CISSP Practice Questions Directory
Browse our collection of 1111 scenario-based questions to prepare for the CISSP exam.
- Security and Risk Management You are developing a cybersecurity training program for your team. What is an essential element that MUST be included to...
- Security Architecture and Engineering Symmetric cryptography requires the same key for encryption and decryption. Which of the following are viable key-exchange techniques to share...
- Security Assessment and Testing John needs to evaluate the performance of a recently upgraded web application, focusing on infrequently used features to ensure a...
- Security Architecture and Engineering You are deploying an ERP software that must be efficient, comply with security policies, and allow users to verify integrity....
- Communication and Network Security IPsec (Internet Protocol Security) is a suite designed to secure internet communications. Which of the following are primary functions of...
- Asset Security Which BIA metric describes the maximum tolerable amount of data loss, measured in time, following a disruptive event?
- Communication and Network Security Layer 1 of the OSI model is the Physical Layer. Which of the following are considered standard interfaces or protocols...
- Communication and Network Security Due to technological advancements like switching, which networking domain is experiencing a significant reduction in size or even disappearing?
- Identity and Access Management Malicious actors use various methods to steal passwords. Which of the following attacks is typically the fastest for uncovering passwords...
- Security Architecture and Engineering A server was implemented without a UPS and subsequently incurred hardware damage. What is the most likely cause, and how...
- Security Assessment and Testing You are preparing a report for the board regarding a recent vulnerability assessment. What is the most professional way to...
- Security Assessment and Testing As a CISO, you have completed the Discovery, Enumeration, Vulnerability Mapping, and Exploitation phases of a penetration test. What is...
- Security Architecture and Engineering A proximity detector is often used in physical security and automation. Which of the following accurately describes this device?
- Security and Risk Management Which document formally authorizes the existence of a project and provides the Project Manager with the authority to apply organizational...
- Security Architecture and Engineering You are designing a distributed system where components must be notified of events in other components while remaining loosely coupled....
- Software Development Security Which tool provides a graphical representation of attack paths to help a development team understand all the ways a specific...
- Identity and Access Management During an audit of access rights, you find confusion regarding terminology. Which term BEST describes the specific level of privileges...
- Asset Security Your corporation is reviewing its data policy after frequent misclassifications. Which of the following works BEST as a label for...
- Security and Risk Management Your company finds that users have read access to data not necessary for their jobs. Which principle should guide the...
- Security Architecture and Engineering A bank administrator needs to ensure that software updates from a vendor have not been altered. Which action is most...
- Security and Risk Management Which remote access policy most effectively demonstrates the 'Trust but Verify' principle in a highly regulated financial firm?
- Asset Security A bank relies on a critical application that is End-of-Life (EOL) with no upgrade path. What is the best strategy...
- Security Assessment and Testing Interface testing reveals inadequate separation between the presentation layer and the data access layer in a healthcare app. What is...
- Communication and Network Security A global organization is implementing cloud-based federated identity. Which measure is most effective in preventing unauthorized access from compromised federated...
- Security Operations A physical security operations console is overwhelmed by repeated alerts generated by the same events, leading to operator fatigue and...
- Software Development Security In the Model-View-Controller (MVC) architecture, which layer acts as the intermediary that facilitates interaction between the data logic and the...
- Security and Risk Management An organization has suffered social engineering attacks. Which training strategy is MOST effective for helping employees recognize and respond to...
- Security Architecture and Engineering A bank is integrating a third-party analytics vendor. To minimize the risk of data leaks during regular data exchanges, which...
- Identity and Access Management After a breach involving a former employee's active account, which action should a company prioritize FIRST to prevent recurrence?
- Security Operations A manufacturing company wants to improve its Disaster Recovery (DR) simulation by replicating realistic communication obstacles. Which action best achieves...
- Security and Risk Management A US company exporting an advanced network tool with decryption capabilities must ensure compliance with international regulations. What is the...
- Security Architecture and Engineering When designing a surveillance system for a new data center, which approach most effectively protects against camera tampering?
- Software Development Security A significant security vulnerability is discovered in proprietary production software that allows unauthorized process modifications. What is the FIRST step...
- Identity and Access Management A development team needs an Identity and Access Management solution that is flexible enough to handle developers switching between different...
- Software Development Security You are the lead security engineer for a new microservices-based application. Which security approach should you prioritize to ensure robust...
- Security Operations Your SOC tools trigger alerts of simultaneous file modifications across several departments. What is the best immediate action to contain...
- Security and Risk Management During a daily scrum, a developer publicly accuses another of intentionally introducing a security vulnerability. How should the project manager...
- Security Architecture and Engineering A financial services company is consolidating operations into a single, secure data center. Which security measure should be prioritized to...
- Identity and Access Management You are configuring auditing for a new third-party access control software and want to gather a broad set of data...
- Security Architecture and Engineering Your monitoring cameras are experiencing intermittent feed loss and degraded image quality. What troubleshooting steps should you take first?
- Security and Risk Management Your company is launching an application that processes personal data. Which practice best demonstrates the implementation of 'Privacy by Design'?
- Security Architecture and Engineering An organization is attempting to send a message with integrity protection. The following steps are described: 1. Digest is encrypted....
- Security and Risk Management When should a Business Continuity Plan (BCP) be updated to ensure it remains effective and relevant?
- Communication and Network Security Your organization wants to gather publicly available information to map a target company's network during a security assessment. Which technique...
- Security and Risk Management Which of the following sensitive assets can be effectively protected under trade secret laws? (Select all that apply)
- Security and Risk Management Your organization is using the STRIDE framework to identify threats. Which scenarios would NOT be effectively verified or addressed by...
- Communication and Network Security During a meeting regarding secure communication, the components of the Transport Layer Security (TLS) protocol are discussed. Which of the...
- Software Development Security A new web application has just been deployed. What should be the first critical step taken to minimize potential security...
- Security Architecture and Engineering Your company is implementing digital signatures for financial transactions. Which of the following security goals are achieved by using digital...
- Security Operations In a banking application, programmers are restricted from updating production code without a formal review and approval process. This ensures...