ISC2 CISSP (Certified Information Systems Security Professional) practice questions
244 free questions with answers and explanations.
- 201.An organization is deploying a new cloud-based customer relationship management (CRM) system. As part of its security design, all data at rest within the cloud provider's storage will be encrypted using customer-managed encryption keys (CMEK). All data in transit will be encrypted using TLS 1.3. Which resource protection technique is being implemented for the data at rest?Security Operations
- 202.A Chief Information Security Officer (CISO) is presenting to the board about the organization's security posture. They highlight the importance of regularly reviewing access permissions, disabling accounts for terminated employees promptly, and enforcing strong password policies. These measures collectively support which core security principle?Security Operations
- 203.A global manufacturing company is developing a comprehensive disaster recovery plan (DRP). The leadership team has identified that the critical enterprise resource planning (ERP) system must be restored and fully operational within 24 hours of a disaster. Which metric does this 24-hour timeframe represent?Security Operations
- 204.A security manager is evaluating a new vendor's Software-as-a-Service (SaaS) solution. The vendor provides an attestation report that details the effectiveness of their security controls over a specific period, conducted by an independent third-party auditor. Which type of report is the security manager MOST likely reviewing?Security Assessment and Testing
- 205.An organization is implementing a new business continuity plan (BCP). As part of this, they are identifying critical business functions and the resources required to support them. A key activity is to determine the maximum period of time that a business function can be inoperative without causing unacceptable damage to the organization. What is this specific metric called?Security Operations
- 206.A security analyst is investigating a series of failed login attempts originating from an external IP address. The attempts are targeting a critical internal application. What is the MOST appropriate immediate action to take after verifying the legitimacy of the threat?Security Operations
- 207.A financial institution is implementing a new data retention policy that mandates keeping all transaction logs for a minimum of seven years. This policy is primarily driven by regulatory compliance requirements. Which foundational security operations concept is MOST directly addressed by this requirement?Security Operations
- 208.A security team is performing a penetration test against a new web application. They discover that the application allows users to upload profile pictures, but it does not properly validate the file type or content, leading to the successful upload and execution of a malicious script. This vulnerability represents a failure in which aspect of the CIA triad?Security Assessment and Testing
- 209.A security auditor is reviewing an organization's change management process. They discover that a critical firewall rule modification was implemented without proper approval from the change advisory board (CAB) and without an associated risk assessment. Which of the following types of audit findings BEST describes this situation?Security Assessment and Testing
- 210.A security architect is designing a new physical security system for a data center. The design includes multiple layers: a perimeter fence with CCTV, badge access control at the building entrance, biometric scanners for the server room, and individual rack locks. Which principle of physical security is BEST exemplified by this design?Security Operations
- 211.A security engineer is tasked with evaluating the effectiveness of security controls in a new cloud-native application. The engineer decides to simulate a real-world attack by attempting to exploit known vulnerabilities and misconfigurations in a production-like environment. Which type of security assessment is the engineer performing?Security Assessment and Testing
- 212.A global enterprise has experienced a significant data breach due to a zero-day vulnerability in a widely used operating system. The incident response team successfully contained and eradicated the threat. During the post-incident review, management emphasizes the need to improve the organization's resilience against future, unknown threats. Which of the following strategies would be MOST effective in achieving this long-term goal?Security Operations
- 213.An organization is evaluating backup solutions for its critical data. They are comparing a solution that backs up data every 24 hours (daily backups) with one that performs continuous data protection (CDP), mirroring changes as they occur. The organization has calculated the maximum tolerable data loss, or Recovery Point Objective (RPO), to be 4 hours. Which backup solution best meets this RPO requirement?Security and Risk Management
- 214.A critical infrastructure organization relies on a Supervisory Control and Data Acquisition (SCADA) system for operational control. A recent security audit highlighted that the system, designed over 20 years ago, uses proprietary protocols that are difficult to patch and has several unaddressed vulnerabilities. Replacing the system is prohibitively expensive and would cause significant operational disruption. Due to these constraints, the organization decides to implement robust network segmentation, intrusion detection systems, and strict access controls around the SCADA network to prevent external threats from reaching it. What is the primary risk management strategy being employed?Security and Risk Management
- 215.A financial institution is implementing a new customer data management system. Due to stringent regulatory requirements regarding data privacy and integrity, the organization needs to ensure that the system's security controls are designed to prevent unauthorized disclosure and modification of customer information throughout its lifecycle. Which security principle is primarily addressed by these concerns?Security and Risk Management
- 216.A multinational corporation is developing a new cloud-based application that will process sensitive customer data across various jurisdictions. To ensure consistent security practices and legal compliance, the Chief Information Security Officer (CISO) mandates the creation of a high-level document that defines the organization's overall security stance and objectives for the application, applicable to all employees and contractors. Which type of document is the CISO mandating?Security and Risk Management
