ISC2 CISSP (Certified Information Systems Security Professional) practice questions

244 free questions with answers and explanations.

Practice test
  1. 151.A software development team is employing a technique to automatically discover potential vulnerabilities by feeding malformed or unexpected inputs to an application. This process is being conducted during the testing phase. What is this technique called?Software Development Security
  2. 152.A software development team is adopting a DevOps approach, aiming for continuous integration and continuous deployment (CI/CD). To ensure security is integrated throughout this rapid development cycle, which of the following practices is most crucial for 'shifting left' security?Software Development Security
  3. 153.A critical software application relies on several open-source libraries. A security audit reveals that one of these libraries has a known, high-severity vulnerability (CVE). The development team needs to assess the immediate risk. Which of the following is the most important factor to consider when determining the actual risk to the application?Software Development Security
  4. 154.A software development team is preparing for a new release. During the final testing phase, several critical vulnerabilities are identified in third-party libraries used within the application. The project manager is pushing for an immediate release due to business pressures. Which of the following is the MOST appropriate action for the security team to recommend?Software Development Security
  5. 155.A legacy application is being re-engineered due to high maintenance costs and security vulnerabilities. The development team is considering various strategies to improve security. Which strategy, focused on fundamental changes to the application's architecture and design, represents the most effective long-term approach to mitigating systemic vulnerabilities?Software Development Security
  6. 156.A financial institution is developing a new mobile banking application. The security architect is concerned about potential data leakage from the application's local storage if the device is compromised. Which of the following security controls would best mitigate this risk?Software Development Security
  7. 157.A new web application is being developed to handle sensitive customer data. During the design phase, the security architect emphasizes the importance of preventing Cross-Site Scripting (XSS) attacks. Which of the following is the MOST effective control to implement at the application layer to mitigate reflected and stored XSS vulnerabilities?Software Development Security
  8. 158.A software vendor is evaluating third-party components and libraries for inclusion in their new product. They are concerned about potential intellectual property (IP) infringement and hidden vulnerabilities. Which of the following assessments would be most effective in addressing both of these concerns?Software Development Security
  9. 159.During the maintenance phase of a critical business application, a zero-day vulnerability is discovered in a core library. The vendor releases an emergency patch. What is the most critical security consideration for the operations team when applying this patch?Software Development Security
  10. 160.An organization is developing a new, highly sensitive application. During the design phase, the security architect proposes implementing a Trusted Computing Base (TCB) for critical security functions. What is the primary advantage of designing a TCB for this application?Software Development Security
  11. 161.A development team is implementing a new API for their microservices architecture. To prevent common web application attacks, they are focusing on validating all input received by the API. Which validation strategy is generally considered the most secure and robust?Software Development Security
  12. 162.A security auditor is reviewing an organization's cloud infrastructure. They discover that a critical S3 bucket, intended to store internal backups, is misconfigured, allowing public read access. This misconfiguration directly violates the organization's data classification policy which mandates strict confidentiality for backup data. Which type of audit finding does this primarily represent?Security Assessment and Testing
  13. 163.A financial institution is undergoing an annual security audit. The auditor requests evidence of the organization's policies, procedures, and training records related to data handling and access control. This request primarily focuses on which type of security process data?Security Assessment and Testing
  14. 164.A security assessment reveals that an organization's incident response plan has never been tested in a simulated environment. The plan outlines clear steps for incident detection, analysis, containment, eradication, recovery, and post-incident review. However, without actual testing, the effectiveness of these steps and the team's ability to execute them under pressure are unknown. This represents a gap in which aspect of the security program?Security Assessment and Testing
  15. 165.A security team is considering adopting the Open Source Security Testing Methodology Manual (OSSTMM) for their penetration testing activities. Which of the following is a key characteristic emphasized by OSSTMM that differentiates it from other methodologies?Security Assessment and Testing
  16. 166.An organization relies heavily on a legacy application that processes sensitive customer data. Due to its age and complexity, standard vulnerability scanning tools often produce a high number of false positives or fail to adequately test its unique protocols. Furthermore, modifying the application's code is extremely risky and costly. The security team needs to determine if the application is vulnerable to real-world attacks. Which testing approach would be most appropriate given these constraints?Security Assessment and Testing
  17. 167.A security architect is designing a new cloud-based application and needs to integrate security testing throughout the development lifecycle. They are looking for a strategy that emphasizes testing early and often, automatically, and within the development pipeline. Which approach best describes this strategy?Security Assessment and Testing
