CISSP Practice Questions Directory
Browse our collection of 1111 scenario-based questions to prepare for the CISSP exam.
- Security Operations As part of a disaster recovery exercise, a cloud service provider tests a scenario in which a natural disaster disables...
- Security and Risk Management A financial institution is developing a new online banking platform that will serve customers across multiple jurisdictions. To ensure compliance...
- Software Development Security A large enterprise with a mature cybersecurity program is evaluating advanced sandboxing solutions to defend against Advanced Persistent Threats (APTs)....
- Asset Security An organization is migrating its workloads to cloud-based services and plans to retire on-premises servers that previously stored sensitive research...
- Identity and Access Management A software development organization is running multiple cloud-based projects in parallel. Different teams and roles require access to different cloud...
- Security Operations Following the deployment of a User and Entity Behavior Analytics (UEBA) solution, a security operations team observes coordinated data exfiltration...
- Security Assessment and Testing While performing synthetic transaction monitoring on a cloud-hosted application, an operations team observes repeated timeouts during simulated login and data...
- Security Architecture and Engineering A signals intelligence team intercepts a set of encrypted communications believed to use a classical (pre-modern) cipher. Analysts plan to...
- Identity and Access Management After a security incident, a retail company discovered that the attacker exploited an employee’s user account that remained active even...
- Security and Risk Management An IT department is updating its remote access policies to strengthen network security. Which of the following policies best embodies...
- Security Operations A software development company uncovers a critical security flaw in one of its popular products that could allow attackers to...
- Security and Risk Management A recent risk assessment has highlighted a significant threat from insiders within an organization, primarily because employees currently hold more...
- Communication and Network Security A company uses Kerberos for authentication across its internal systems. The security team is concerned about insider threats, specifically situations...
- Identity and Access Management An online learning platform wants to let students enroll in courses using their existing university accounts. The platform must verify...
- Security and Risk Management A cybersecurity consultant is helping a startup design its first security program. The company operates in a heavily regulated industry...
- Security Architecture and Engineering A network administrator regularly downloads firmware and software updates from a vendor’s official website. Before deploying these updates in production,...
- Software Development Security A software company formally requires its developers to follow secure coding principles as part of their employment contracts. Management wants...
- Security Operations A hospital is validating its disaster recovery capabilities by operating its clinical systems simultaneously at both the primary site and...
- Security and Risk Management As part of a broader IT modernization effort, an organization is planning to move its data storage environment to a...
- Software Development Security During the interface testing of a multi-tier web application, it is discovered that there is insufficient segregation between the presentation...
- Software Development Security A software development company allows its developers to work remotely, raising concerns about the security of its codebase. Which of...
- Security Assessment and Testing During a thorough security review of a network security appliance, it was found that the device uses a fixed cryptographic...
- Security and Risk Management A technology company's mobile application collects user location data to provide personalized content and advertisements. A user residing in California...
- Identity and Access Management A software development company is implementing a new identity management solution to secure access to its code repositories. The company...
- Asset Security Your organization is developing a comprehensive asset inventory as part of its security program. Which of the following tools would...
- Asset Security Your organization is preparing to migrate several business units’ data to a centralized cloud data lake. During planning, the Chief...
- Security and Risk Management A project manager needs to share a confidential project report with an external consultant. The document should remain accessible only...
- Communication and Network Security Your organization has discovered that employees are using unauthorized cloud applications and web services, leading to a significant increase in...
- Communication and Network Security Which of the following is not an effective countermeasure against L2 (Layer 2) Man-in-the-Middle attacks?
- Communication and Network Security Which of the following is not a feature specific to IPv6 that increases security compared to IPv4?
- Communication and Network Security Which of the following should not be considered unicast communication?
- Communication and Network Security Which of the following statements about broadcast communication is not true?
- Communication and Network Security Which of the following best represents an example of Anycast communication?
- Communication and Network Security Which of the following attacks can be carried out through BGP manipulation and results in network traffic being redirected to...
- Communication and Network Security Which of the following protect against replay attacks? (Choose all that apply)
- Communication and Network Security Which of the following information security principles — even if only partially or optionally — has been present in IPv4...
- Communication and Network Security Which of the following statements about IPsec is not true? (Choose all that apply)
- Communication and Network Security How does SSL/TLS provide Perfect Forward Secrecy (PFS)?
- Communication and Network Security In your company, when a user leaves, their account is disabled in Active Directory (AD) because all systems rely on...
- Communication and Network Security Which of the following is NOT considered a common HTTP tunneling technique?
- Communication and Network Security When preparing to start a packet capture in Wireshark, which is typically the first filter you apply to ensure that...
- Communication and Network Security In an enterprise environment, iSCSI connections are often secured using various technical controls. Which of the following is not a...
- Communication and Network Security Which of the following factors can increase the bandwidth (signal-carrying capacity) of a coaxial cable? (Select all that apply)
- Communication and Network Security Which of the following statements about fiber optic cables is incorrect?
- Identity and Access Management Your company uses a well-known Identity and Access Management (IAM) system. One user reports that they’ve lost the ID document...
- Identity and Access Management You discover that a remote employee, who has been working for your company for two weeks, completed the initial registration...
- Identity and Access Management You discover that in your company, user accounts are not deprovisioned after employees leave. This poor practice can lead to...
- Identity and Access Management In your organization, there are three service accounts that the system owners confirm cannot be deleted and must remain active...
- Identity and Access Management According to ISO/IEC 27001 and related best practices, what are you required to do for all service accounts in use...
- Identity and Access Management Which of the following factors can jeopardize all four steps of the IAAA process — Identification, Authentication, Authorization, and Accountability?...