ISC2 CISSP (Certified Information Systems Security Professional) practice questions
244 free questions with answers and explanations.
- 101.A manufacturing facility is upgrading its Industrial Control Systems (ICS) and is concerned about supply chain attacks compromising firmware before deployment. They need a mechanism to cryptographically verify the authenticity and integrity of firmware updates received from vendors. Which cryptographic method is essential for achieving this goal?Security Architecture and Engineering
- 102.A security architect is designing a new system that needs to operate reliably even when individual components fail. The system processes critical data, and any interruption in service could have severe consequences. Which architectural principle should be heavily incorporated to ensure continuous operation and data availability?Security Architecture and Engineering
- 103.A software development team is designing a new web application that will handle sensitive customer data. They are concerned about potential vulnerabilities introduced during the coding phase. Which of the following principles should they prioritize to mitigate common web application risks identified by organizations like OWASP?Security Architecture and Engineering
- 104.A company is implementing a new cloud-based application that processes sensitive customer data. To ensure data at rest is protected, they decide to use full disk encryption on the virtual machines. Which key management practice is crucial for maintaining the security of these encrypted disks, especially during operational changes or disaster recovery scenarios?Security Architecture and Engineering
- 105.A security architect is evaluating a new embedded system designed for industrial control. The system needs to guarantee the integrity of its operating system and firmware from unauthorized modification throughout its lifecycle, even during boot-up. Which security capability is most crucial for achieving this requirement?Security Architecture and Engineering
- 106.A healthcare organization is developing a new patient record system. They need to ensure that the system design inherently protects patient privacy throughout the entire data lifecycle, from collection to deletion, without requiring extensive add-on security features. Which design principle is being emphasized here?Security Architecture and Engineering
- 107.A manufacturing plant is integrating new Internet of Things (IoT) sensors into its operational technology (OT) network to monitor equipment performance. These sensors have limited processing power and memory. Which type of cryptographic key is generally preferred for securing communication between these resource-constrained devices and a central server, and why?Security Architecture and Engineering
- 108.A global enterprise is designing its network infrastructure to support highly confidential data processing across multiple international sites. Due to stringent regulatory requirements, the solution must ensure that data processed in one country cannot be accessed by personnel whose roles are restricted to other countries, even if they have equivalent clearance levels. Which security architecture element is most effective in enforcing this type of strict, context-aware access control based on geographical or organizational separation?Security Architecture and Engineering
- 109.A financial institution is developing a new mobile banking application. During the design phase, the security team identifies a significant risk related to unsecured data storage on the client device. Which specific mobile system vulnerability category does this fall under, and what is a common mitigation strategy?Security Architecture and Engineering
- 110.An organization is deploying a new web server that will host a public-facing application. To prevent common attacks such as SQL Injection and Cross-Site Scripting (XSS), the development team is adopting a 'secure by design' approach. Which of the following is the most effective security control to implement at the application layer to mitigate these specific vulnerabilities?Security Architecture and Engineering
- 111.A security architect is designing a system for handling highly sensitive government intelligence. The primary concern is preventing unauthorized disclosure of information, even if a subject has legitimate access at a lower classification level. Which security model is most appropriate for this requirement?Security Architecture and Engineering
- 112.A developer is creating a mobile application that processes payment information. The application needs to securely store cryptographic keys on the device to perform encryption and decryption operations. Which security capability of mobile systems is specifically designed to provide a hardware-backed, isolated environment for storing such sensitive data?Security Architecture and Engineering
- 113.An organization is implementing a Trusted Platform Module (TPM) in its new laptop fleet. Beyond secure boot, which specific security capability does the TPM provide that helps ensure the integrity of the operating system and applications loaded after the initial boot process, particularly against persistent malware or rootkits?Security Architecture and Engineering
- 114.A software development team is adopting a 'Security by Design' approach for a new critical application. One of the key principles they are implementing is 'Minimizing the Attack Surface'. Which of the following actions best exemplifies this principle in practice during the design and development phases?Security Architecture and Engineering
- 115.A security architect is designing a new system that will handle sensitive government intelligence. The primary requirement is to prevent information from flowing from a higher security level to a lower security level, even if the user has clearance for both. Which security model is best suited to enforce this specific confidentiality requirement?Security Architecture and Engineering
- 116.A team is designing a new microservices architecture. They need a mechanism to ensure that each service can cryptographically verify the origin and integrity of messages received from other services within the architecture. Which cryptographic primitive is best suited for this purpose, assuming confidentiality is handled separately?Security Architecture and Engineering
- 117.A large organization is migrating its legacy on-premise applications to a cloud-native architecture. They need a solution that can manage user identities and access across both on-premise and multiple cloud environments, providing a unified single sign-on experience. Which of the following identity services BEST addresses this hybrid cloud requirement?Identity and Access Management (IAM)
