Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free ISC2 Certified Information Systems Security Professional CISSP Exam Questions

Page: 1 / 100 Total 1486 questions

Want more questions? Get Premium Access.

Question 1

The PRIMARY characteristic of a Distributed Denial of Service (DDoS) attack is that it

Question 2

Which of the following MUST be part of a contract to support electronic discovery of data stored in a cloud environment?

Question 3

Which of the following is a recommended alternative to an integrated email encryption system?

Correct Answer: C. Encrypt sensitive data separately in attachments
Explanation:

The recommended alternative to an integrated email encryption system is to encrypt sensitive data separately in attachments. An integrated email encryption system is a system or a service that provides or offers the encryption or the protection for the email messages or the email communications, by using or applying the cryptographic techniques or the mechanisms, such as the public key encryption, the symmetric key encryption, or the digital signatures. An integrated email encryption system can protect the confidentiality, the integrity, or the authenticity of the email messages or the email communications, as it can prevent or reduce the risk of unauthorized or inappropriate access, disclosure, modification, or spoofing of the email messages or the email communications by the third parties or the attackers who intercept or capture the email messages or the email communications over the network. However, an integrated email encryption system can also have some limitations or challenges, such as the compatibility, the usability, or the cost. Therefore, the recommended alternative to an integrated email encryption system is to encrypt sensitive data separately in attachments, which means that instead of encrypting the entire email message or the email communication, only the sensitive data or the information that is attached or appended to the email message or the email communication, such as the documents, the files, or the images, are encrypted or protected, using the cryptographic techniques or the mechanisms, such as the password, the passphrase, or the key. Encrypting sensitive data separately in attachments can provide a similar level of security or protection for the email messages or the email communications, as it can prevent or reduce the risk of unauthorized or inappropriate access, disclosure, modification, or spoofing of the sensitive data or the information by the third parties or the attackers who intercept or capture the email messages or the email communications over the network, and it can also overcome or address some of the limitations or challenges of the integrated email encryption system, such as the compatibility, the usability, or the cost.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4, page 116;Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4, page 173


Question 4

Which of the following is the MOST appropriate action when reusing media that contains sensitive data?

Correct Answer: B. Sanitize
Explanation:

The most appropriate action when reusing media that contains sensitive data is to sanitize the media. Sanitization is the process of removing or destroying all data from the media in such a way that it cannot be recovered by any means. Sanitization can be achieved by various methods, such as overwriting, degaussing, or physical destruction. Sanitization ensures that the sensitive data is not exposed or compromised when the media is reused or disposed of. Erase, encrypt, and degauss are not the most appropriate actions when reusing media that contains sensitive data, although they may be related or useful steps. Erase is the process of deleting data from the media by using the operating system or application commands or functions. Erase does not guarantee that the data is completely removed from the media, as it may leave traces or remnants that can be recovered by using special tools or techniques. Encrypt is the process of transforming data into an unreadable form by using a cryptographic algorithm and a key. Encrypt can protect the data from unauthorized access or disclosure, but it does not remove the data from the media. Encrypt also requires that the key is securely managed and stored, and that the encryption algorithm is strong and reliable. Degauss is the process of applying a strong magnetic field to the media to erase or scramble the data. Degauss can effectively sanitize magnetic media, such as hard disks or tapes, but it does not work on optical media, such as CDs or DVDs. Degauss also renders the media unusable, as it destroys the servo tracks and the firmware that are needed for the media to function properly.


Question 5

A company wants to implement two-factor authentication (2FA) to protect their computers from unauthorized users. Which solution provides the MOST secure means of authentication and meets the criteria they have set?

Question 6

Refer to the information below to answer the question.

During the investigation of a security incident, it is determined that an unauthorized individual accessed a system which hosts a database containing financial information.

Aside from the potential records which may have been viewed, which of the following should be the PRIMARY concern regarding the database information?

Correct Answer: A. Unauthorized database changes
Explanation:

The primary concern regarding the database information, aside from the potential records which may have been viewed, is the unauthorized database changes. The unauthorized database changes are the modifications or the alterations of the database information or structure, such as the data values, the data types, the data formats, the data relationships, or the data schemas, by an unauthorized individual or a malicious actor, such as the one who accessed the system hosting the database. The unauthorized database changes can compromise the integrity, the accuracy, the consistency, and the reliability of the database information, and can cause serious damage or harm to the organization's operations, decisions, or reputation. The unauthorized database changes can also affect the availability, the performance, or the functionality of the database, and can create or exploit the vulnerabilities or the weaknesses of the database. Integrity of security logs, availability of the database, and confidentiality of the incident are not the primary concerns regarding the database information, aside from the potential records which may have been viewed, as they are related to the evidence, the accessibility, or the secrecy of the security incident, not the modification or the alteration of the database information.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 7, Security Operations, page 865.Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 7, Security Operations, page 881.


Question 7

Which type of test would an organization perform in order to locate and target exploitable defects?

