ISC2 CISSP (Certified Information Systems Security Professional) practice questions

244 free questions with answers and explanations.

Practice test
  1. 51.A large enterprise is designing a new campus network and needs to segment different departments to enhance security and manage broadcast domains efficiently. Each department requires its own logical network, but the physical infrastructure should remain shared to reduce costs. Which technology would best achieve this segmentation?Communication and Network Security
  2. 52.A company policy dictates that all 'Confidential' data must be stored on encrypted file shares and only accessible by authorized personnel with a 'need-to-know'. A junior administrator accidentally moves a folder containing 'Confidential' customer records to a publicly accessible unencrypted network share. Which of the following controls was PRIMARILY circumvented by this action?Asset Security
  3. 53.A global e-commerce company is updating its data retention policy for customer transaction records. Due to varying legal and regulatory requirements across different jurisdictions, the company must ensure that data is not kept longer than legally mandated, but also not deleted prematurely if still required for business operations or legal hold. What is the MOST critical element to establish for an effective data retention policy in this complex environment?Asset Security
  4. 54.An organization is migrating sensitive customer data from on-premises servers to a public cloud storage service. To meet regulatory requirements, the data must remain encrypted at all times, including during transfer and when stored in the cloud. Furthermore, the organization wants to ensure that the CSP cannot access the plaintext data. Which encryption strategy should be implemented?Asset Security
  5. 55.A software development company is implementing a new policy for handling source code, which is considered highly proprietary. The policy states that all source code files must be digitally signed by the developer upon check-in to the version control system and that an automated scan must verify the signature's validity before the code can be accepted into the main branch. Which security objective is this policy primarily designed to enforce?Asset Security
  6. 56.A software development company uses an agile methodology and frequently deploys updates to its customer-facing applications. The company processes customer payment information. To comply with PCI DSS and ensure that sensitive cardholder data is never stored on developer workstations or in non-production environments, which of the following is the MOST effective administrative control?Asset Security
  7. 57.A research institution collects and processes genetic data for scientific studies. This data is highly sensitive and requires stringent protection. According to best practices, who is ultimately accountable for determining the classification level of this genetic data and approving its access requirements?Asset Security
  8. 58.A government agency is implementing a new system to store classified documents. The system design includes mandatory access control (MAC) mechanisms where access decisions are based on the sensitivity labels of the documents and the clearance levels of the users. Which of the following is the MOST relevant concept being applied here?Asset Security
  9. 59.A system administrator is configuring access controls for a critical financial application. The application processes highly sensitive customer transaction data. According to best practices in asset security, which role is ultimately responsible for defining the classification of this data and approving its access requirements?Asset Security
  10. 60.An organization is developing a new data classification scheme. They need to ensure that the scheme properly categorizes information based on its sensitivity and impact if compromised. Which of the following is the MOST appropriate first step in developing an effective data classification scheme?Asset Security
  11. 61.A financial institution is implementing a new data loss prevention (DLP) solution. The solution needs to identify and block the transmission of credit card numbers (PANs) and Social Security Numbers (SSNs) from internal systems to external networks. Which data security control category does this DLP solution primarily fall under?Asset Security
  12. 62.A cloud service provider (CSP) offers object storage for sensitive customer data. A client requires that cryptographic keys for their data stored in this service are generated, stored, and managed solely within their own on-premises Hardware Security Modules (HSMs). Which of the following key management models best describes this client's requirement?Asset Security
  13. 63.A financial services organization is reviewing its data handling practices for customer Personally Identifiable Information (PII). According to best practices and regulatory compliance, which role is ultimately accountable for determining the classification level and protection requirements for this PII?Asset Security
  14. 64.A manufacturing company uses several Supervisory Control and Data Acquisition (SCADA) systems to manage its industrial processes. These systems generate vast amounts of operational data, which is critical for real-time monitoring and historical analysis. The PRIMARY concern for this operational data is its continuous availability and integrity, as any disruption could lead to production halts and safety risks. Which asset security principle is paramount for this SCADA operational data?Asset Security
  15. 65.A government contractor is decommissioning a server rack containing multiple hard drives that previously stored 'Secret' classified information. The contract mandates that all media containing classified data must be subject to specific destruction procedures outlined in NIST SP 800-88 Rev. 1. What is the MOST appropriate data sanitization method for these hard drives to meet the 'Secret' classification requirements?Asset Security
  16. 66.A company is implementing a new policy for handling 'Confidential' data. The policy states that all such data must be stored on encrypted file shares, accessed only by authorized personnel, and automatically subject to a 7-year retention period. Which type of data security control is the 'encrypted file shares' requirement an example of?Asset Security
  17. 67.A global pharmaceutical company is undergoing a divestiture, separating a division into a new independent entity. This division holds critical intellectual property (IP) and patient data. During the data transfer process, what is the MOST important consideration regarding the handling of this data to ensure legal and regulatory compliance for both entities?Asset Security