- 118.A security team is implementing logical access controls for a new enterprise resource planning (ERP) system. They want to ensure that users can only initiate transactions (e.g., 'create purchase order') and view reports relevant to their specific department and job function, without being able to modify system configurations or access sensitive HR data. Which principle of access control is being MOST directly applied?Identity and Access Management (IAM)
- 119.A security architect is designing an authentication system for a critical infrastructure facility. The system must provide strong assurance of identity and resist attacks like replay attacks and credential compromise. Which authentication mechanism, when properly implemented, offers the highest level of assurance against these threats by using cryptographic techniques?Identity and Access Management (IAM)
- 120.A healthcare organization is migrating its patient records system to a cloud-based Identity as a Service (IDaaS) provider. The security team is particularly concerned about ensuring the confidentiality and integrity of patient data during authentication and authorization processes handled by the IDaaS. Which control is MOST critical to implement and verify with the IDaaS provider to mitigate these concerns?Identity and Access Management (IAM)
- 121.A software development company is adopting a DevOps culture and needs to manage access for automated processes and microservices without using traditional user credentials. They require a secure method for these non-human entities to authenticate and obtain authorization to interact with other services and resources. Which protocol or framework is MOST appropriate for this scenario?Identity and Access Management (IAM)
- 122.A security auditor is reviewing an organization's access control matrix. The matrix shows that a specific user, 'Alice', has 'read' access to 'Project X' files and 'write' access to 'Project Y' files. The auditor notes that 'Project Y' files are highly sensitive and should only be accessible by project leads. Which access control model is MOST likely being used?Identity and Access Management (IAM)
- 123.An organization is designing an access control system for a highly secure research laboratory. Access to the lab requires employees to use a smart card, enter a PIN, and pass a retina scan. Additionally, access is only granted during specific working hours and only if the employee's security clearance level matches the lab's classification. What type of access control, combining multiple factors and contextual rules, is being implemented?Identity and Access Management (IAM)
- 124.A system administrator observes a sudden surge of failed login attempts originating from a single IP address against multiple user accounts on the company's external-facing web application. The attempts are occurring rapidly, trying various common passwords. Which type of access control attack is MOST likely underway?Identity and Access Management (IAM)
- 125.A system administrator is investigating a series of unauthorized access attempts to a critical server. The logs show numerous login failures originating from a single IP address, systematically trying different usernames and common passwords. Which type of access control attack is MOST likely occurring?Identity and Access Management (IAM)
- 126.A security administrator is evaluating a new authentication system that uses cryptographic keys stored on a hardware token (e.g., a YubiKey) for user authentication. The system requires the user to insert the token and then touch it to complete the login process. Which authentication factor does the 'touching the token' action primarily represent?Identity and Access Management (IAM)
- 127.A multinational corporation is expanding its operations and requires a standardized, federated identity management solution to allow employees seamless access to resources across different subsidiaries and cloud services, without requiring multiple credentials. Which of the following technologies is BEST suited to achieve this goal?Identity and Access Management (IAM)
- 128.A security architect is designing a new access control system for a critical infrastructure facility. The system must ensure that access decisions are based on a comprehensive set of environmental conditions, user attributes, resource attributes, and defined policies, rather than predefined roles or static permissions. Which access control model best fits this requirement?Identity and Access Management (IAM)
- 129.A global company is integrating a new cloud-based Human Resources (HR) application. This application needs to synchronize employee identity data (e.g., new hires, terminations, role changes) with the company's on-premise Active Directory and other SaaS applications in real-time. Which standard is specifically designed to automate and manage user provisioning and deprovisioning across disparate systems?Identity and Access Management (IAM)
- 130.A security auditor discovers that several former employees still have active accounts on various internal systems, and their access has not been revoked. This oversight poses a significant security risk. Which aspect of the identity and access provisioning lifecycle has failed?Identity and Access Management (IAM)
- 131.A financial institution is implementing a new customer-facing portal that requires strong authentication for online banking transactions. The security team wants to incorporate a method where users are prompted for a one-time passcode generated by a mobile application on their registered smartphone. Which authentication factor does this scenario primarily represent?Identity and Access Management (IAM)
- 132.A project manager is concerned about the security implications of integrating an external vendor's cloud-based application with the company's internal services. The vendor proposes using Security Assertion Markup Language (SAML) for user authentication and authorization between the two environments. What primary benefit does SAML offer in this scenario?Identity and Access Management (IAM)
- 133.A company is integrating a new cloud-based CRM application from a third-party vendor. The security team wants to ensure that user identities and authentication are managed centrally within the company's existing Active Directory, rather than creating separate accounts in the CRM. Which federated identity standard is BEST suited for this requirement, specifically for authentication and authorization?Identity and Access Management (IAM)
- 134.A financial institution is integrating a new cloud-based customer relationship management (CRM) system that will store sensitive customer data. They are concerned about ensuring the confidentiality and integrity of identity data managed by the third-party cloud provider. Which of the following is the MOST effective contractual and technical control combination to mitigate these risks?Identity and Access Management (IAM)