- 217.A global manufacturing company is expanding its operations into a new region. Before establishing local data centers and processing customer data, the legal team identifies that the new region has stringent data protection laws requiring data to be processed and stored within its national borders. Which of the following concepts is the legal team primarily addressing?Security and Risk Management
- 218.A small non-profit organization relies heavily on donor data, which includes sensitive financial and personal information. They have limited IT staff and budget. A recent risk assessment identified that their current data backup solution is vulnerable to ransomware and that their current incident response plan is rudimentary. The board has a very low-risk tolerance for data loss or breach. Given these constraints, which of the following actions represents the MOST pragmatic and effective next step to address this risk?Security and Risk Management
- 219.A critical infrastructure organization relies on a Supervisory Control and Data Acquisition (SCADA) system for managing its operations. To protect the system from unauthorized access and potential cyberattacks, the organization implements network segmentation, intrusion detection systems (IDS), and strong authentication protocols. These measures are examples of what type of security control?Security and Risk Management
- 220.A critical software component for a widely used public-facing application is developed by a third-party vendor. A recent supply chain attack affecting a similar vendor caused a significant outage for another organization. The security team is now tasked with assessing the risk associated with this third-party component. Which of the following is the MOST effective approach to manage this supply chain risk?Security and Risk Management
- 221.A multinational corporation is developing a new cloud-based application that will process personal data of users in various jurisdictions. The legal team is reviewing the General Data Protection Regulation (GDPR) for European users, the California Consumer Privacy Act (CCPA) for California residents, and other relevant privacy laws. They are also considering internal corporate policies that mandate a higher standard of data protection than some local laws. Which aspect of security governance principles is most critical in aligning these diverse requirements into a cohesive framework?Security and Risk Management
- 222.A global e-commerce company is preparing for its annual external audit. The auditors request documentation detailing the formal process by which security controls are selected, implemented, and managed to reduce identified risks to an acceptable level. Which document or concept are the auditors most likely referring to?Security and Risk Management
- 223.A software development company is adopting a DevSecOps approach. As part of this, security testing and vulnerability scanning tools are integrated into the continuous integration/continuous deployment (CI/CD) pipeline. This measure aims to identify and remediate security flaws early in the development lifecycle. Which of the following risk management strategies is primarily being implemented?Security and Risk Management
- 224.A publicly traded company is preparing its annual financial report. An internal audit reveals that the company's financial data systems currently lack robust audit trails for all transactions, making it difficult to definitively prove the origin and authenticity of certain entries. This deficiency primarily impacts which of the following security principles?Security and Risk Management
- 225.A financial services organization is considering outsourcing its customer support operations to a third-party vendor located in a different geographical region. The organization is particularly concerned about the vendor's ability to protect sensitive customer data in accordance with its own stringent internal policies and relevant data protection regulations (e.g., GDPR, CCPA). Which of the following is the MOST critical initial step in managing this supply chain security risk?Security and Risk Management
- 226.A technology company is developing a new mobile application that will handle sensitive user data. Before deployment, the development team conducts a structured analysis to identify potential vulnerabilities and threats from an attacker's perspective, without requiring actual code review. They prioritize these findings based on potential impact and likelihood. Which methodology are they most likely employing?Security and Risk Management
- 227.An airline's critical flight control system experiences a complete outage due to a regional power grid failure. The system's disaster recovery plan specifies that operations must be restored within 24 hours to maintain flight schedules and passenger safety. This 24-hour target represents which of the following?Security and Risk Management
- 228.A financial institution is evaluating its current incident response plan. During a recent simulated attack, it was discovered that the legal department was not involved in the initial stages of incident containment and eradication, leading to potential missteps regarding evidence preservation and regulatory reporting requirements. Which aspect of security governance principles was most clearly overlooked in this scenario?Security and Risk Management
- 229.A multinational corporation is developing a new global privacy policy. The legal team discovers that the data protection laws in one of its operating regions explicitly prohibit the transfer of certain types of personal data outside national borders, even if the destination country has comparable data protection standards. This legal requirement is an example of which of the following?Security and Risk Management
- 230.An organization's security policy states that all employees must complete security awareness training annually. However, a recent audit revealed that only 60% of employees completed the training last year. Furthermore, the training content has not been updated in three years, despite significant changes in the threat landscape. This situation indicates a weakness in which aspect of the security awareness, training, and education (SATE) program?Security and Risk Management
