CISSP Practice Questions Directory
Browse our collection of 1111 scenario-based questions to prepare for the CISSP exam.
- Communication and Network Security You receive a scan report showing open ports 135, 139, 445, and 3389, along with OS details for Windows Server...
- Security Operations An EDR system shows that many users are clicking malicious links in phishing emails. To address this root cause effectively,...
- Security Operations A Linux server is vulnerable to a TOCTOU (Time of Check to Time of Use) flaw, allowing unauthorized file access...
- Identity and Access Management You are presenting a budget for a new Identity and Access Management (IAM) system. Which of the following are valid...
- Communication and Network Security Your organization requires a protocol that supports mutual (dual) authentication between servers. Which of the following does NOT provide mutual...
- Security Architecture and Engineering A reference monitor mediates all access requests between subjects and objects to enforce security policies. Which of the following is...
- Identity and Access Management Based on the standard concepts of an Access Control Matrix (ACM), which of the following statements represents a correct 'Capability...
- Identity and Access Management Your organization uses Google Workspace (Google Drive). Which statement accurately describes the access control model used when a user shares...
- Identity and Access Management Your organization is transitioning to Role-Based Access Control (RBAC). Which of the following are core components or characteristics of the...
- Software Development Security You are developing an application that shares diverse data types with other applications via APIs. Which data format is most...
- Identity and Access Management When onboarding new users to a legacy application that only supports single-factor authentication (password), what is the most secure approach...
- Identity and Access Management Before a user can access services through a Service Provider (SP) using SAML, what essential setup must be configured between...
- Asset Security Your company needs to protect sensitive IP data within legacy databases on older Windows servers where data structures cannot be...
- Software Development Security A legacy database lacks audit trails, and entries are being altered by a suspected insider. What step can you take...
- Security Architecture and Engineering You manage many IoT devices running outdated firmware that are not yet End-of-Life (EOL). What action should you take first...
- Security Architecture and Engineering Which of the following countermeasures would be most effective in mitigating the risk of side-channel attacks (like power analysis or...
- Identity and Access Management A company using BYOD policies sees an increase in SIM-swap attacks. Which countermeasure is the highest priority to bolster defenses?
- Asset Security A healthcare organization is transitioning to digital health technologies and connected medical devices. Which action is most critical to safeguard...
- Asset Security A multinational organization is centralizing diverse data assets into a unified data lake. What primary factor should be prioritized for...
- Identity and Access Management When assessing a newly acquired third-party collaboration tool for sharing sensitive data, what is the most crucial factor to focus...
- Security Architecture and Engineering A financial institution needs to ensure that sensitive messages remain unchanged during transmission. Which action most effectively guarantees message integrity?
- Communication and Network Security Which of the following Ethernet cable categories support data transmission speeds above 100 Mbps? (Select all that apply)
- Communication and Network Security An enterprise plans to implement Fibre Channel over Ethernet (FCoE). Which aspect of the existing network must be evaluated to...
- Security Operations A manufacturing company is conducting parallel testing on its new disaster recovery (DR) site. Which specific aspect should be prioritized...
- Asset Security A CISO discovers that many network devices (routers, printers) lack secure default settings. What should be the first course of...
- Security Architecture and Engineering A development team wants an application to 'fail securely' to protect PII. What should they prioritize?
- Identity and Access Management In which area of access control management would Artificial Intelligence (AI) add the most value?
- Security Architecture and Engineering Which component of a SCADA system presents the greatest challenge for robust physical security?
- Security Architecture and Engineering An airline wants to display flight data (altitude, speed) on seat-back Raspberry Pis. How can they implement this while ensuring...
- Communication and Network Security A company is deploying a Next-Generation Firewall (NGFW) to protect against malware and APTs while maintaining high network performance. Which...
- Security Operations Following a phishing attack, which aspect of the internal incident report is most critical for organizational learning and long-term communication?
- Communication and Network Security A large financial institution needs to implement a secure real-time messaging system to facilitate instant communication between traders and compliance...
- Asset Security A healthcare provider is in the process of migrating sensitive patient records to a new Electronic Health Record (EHR) system....
- Security and Risk Management A multinational corporation is selecting a SaaS provider. Which capability is most essential for meeting minimum global security and legal...
- Asset Security A fintech startup is expanding rapidly. What is the most effective strategy for sustainable and scalable asset management?
- Security and Risk Management Your company is transitioning several outsourced marketing operations in-house. What is the first action you should take in response to...
- Security and Risk Management An organization is developing a new employment agreement for marketing staff. Which element is most critical for protecting PII and...
- Security and Risk Management When evaluating a third-party vendor based in a country with relaxed data privacy laws, what is the most essential step...
- Security Operations Which countermeasure is most beneficial in mitigating the risks of automated DDoS attacks against a web-based user data collection form?
- Security Architecture and Engineering Given the Caesar Cipher transformation where (Olssv Kbkl | 7) is decoded as 'Hello Dude,' what is the decoded message...
- Security and Risk Management A new CISO identifies a misalignment between governance and security practices. Which action is most effective in addressing this strategic...
- Security and Risk Management As a new CISO, which actions would be most effective in creating a security-focused culture? (choose all that apply)
- Identity and Access Management A university uses Attribute-Based Access Control (ABAC). A student tries to access a sensitive file from an insecure personal device....
- Security and Risk Management Your company is acquiring another firm. What is the most effective way to verify their true information security posture and...
- Security and Risk Management Which action best indicates that a company is proactively embedding security into its core operational processes at an executive level?
- Security and Risk Management What is the most effective proactive approach to prevent data Integrity issues to explain to a CEO?
- Security and Risk Management When creating a security policy, which characteristic is most essential?
- Security and Risk Management As a CISO, you are tasked with reducing the risk of insider threats. Which of the following measures is LEAST...
- Security and Risk Management You are assessing the effectiveness of practices aimed at preventing collusion. Which of the following is LEAST effective in preventing...
- Security and Risk Management In the context of Open Source Intelligence (OSINT) gathering, which of the following scenarios is considered illegal?