CISSP Practice Questions Directory
Browse our collection of 1111 scenario-based questions to prepare for the CISSP exam.
- Security and Risk Management Under the General Data Protection Regulation (GDPR), which of the following is NOT a recognized right of the data subject?
- Asset Security Your Asset Security Policy mandates the disposal of hardware older than five years. You have high-performing refurbished devices that are...
- Security and Risk Management Your company is transitioning to a risk-centric approach. What is the initial step you should take when creating a thorough...
- Software Development Security Your organization has formed a Scrum team to create an E-Commerce website. Which of the following statements regarding the Scrum...
- Identity and Access Management Which declarative, XML-based access control policy language includes a specific processing model for interpreting and enforcing security policies?
- Security Architecture and Engineering A data center fire triggers a chemical suppression system. The fire is contained, but equipment is damaged. What is the...
- Communication and Network Security Maria is comparing NIDS and NIPS. What is a key similarity between these two network security systems?
- Security and Risk Management A cloud provider is pursuing FedRAMP certification to serve federal agencies. FedRAMP security controls are based on which framework?
- Asset Security When classifying company assets for sensitivity and importance, which factor is the most important consideration?
- Security and Risk Management Which of the following represent key elements involved in a risk analysis process? (Select all that apply.)
- Security and Risk Management A US-based organization discovers that system and user account passwords are for sale on the dark web. Which law or...
- Security and Risk Management Emily is reviewing laws to protect student privacy at a university. Which of the following laws do NOT specifically provide...
- Security Assessment and Testing When planning a security testing schedule for a sensitive financial application, which factors should be considered? (Choose all that apply)
- Security and Risk Management According to NIST 800-53A, a security and privacy assessment evaluates four main components: specifications, mechanisms, activities, and which of the...
- Communication and Network Security What is the most effective method for creating a secure, transparent connection between two physical locations so users can access...
- Asset Security An e-commerce website uses Stripe to process secure online payments. In the context of data protection and privacy regulations, which...
- Security Architecture and Engineering You are conducting a file integrity check. Which of the following actions will NOT result in a change to the...
- Identity and Access Management An organization wants to defend against rainbow table attacks. Which of the following measures would be LEAST effective in protecting...
- Security and Risk Management To enhance security and mitigate insider threats, what is the first step an organization should take in the hiring process?
- Communication and Network Security Your team is transitioning from IPv4 to IPv6. Which of the following statements about IPv6 is FALSE?
- Communication and Network Security An organization plans to segment its network to improve security. Which tool or technology is primarily used to achieve this...
- Security Operations Which of the following attacks can use email as the primary initial attack vector, even if the technical exploitation occurs...
- Communication and Network Security Which of the following is NOT a valid benefit of using Network Address Translation (NAT) in a company's infrastructure?
- Identity and Access Management To prevent 'privilege creep' (users retaining rights they no longer need), which strategy is the most effective and systematic?
- Identity and Access Management A junior administrator needs to install an application on a Windows server that requires elevated rights. Which account type minimizes...
- Identity and Access Management An access management system generates excessive SIEM alerts because it triggers after only two failed password attempts. How should the...
- Communication and Network Security RADIUS is used for secure remote access. Which of the following services are NOT natively provided by the RADIUS protocol?...
- Security and Risk Management While reviewing PCI-DSS requirements to protect payment card data, which of the following is NOT explicitly required by the standard?
- Security and Risk Management Which of the following methods, when applied to sensitive customer data, ensures the process is irreversible and the data cannot...
- Security and Risk Management Under the NIST Risk Management Framework (RMF), at what stage does an organization determine its risk tolerance and risk management...
- Security Architecture and Engineering Regarding cryptographic key lengths and system strength, which of the following statements is INCORRECT? (Select all that apply)
- Security Architecture and Engineering During the SSL/TLS handshake, which of the following does NOT need to be independently verified by the client to trust...
- Security Architecture and Engineering You need to secure an internal-only web application accessed via the corporate LAN. What is the most practical and cost-effective...
- Communication and Network Security In the context of the ISO-OSI model, at which layer(s) can encryption be implemented?
- Communication and Network Security Your team is analyzing the following MAC addresses: Device A (00:1A:CC:3C:9A:55), Device B (00:1A:CC:BC:9A:55), Device C (00:1A:CC:11:9A:55), and Device D...
- Communication and Network Security You are troubleshooting a network where every device connects to a modern managed switch. Using a packet sniffer (Wireshark) on...
- Identity and Access Management A SOC team reports that misaligned timestamps across multiple logs in a SIEM are breaking incident correlation. Which of the...
- Communication and Network Security You have acquired several used PLC devices with known MAC addresses but unknown IP addresses. Which protocol is best suited...
- Security Architecture and Engineering Which cryptographic algorithm is best suited for ensuring the integrity of a large file transmitted between offices over a secure...
- Security Operations When designing a Disaster Recovery Plan (DRP) for critical operations, which of the following should be your FIRST consideration to...
- Software Development Security To minimize security vulnerabilities in a new software application handling sensitive data, which SDLC activity should be prioritized to prevent...
- Communication and Network Security Which of the following access control measures is MOST effective in preventing privilege escalation attacks within an organization?
- Security Operations Your organization is launching a security awareness campaign. Which of the following is NOT typically a goal of such a...
- Security Assessment and Testing Which of the following are recognized steps in the vulnerability assessment process? (Choose all that apply)
- Security Operations Your company has detected suspicious activity and a potential breach on the network. What is the FIRST step you should...
- Security Architecture and Engineering When designing a new user authentication system, which of the following represents the industry best practice for storing user passwords?
- Security and Risk Management As a lead security analyst, you need to prioritize which of several identified vulnerabilities to address first. Which criterion provides...
- Security and Risk Management A multinational corporation is updating its Incident Response (IR) strategy following a major breach. To demonstrate Due Diligence, the Board...
- Identity and Access Management An organization is deploying a cloud-based Federated Identity solution to streamline collaboration with external partners. To mitigate the risk of...
- Asset Security A critical infrastructure provider operates multiple geographically dispersed sites. The Chief Information Security Officer (CISO) reports that the current Asset...