- 135.A security team is evaluating methods to enhance the security of their remote access VPN. They want to implement a solution that requires users to provide something they uniquely possess, in addition to their password, to authenticate. Which authentication factor category does this 'something they possess' fall under?Identity and Access Management (IAM)
- 136.A company is implementing a new physical access control system for its data center. The security team wants to ensure that access is granted based on attributes like job role, time of day, and specific project assignment. Which access control model would BEST support this granular, context-aware decision-making?Identity and Access Management (IAM)
- 137.An organization is implementing an identity management system that must ensure that users can only access resources absolutely necessary for their job functions, and that these permissions are automatically removed when their roles change or they leave the organization. Which principle is MOST critical for the successful implementation and continuous enforcement of this system?Identity and Access Management (IAM)
- 138.A financial institution is implementing a new customer-facing portal that will integrate with various internal and external services. To enhance security and user experience, they decide to use a centralized identity provider for authentication and authorization, allowing customers to use their existing social media accounts (e.g., Google, Facebook) to log in. What is the MOST significant security risk associated with relying heavily on third-party identity services for customer authentication?Identity and Access Management (IAM)
- 139.A security engineer is configuring a new system where user provisioning needs to be highly automated and synchronized across multiple disparate systems (e.g., HR system, Active Directory, cloud applications). The goal is to ensure that when a new employee is hired, their accounts are created automatically, and when they leave, their access is revoked consistently across all systems. Which protocol or standard is MOST suitable for automating identity provisioning and de-provisioning in this complex environment?Identity and Access Management (IAM)
- 140.A security engineer is configuring a new system where user provisioning needs to be highly automated and standardized across various cloud applications. The goal is to reduce manual effort and ensure consistency in identity data exchange. Which open standard is specifically designed to facilitate automated user provisioning and deprovisioning between identity providers and service providers?Identity and Access Management (IAM)
- 141.A large multinational corporation is implementing a new global identity and access management (IAM) system. The security architect is tasked with ensuring that access reviews are conducted periodically and that dormant accounts are promptly disabled. Which aspect of the identity and access provisioning lifecycle is being addressed?Identity and Access Management (IAM)
- 142.A large enterprise is migrating its legacy monolithic application to a microservices architecture. The security team is concerned about ensuring secure communication between the numerous new services, which will reside in different containers and potentially across multiple cloud environments. Which security control is MOST suitable for establishing trust and securing inter-service communication in this decoupled environment?Software Development Security
- 143.A security architect is reviewing the design of a new critical financial application. The application will process high-value transactions and is being developed using a complex object-oriented programming language. To ensure the integrity and confidentiality of sensitive data within the application's memory, which secure coding principle is MOST relevant to prevent data exposure through memory management flaws?Software Development Security
- 144.A company is developing a new cloud-native application that will handle sensitive customer data. They want to ensure that the application's runtime environment is constantly monitored for security policy violations and anomalous behavior. Which security control is best suited for this requirement?Software Development Security
- 145.An organization is considering purchasing a new off-the-shelf software solution. The procurement team has identified several vendors, and the security team is tasked with assessing the security posture of their products. Beyond reviewing documentation and audit reports, which of the following actions is MOST critical for the security team to perform to assess the acquired software's security effectively?Software Development Security
- 146.A development team is implementing a new customer relationship management (CRM) system. During the coding phase, a junior developer introduces a vulnerability by using an outdated library with known security flaws. Which of the following security practices would have been most effective in preventing this specific issue?Software Development Security
- 147.A development team is using an Agile methodology for a new application. Security requirements are being defined, but there is concern that these requirements might be overlooked or misinterpreted during the rapid development sprints. Which of the following practices BEST integrates security into the Agile software development life cycle (SDLC) without significantly hindering agility?Software Development Security
- 148.A legacy application is being modernized, and a key requirement is to ensure that critical business logic remains tamper-proof and executes as intended, even in potentially compromised environments. The development team is exploring methods to achieve this high level of assurance. Which of the following software security mechanisms is BEST suited to protect critical code and data integrity within the application's runtime environment?Software Development Security
- 149.A security architect is performing a threat modeling exercise for a new web application. The application will handle sensitive user data and interact with several backend services. Which of the following data flow diagram (DFD) elements primarily represents a potential point where an attacker could intercept or tamper with data?Software Development Security
- 150.A software vendor is evaluating third-party components and libraries for inclusion in their new product. They are concerned about potential intellectual property (IP) infringement and hidden vulnerabilities. Which of the following assessments would be most effective in addressing both of these concerns?Software Development Security