CISSP Practice Questions Directory
Browse our collection of 1111 scenario-based questions to prepare for the CISSP exam.
- Asset Security As a new CISO, you find several retired hard disks in the server room containing sensitive data in plaintext. What...
- Security Architecture and Engineering Following a spike in abnormal network traffic, you need to provide a report to C-level executives quickly. Which step should...
- Security and Risk Management While gathering personal data from potential customers for marketing purposes, which of the following options is the most effective for...
- Security and Risk Management You are reviewing the effectiveness of security controls for a specific business unit and find an inadequate assessment. Based on...
- Security Architecture and Engineering You are designing a cryptographic system for sensitive financial data. Which of the following is the most effective way to...
- Security and Risk Management What is the most commonly established committee at the board level, also known as governance committees, in accordance with legal...
- Security Operations A CEO wants a centralized log management solution implemented immediately for a financial institution. What is your plan to proceed?
- Software Development Security Your company aims to transition from a chaotic software construction approach with poor design to a methodology characterized by well-defined...
- Asset Security If we disregard factors of cost and feasibility, which method is most effective to guarantee that no residual data remains...
- Software Development Security In a high-security environment, which container runtime security practice should be prioritized to prevent unauthorized access and ensure data privacy...
- Security Architecture and Engineering You need to choose memory for storing embedded system firmware that is updated infrequently but must be updateable when necessary....
- Security Architecture and Engineering When implementing Trusted Platform Modules (TPMs) on corporate devices, which of the following represents the most significant security concern for...
- Identity and Access Management As a CISO implementing Single Sign-On (SSO) to simplify access management, what is the most significant security concern associated with...
- Security Assessment and Testing During misuse case testing for a new web application, you identify a threat where an attacker exploits the data encryption...
- Security Architecture and Engineering A healthcare organization is migrating patient records to the cloud. Which of the following sequences of actions represents the most...
- Security Architecture and Engineering You are conducting a threat modeling exercise using the STRIDE model for a new online payment system. Which of the...
- Identity and Access Management A CISO wants to improve user experience and access speed for critical systems while maintaining security. Which strategy is most...
- Asset Security As a newly appointed CISO, you must identify which assets require your direct, hands-on management. Which of the following should...
- Asset Security Which of the following best describes personal information according to standards like NIST SP 800-122 and GDPR? (Choose all that...
- Asset Security According to HIPAA, which of the following types of information are correctly classified as Personal Health Information (PHI)? (Choose all...
- Security Operations To assess the overall effectiveness of a comprehensive security awareness training program, which metric would best reflect the achievement of...
- Asset Security As a CISO overseeing the development of a data classification policy, what is the ultimate goal of the data classification...
- Asset Security To implement an effective data classification framework, which factors should a CISO consider to determine how data is stored, accessed,...
- Asset Security When considering various aspects of data classification in a large organization, which of the following statements are true?
- Asset Security Which of the following examples correctly represent 'data at rest' within a mid-sized organization? (Select all that apply)
- Security and Risk Management As the Compliance Officer of a global e-commerce company, which activities fall under your direct responsibility? (Select all that apply)
- Identity and Access Management Regarding the roles and responsibilities in data management, which of the following statements is true?
- Identity and Access Management You are working for a mid-sized company that is implementing access controls for sensitive data. What is the primary purpose...
- Identity and Access Management A company discovered a timing flaw where authorization checks were bypassed during the authentication process. To address this issue, which...
- Identity and Access Management Your company operates a critical application that requires robust security, but can only implement single-factor authentication (1FA). Which of the...
- Identity and Access Management Your company has a user represented by multiple identities across various applications (e.g., name.surname vs name_surname). Which of the following...
- Security and Risk Management A financial services company needs to create a report for regulators to demonstrate the security posture of its cloud-based infrastructure....
- Identity and Access Management Your company is implementing a system requiring users to provide two passwords stored in separate databases. What does this approach...
- Identity and Access Management Which of the following statements are true about passkeys for enhancing authentication?
- Security Operations Rumors suggest an employee is selling confidential data. How would you define the potential risks and propose a security measure...
- Security and Risk Management As a CISO of a multinational company, what is an essential consideration when formulating policies for Personally Identifiable Information (PII)...
- Asset Security What terms describe laws that require compliance regardless of data location and laws that mandate data remain within physical borders?
- Communication and Network Security You aim to ensure the security of data transmission between your servers and traveling C-level clients abroad. Which solution should...
- Security and Risk Management Your company is transitioning to a risk-centric approach and you must conduct a thorough Risk Assessment. What is the initial...
- Security Architecture and Engineering If you aim to deploy a customized version of Linux Ubuntu in the cloud without investing time in network optimization...
- Asset Security You have determined that all incoming data must be accompanied by metadata. Which of the following are examples of system...
- Asset Security When formulating a Data Classification policy for a medium-sized enterprise, what is the foremost aspect to consider?
- Identity and Access Management A company is launching a new online system for a diverse global workforce. Which registration and identity proofing method best...
- Security Assessment and Testing After theoretical vulnerability reports failed to secure a higher security budget from the CEO, what is the best next step...
- Security Operations Attackers frequently exploit log files to conceal their activities. Which of the following methods can enhance the security and integrity...
- Security Operations Which organizational control serves the dual purpose of detecting fraudulent activities and acting as a contingency plan for employee departure?
- Security Operations Managing changes through requests is vital for system stability. What component will a Change Request always have?
- Asset Security While working for a medium-sized enterprise, you are tasked with data classification. Which of the following statements is the LEAST...
- Asset Security Your company's workforce and data storage are expanding. Given your current levels (Low, Medium, High), what step will you take...
- Security and Risk Management Which of the following best describes an Information Security Management System (ISMS)?