  18. 68.A multinational corporation is implementing a new global data handling policy. The Chief Privacy Officer (CPO) is tasked with ensuring compliance across all jurisdictions. Which of the following principles is paramount when designing data retention schedules for personal data collected from EU citizens?Asset Security
  19. 69.A financial institution processes Personally Identifiable Information (PII) for millions of customers. A new regulatory requirement mandates that all PII used for marketing purposes must be logically segregated from operational PII and subject to stricter access controls. Which data security control category does this requirement primarily fall under?Asset Security
  20. 70.A global e-commerce company is migrating its customer database to a public cloud environment. The company's policy dictates that all Personally Identifiable Information (PII) must be protected at rest and in transit. To meet regulatory compliance, the company wants to ensure that the cloud provider does not have access to the encryption keys for their most sensitive customer data. Which encryption key management approach should the company implement?Asset Security
  21. 71.A software development firm is using an agile methodology and frequently deploys updates to its cloud-native applications. They need to ensure that database backups containing customer PII are securely marked and handled according to their 'Confidential' classification. What is the PRIMARY purpose of 'labeling' these backups?Asset Security
  22. 72.A healthcare organization is decommissioning several servers that contain electronic protected health information (ePHI). According to NIST SP 800-88 Revision 1 guidelines, which data sanitization method is most appropriate to ensure that the data cannot be retrieved by any known technology, given the sensitive nature of the information and the need for absolute destruction?Asset Security
  23. 73.A financial services company is preparing for an audit of its data retention policies. The auditor is specifically interested in how the company ensures compliance with legal and regulatory requirements for retaining transaction records, which mandate a minimum retention period of seven years. Which of the following is the MOST critical aspect for the company to demonstrate to the auditor regarding its data retention practices?Asset Security
  24. 74.A multinational corporation operates in several jurisdictions, each with distinct data privacy regulations (e.g., GDPR, CCPA). The company stores customer Personally Identifiable Information (PII) in a central data lake. To ensure compliance across all regions, which of the following data handling requirements is MOST critical to implement for this PII?Asset Security
  25. 75.A financial services company is preparing for an audit of its data retention policies. The auditor specifically asks for evidence that customer transaction data, which is classified as 'Confidential', is retained only for the legally mandated period of 7 years and then securely disposed of. Which of the following elements is MOST critical for demonstrating compliance with this requirement?Asset Security
  26. 76.A multinational corporation is implementing a new global data handling policy. They have identified that certain customer data, while not explicitly classified as 'confidential,' must only be collected and processed for the specific purpose for which it was originally obtained. What privacy principle is the corporation emphasizing with this requirement?Asset Security
  27. 77.A global pharmaceutical company is conducting an internal audit of its research and development data. The audit reveals that highly sensitive experimental drug formulas are being stored on unencrypted, publicly accessible cloud storage buckets. Which of the following data security controls has most critically failed in this scenario?Asset Security
  28. 78.A large e-commerce company stores vast amounts of customer data, including names, addresses, credit card numbers, and purchase history. The company has a privacy policy stating that customer data will only be used for order fulfillment and personalized marketing, and will not be shared with third parties without explicit consent. This policy is an example of what core aspect of protecting privacy?Asset Security
  29. 79.A financial institution is implementing a new data classification scheme. The Chief Information Security Officer (CISO) is defining the roles and responsibilities for managing the lifecycle of sensitive customer data. Which role is ultimately accountable for determining the classification level of specific datasets and authorizing access to them?Asset Security
  30. 80.A multinational corporation operates in several countries, each with distinct data privacy regulations regarding the collection, processing, and storage of customer data. The company is developing a global data handling policy. Which principle, often found in privacy regulations like GDPR, dictates that personal data should only be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes?Asset Security
  31. 81.A healthcare provider is deploying a new Electronic Health Record (EHR) system. The system will store highly sensitive patient medical information. To comply with HIPAA and other privacy regulations, the organization must ensure that patient data is not used for purposes beyond direct patient care, billing, and healthcare operations without explicit consent. Which privacy principle is primarily being addressed here?Asset Security
  32. 82.A healthcare organization is decommissioning an old server that stored electronic protected health information (ePHI). The server's hard drives contain sensitive patient data that must be permanently rendered unrecoverable to comply with HIPAA regulations and organizational policy. Which of the following data sanitization techniques provides the HIGHEST level of assurance for permanent data destruction?Asset Security
  33. 83.A financial institution is implementing a new data classification scheme for its customer information. The scheme defines 'Confidential' data as information whose unauthorized disclosure would cause severe financial damage or legal penalties. Which of the following is the MOST appropriate next step after defining this classification level?Asset Security