- 231.A small non-profit organization relies heavily on donor data, which includes sensitive financial and personal information. The organization has limited IT staff and budget. They decide to implement basic security controls, such as strong passwords and antivirus software, and also purchase cyber liability insurance to cover potential data breaches. This approach best characterizes which of the following risk management strategies?Security and Risk Management
- 232.A critical infrastructure organization is performing a Business Impact Analysis (BIA) to prioritize its systems for disaster recovery planning. They have determined that the maximum acceptable downtime for their SCADA system is 1 hour, and the maximum acceptable data loss is 15 minutes. Based on these findings, which of the following is the MOST appropriate disaster recovery strategy for the SCADA system?Security and Risk Management
- 233.A managed security service provider (MSSP) is onboarding a new client, a small startup. The client explicitly states that they do not want any user data to be stored outside of their primary cloud region in the European Union, even for backup or disaster recovery purposes, due to strict data residency laws they must adhere to. The MSSP proposes a backup solution that replicates data to a geographically distant data center within the same EU region. What is the primary legal principle guiding the client's requirement?Security and Risk Management
- 234.An organization is conducting a Business Impact Analysis (BIA) as part of its business continuity planning. During this process, they identify that the maximum acceptable downtime for their e-commerce website is 2 hours, as every hour of outage results in significant financial losses and reputational damage. Which key metric is being defined in this scenario?Security and Risk Management
- 235.A healthcare provider is implementing a new electronic health record (EHR) system. The project manager is concerned about ensuring that patient data remains accurate and unaltered throughout its lifecycle, from input by medical staff to archival. Which core security concept is primarily being addressed by this concern?Security and Risk Management
- 236.A software company is preparing to release a new version of its popular accounting software. Before release, the product manager mandates a final review to ensure that all features and functions perform as intended, without any unexpected side effects, and that the software meets its specified security requirements. Which type of testing is this primarily focused on?Security and Risk Management
- 237.A software development company is adopting a DevSecOps approach. As part of this, security teams are integrating automated security tests, code reviews, and vulnerability scanning into the continuous integration/continuous delivery (CI/CD) pipeline. This proactive approach aims to identify and mitigate security flaws early in the software development life cycle. Which risk management strategy is being primarily implemented here?Security and Risk Management
- 238.A large pharmaceutical company is undergoing a major digital transformation, adopting cloud services, IoT devices for manufacturing, and AI for drug discovery. The Chief Information Security Officer (CISO) is tasked with integrating security into these new initiatives while ensuring continuous alignment with the company's strategic business goals and regulatory landscape. Which of the following best represents the CISO's most critical responsibility in this scenario from a security governance perspective?Security and Risk Management
- 239.A global manufacturing company is expanding its operations into a new region. Before establishing local data centers and IT infrastructure, the security team is tasked with understanding the local data protection laws, industry-specific regulations, and international agreements that will apply to their new operations. What is the primary area of security and risk management this activity falls under?Security and Risk Management
- 240.A healthcare organization is conducting a risk assessment for its new patient portal. During the analysis, they identify a potential vulnerability that could allow an attacker to gain unauthorized access to patient records. The likelihood of this vulnerability being exploited is estimated at 0.2 per year, and the potential financial impact of a single successful breach is estimated at $500,000. What is the Annualized Loss Expectancy (ALE) for this specific risk?Security and Risk Management
- 241.A financial institution is implementing a new customer data management system. During the planning phase, the project team identifies that certain customer data, if disclosed, could lead to severe financial penalties and reputational damage. Which of the following security principles is primarily concerned with preventing unauthorized disclosure of this sensitive information?Security and Risk Management
- 242.A healthcare organization is conducting a risk assessment for its new patient portal. During the assessment, they identify that a successful phishing attack could lead to unauthorized access to electronic protected health information (ePHI). The potential financial impact of a data breach is estimated at $1,000,000, and the likelihood of such an attack occurring in a year is estimated at 0.05. What is the Annualized Loss Expectancy (ALE) for this specific risk?Security and Risk Management
- 243.A security team is performing a comprehensive security assessment of a critical web application. They have access to the application's source code, architecture diagrams, and internal documentation, but they are conducting the assessment from an external network perspective without direct access to the internal network infrastructure. What type of testing is being performed?Security Assessment and Testing
- 244.A large enterprise is implementing a new federated identity management system to allow employees to access multiple cloud applications with a single set of credentials. The security architect is evaluating a protocol that enables the secure exchange of authentication and authorization data between an identity provider and a service provider over the internet. Which of the following protocols is best suited for this requirement?Identity and Access Management (IAM)