Information Security Officer (CISO) for a global corporation with operations in several countries. You have a…
  124. Q124 Which of the following is NOT part of the cryptographic lifecycle?
  125. Q125 Which of the following reflects how many different types of tasks a module can carry out?

More ISC2 certifications

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need