  34. 84.An organization is migrating its on-premises customer database, containing PII, to a public cloud environment. Before the migration, a data governance committee determines that certain fields, such as customer names and email addresses, must be obfuscated or replaced with fictitious data for all non-production environments (development, testing, QA). Which data security control is being applied here?Asset Security
  35. 85.A cloud service provider (CSP) offers various data storage options to its clients. A client needs to store highly confidential intellectual property data that requires the highest level of assurance regarding data confidentiality and integrity, even if the underlying storage infrastructure is compromised. Which data security control, if implemented by the CSP, would best address this client's concern?Asset Security
  36. 86.An organization is migrating its on-premises data center to a public cloud environment. They have classified their data into four categories: Public, Internal Use Only, Confidential, and Highly Confidential. The legal department has mandated that 'Highly Confidential' data, which includes trade secrets and unpatented inventions, must always reside within the organization's legal jurisdiction and should not be accessible by the cloud provider's staff, even for maintenance. Which of the following approaches BEST satisfies these requirements?Asset Security
  37. 87.A healthcare provider is decommissioning an aging Electronic Health Record (EHR) system that contains sensitive patient data. Before the physical disposal of the associated storage media (hard drives), which data sanitization method provides the HIGHEST level of assurance that the data cannot be recovered, even with advanced forensic techniques?Asset Security
  38. 88.An organization is developing a new data classification scheme. They need to ensure that the classification levels accurately reflect the potential impact of unauthorized disclosure, alteration, or destruction of the data. Which of the following is the MOST important objective of this data classification effort?Asset Security
  39. 89.A company is decommissioning a server farm containing hundreds of hard drives that stored various classifications of data, including 'Confidential' customer PII and 'Public' marketing materials. To ensure compliance with data sanitization standards for the 'Confidential' data while being cost-effective for 'Public' data, which combination of sanitization methods would be MOST appropriate?Asset Security
  40. 90.A cloud service provider (CSP) offers various storage services to its clients. A client stores highly sensitive financial transaction data with the CSP but requires full control over the encryption and decryption processes, including key management. Which of the following models BEST describes this client's requirement?Asset Security
  41. 91.A cryptocurrency exchange platform is implementing a new system to manage user wallets and transaction keys. Due to the high value and sensitivity of these assets, the platform requires a solution that generates, stores, and manages cryptographic keys in a hardened, tamper-resistant hardware device. Which security architecture element is best suited for this purpose?Security Architecture and Engineering
  42. 92.A security engineer is evaluating the physical security of a data center. The primary goal is to prevent unauthorized access to sensitive server racks, even if an intruder manages to bypass the perimeter and building access controls. Which of the following physical security controls would be most effective at this specific point?Security Architecture and Engineering
  43. 93.A security architect is evaluating a new manufacturing control system that utilizes embedded devices. The architect discovers that critical firmware updates are delivered over an unencrypted channel without any integrity checks. This vulnerability could allow an attacker to install malicious firmware. Which security principle is primarily violated in this scenario?Security Architecture and Engineering
  44. 94.A security auditor is reviewing a custom-developed application and identifies a vulnerability where the application explicitly trusts user-supplied data in HTTP headers, leading to potential privilege escalation if a malicious user crafts specific header values. This vulnerability falls under which category of Web-based systems vulnerabilities?Security Architecture and Engineering
  45. 95.A government agency is designing a new information system that handles classified documents. The system must enforce strict confidentiality, ensuring that users can only read information at or below their security clearance level, and cannot write to objects at a lower security level than their own. Which security model best fits this requirement?Security Architecture and Engineering
  46. 96.A security auditor is reviewing a web application and discovers that it is vulnerable to Cross-Site Scripting (XSS). Which OWASP Top 10 category does XSS primarily fall under, and what is the fundamental cause of this vulnerability?Security Architecture and Engineering
  47. 97.A system administrator is configuring a new server for a multi-tenant application. To enhance security and prevent one tenant's processes from directly accessing or corrupting the memory space of another tenant or the operating system kernel, which fundamental security capability of information systems should be properly implemented and configured?Security Architecture and Engineering
  48. 98.A team is designing a new microservices architecture. They need a mechanism to ensure that each service can cryptographically verify the origin and integrity of messages received from other services within the architecture. Which cryptographic primitive is best suited for this purpose, assuming confidentiality is handled separately?Security Architecture and Engineering
  49. 99.A security engineer is tasked with designing a system that ensures the integrity of data throughout its lifecycle, from creation to archival. The system must prevent unauthorized modification of data and maintain an audit trail of all changes. Furthermore, it must ensure that data is always transformed in a 'valid' state, adhering to strict business rules. Which security model is most effective for achieving these specific integrity goals?Security Architecture and Engineering
  50. 100.A financial institution is migrating its legacy systems to a modern cloud-native architecture. They need to ensure that data in transit between microservices, and between the application and external clients, is protected from eavesdropping and tampering. Which cryptographic method is most suitable for establishing secure communication channels in this scenario?Security Architecture and Engineering