  18. 168.A security team is performing a penetration test against a new web application. They manage to gain unauthorized access to an administrative interface by exploiting a known vulnerability in a third-party library. After gaining access, they discover that the application logs user activities but fails to protect the integrity of these logs, allowing an attacker with administrative access to modify or delete them without detection. This secondary finding represents a failure in which security control objective?Security Assessment and Testing
  19. 169.During a security audit, an auditor discovers that critical system patches have not been applied within the mandated 30-day window, despite a clear organizational policy requiring it. The audit finding indicates a deficiency in which area?Security Assessment and Testing
  20. 170.A security team is implementing a continuous monitoring program. They want to ensure that security controls remain effective over time and that any deviations from established baselines are quickly identified. Which of the following security assessment strategies is best suited for this ongoing objective?Security Assessment and Testing
  21. 171.A security manager is evaluating various vulnerability assessment tools. They are particularly interested in a tool that can identify common coding errors, potential buffer overflows, and SQL injection flaws by analyzing the application's source code without executing it. Which type of tool is the manager seeking?Security Assessment and Testing
  22. 172.A security analyst is reviewing a recent penetration test report. The report highlights several vulnerabilities that were successfully exploited, but the client's internal security team was unaware of these weaknesses. The analyst notes that the penetration test was conducted without any prior knowledge provided to the internal security team. Which type of penetration testing methodology was most likely employed?Security Assessment and Testing
  23. 173.A security team is performing a security assessment on a third-party payment gateway integration. The team has been provided with API documentation, network diagrams, and some sample credentials for a test environment. However, they do not have access to the source code. Which type of penetration testing approach does this scenario BEST describe?Security Assessment and Testing
  24. 174.A cloud service provider (CSP) is implementing a new security control to prevent data exfiltration. This control analyzes outgoing network traffic for sensitive information based on predefined patterns and keywords, and blocks or quarantines traffic that violates policy. Which preventative measure is being described?Security Operations
  25. 175.A managed security service provider (MSSP) is onboarding a new client with a complex network infrastructure. To effectively monitor for anomalies and potential threats, the MSSP's first step is to collect network traffic data over a period of time to establish expected behavior patterns. What is this process called?Security Operations
  26. 176.A company's security team is performing a review of their logging infrastructure. They discover that while operating system logs are being collected, application-level logs for their custom-built CRM system are largely disabled by default. The CRM system handles highly sensitive customer data. What is the MOST significant risk introduced by this lack of application-level logging?Security Operations
  27. 177.A security architect is developing an annual security audit plan for a large enterprise. The architect wants to ensure that the audit process provides an independent and objective assessment of the organization's adherence to regulatory requirements and internal policies. Which of the following characteristics is MOST critical for achieving the desired independence and objectivity?Security Assessment and Testing
  28. 178.An organization is developing a comprehensive disaster recovery plan (DRP) for its critical systems. During the planning phase, the team is determining the maximum allowable data loss that an application can sustain without causing significant business damage. Which of the following metrics are they defining?Security Operations
  29. 179.A financial institution is implementing a new security logging and monitoring strategy. They need to ensure that all critical security events from various systems (firewalls, servers, applications) are collected, correlated, and analyzed in real-time to detect sophisticated threats. Which of the following technologies is BEST suited for this purpose?Security Operations
  30. 180.A retail company is planning to implement a new point-of-sale (POS) system across all its stores. Management is concerned about potential vulnerabilities in the new system and wants to ensure that any security flaws are identified and remediated before go-live. Which of the following activities would be MOST effective for proactively identifying security weaknesses in the new POS system's code and configuration?Security Operations
  31. 181.An organization is deploying a new cloud-based customer relationship management (CRM) system. To ensure data privacy and compliance, they are implementing a strategy to encrypt all sensitive customer data both when it is stored and when it is being transmitted between the user's browser and the cloud service. Which of the following foundational security operations concepts does this strategy primarily address?Security Operations
  32. 182.An organization is preparing for a potential large-scale power outage during a severe weather event. They have invested in redundant power generators, uninterruptible power supplies (UPS), and have a warm-site data center in a geographically separate location. The warm-site is configured with hardware and network connectivity, but requires manual data restoration and application configuration. This entire strategy is an example of which recovery strategy?Security Operations
  33. 183.A security team is performing a post-incident review following a data breach. They are examining logs, network captures, and endpoint detection and response (EDR) data to understand the attack's timeline, methods, and impact. Which phase of the incident response process are they currently engaged in?Security Assessment and Testing
  34. 184.A global enterprise has experienced a significant data breach due to a zero-day vulnerability in a widely used operating system. The incident response team successfully contained and eradicated the threat. During the post-incident review, management emphasizes the need to improve the organization's resilience against future, unknown threats. Which of the following strategies would be MOST effective in achieving this long-term goal?Security Operations
  35. 185.A security engineer is tasked with evaluating the effectiveness of security controls in a new cloud-native application. The engineer decides to simulate a real-world attack by attempting to exploit known vulnerabilities and misconfigurations in a production-like environment. Which type of security assessment is the engineer performing?Security Assessment and Testing
  36. 186.A security architect is designing a new physical security system for a data center. The design includes multiple layers: a perimeter fence with CCTV, badge access control at the building entrance, biometric scanners for the server room, and individual rack locks. Which principle of physical security is BEST exemplified by this design?Security Operations
  37. 187.A security auditor is reviewing an organization's change management process. They discover that a critical firewall rule modification was implemented without proper approval from the change advisory board (CAB) and without an associated risk assessment. Which of the following types of audit findings BEST describes this situation?Security Assessment and Testing
  38. 188.A security team is performing a penetration test against a new web application. They discover that the application allows users to upload profile pictures, but it does not properly validate the file type or content, leading to the successful upload and execution of a malicious script. This vulnerability represents a failure in which aspect of the CIA triad?Security Assessment and Testing
  39. 189.A financial institution is implementing a new data retention policy that mandates keeping all transaction logs for a minimum of seven years. This policy is primarily driven by regulatory compliance requirements. Which foundational security operations concept is MOST directly addressed by this requirement?Security Operations
  40. 190.A security analyst is investigating a series of failed login attempts originating from an external IP address. The attempts are targeting a critical internal application. What is the MOST appropriate immediate action to take after verifying the legitimacy of the threat?Security Operations
  41. 191.An organization is implementing a new business continuity plan (BCP). As part of this, they are identifying critical business functions and the resources required to support them. A key activity is to determine the maximum period of time that a business function can be inoperative without causing unacceptable damage to the organization. What is this specific metric called?Security Operations
  42. 192.A security manager is evaluating a new vendor's Software-as-a-Service (SaaS) solution. The vendor provides an attestation report that details the effectiveness of their security controls over a specific period, conducted by an independent third-party auditor. Which type of report is the security manager MOST likely reviewing?Security Assessment and Testing
  43. 193.A global manufacturing company is developing a comprehensive disaster recovery plan (DRP). The leadership team has identified that the critical enterprise resource planning (ERP) system must be restored and fully operational within 24 hours of a disaster. Which metric does this 24-hour timeframe represent?Security Operations
  44. 194.A Chief Information Security Officer (CISO) is presenting to the board about the organization's security posture. They highlight the importance of regularly reviewing access permissions, disabling accounts for terminated employees promptly, and enforcing strong password policies. These measures collectively support which core security principle?Security Operations
  45. 195.An organization is deploying a new cloud-based customer relationship management (CRM) system. As part of its security design, all data at rest within the cloud provider's storage will be encrypted using customer-managed encryption keys (CMEK). All data in transit will be encrypted using TLS 1.3. Which resource protection technique is being implemented for the data at rest?Security Operations
  46. 196.A security team is implementing a new approach to vulnerability management. Instead of relying solely on periodic scans, they are integrating continuous monitoring tools that automatically identify new vulnerabilities as they emerge and correlate them with asset inventories. This allows for near real-time prioritization and remediation. Which aspect of vulnerability management is being MOST significantly enhanced?Security Operations
  47. 197.A security analyst is reviewing logs from a web application firewall (WAF) and notices a high volume of requests originating from a single IP address attempting to access non-existent pages with various SQL injection payloads. The analyst determines this is an active attack and needs to contain it immediately. Which of the following is the MOST appropriate next step according to a typical incident response plan?Security Operations
  48. 198.A security operations center (SOC) analyst observes a sudden and sustained increase in outbound network traffic from an internal server to an unknown external IP address. Further investigation reveals that the server is communicating over an unusual port and the traffic payload appears to be encrypted. Which of the following foundational security operations concepts is primarily being violated?Security Operations
  49. 199.A security team is conducting a vulnerability assessment on a new web application. They are using an automated tool that scans the application's code for known weaknesses and common misconfigurations before it is deployed to production. Which type of assessment is being performed?Security Assessment and Testing
  50. 200.An organization is conducting a security audit of its critical financial systems. The auditor observes that all system administrators have identical, highly privileged access rights, regardless of their specific job functions, and there is no evidence of regular access reviews. This situation MOST directly violates which fundamental security principle?Security Assessment and Testing