Correct Answer: A. Penetration
Explanation:

Penetration testing is a type of test that an organization performs in order to locate and target exploitable defects in its information systems and networks. Penetration testing simulates a real-world attack scenario, where a tester, also known as a penetration tester or ethical hacker, tries to find and exploit the vulnerabilities in the system or network, using the same tools and techniques as a malicious attacker. The goal of penetration testing is to identify the weaknesses and gaps in the security posture of the organization, and to provide recommendations and solutions to mitigate or eliminate them. Penetration testing can help the organization improve its security awareness, compliance, and resilience, and prevent potential breaches or incidents.


Question 8

How can a security engineer maintain network separation from a secure environment while allowing remote users to work in the secure environment?

Correct Answer: B. Implement a bastion host
Explanation:

A bastion host is a hardened system that acts as a gateway between a secure environment and an untrusted network, such as the internet. A bastion host can be used to maintain network separation from a secure environment while allowing remote users to work in the secure environment, by providing controlled access and logging services. A bastion host can also implement additional security measures, such as encryption, authentication, and firewalls, to protect the communication and data. Reference: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Communication and Network Security, page 181; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Communication and Network Security, page 255]


Question 9

What is a warn site when conducting Business continuity planning (BCP)

Correct Answer: B. An area partially equipped with equipment and resources to recover business functions
Explanation:

Business continuity planning (BCP) is a process of identifying, analyzing, and preparing for the potential impacts of disruptive events on the organization's critical business functions and processes. BCP involves developing and implementing strategies and plans to ensure the continuity and recovery of the organization's operations in the event of a disaster or disruption. One of the strategies and plans for BCP is to establish an alternate facility, which is a location, other than the normal facility, that can be used to resume the business functions and processes in case the normal facility is unavailable or unusable. There are different types of alternate facilities, depending on the level of readiness and resources they provide. A warm site is an area partially equipped with equipment and resources to recover business functions, but it requires some additional setup and configuration before it can be fully operational. A warm site typically has some hardware, software, network, and backup systems in place, but it may not have the most current data or applications. A warm site can usually become operational within a few hours or days. Therefore, the correct answer is B. The other options are incorrect because they describe different types of alternate facilities. A hot site is an alternate facility that allows for immediate cutover to enable continuation of business functions. A hot site is fully equipped and configured with the most current data and applications, and it can be activated within minutes or seconds. A cold site is a place void of any resources or equipment except air conditioning and raised flooring. A cold site requires a lot of setup and installation before it can be used to recover business functions, and it can take several days or weeks to become operational. A mobile site is a location, other than the normal facility, used to process data on a daily basis. A mobile site is a portable facility that can be moved and deployed quickly to any location, and it usually has limited capacity and functionality.Reference:Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 8: Security Operations, Section: Foundational Security Operations Concepts, Subsection: Business Continuity Planning and Disaster Recovery Planning;CISSP All-in-One Exam Guide, Eighth Edition, Chapter 8: Security Operations, Section: Business Continuity and Disaster Recovery Planning.


Question 10

A new Chief Information Officer (CIO) created a group to write a data retention policy based on applicable laws. Which of the following is the PRIMARY motivation for the policy?

Question 11

Which is the MOST effective countermeasure to prevent electromagnetic emanations on unshielded data cable?

Correct Answer: B. Encase exposed cable runs in metal conduit
Explanation:

Encasing exposed cable runs in metal conduit is the most effective countermeasure to prevent electromagnetic emanations on unshielded data cable. Electromagnetic emanations are the unintentional radiation of electromagnetic signals from electronic devices, such as computers, monitors, or cables. These signals can be intercepted and analyzed by attackers to obtain sensitive information. Unshielded data cable, such as twisted pair or coaxial cable, is more susceptible to electromagnetic emanations than shielded cable, such as fiber optic cable. Encasing unshielded cable in metal conduit can reduce the amount of emanations and provide physical protection from tampering. Reference: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Communication and Network Security, page 164; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Communication and Network Security, page 238]


Question 12

Wireless users are reporting intermittent Internet connectivity. Connectivity is restored when the users disconnect and reconnect, utilizing the web authentication process each time.

The network administrator can see the devices connected to the APs at all times. Which of the following steps will MOST likely determine the cause of the issue?

Correct Answer: A. Verify the session time-out configuration on the captive portal settings
Explanation:

The most likely step to determine the cause of the issue is to verify the session time-out configuration on the captive portal settings. A captive portal is a web page that requires the user to authenticate or accept some terms of service before accessing the Internet through a wireless network. A session time-out is a parameter that defines how long the user can stay connected to the network without re-authenticating or re-accepting the terms of service. If the session time-out is set too low, the user may experience intermittent Internet connectivity, as they will have to disconnect and reconnect frequently, using the web authentication process each time. The network administrator can check the session time-out configuration on the captive portal settings and adjust it accordingly to prevent or reduce the issue. The other options are less likely to determine the cause of the issue, as they either do not relate to the web authentication process, do not explain the intermittent connectivity, or do not match the network administrator's observation.Reference:CISSP - Certified Information Systems Security Professional, Domain 4. Communication and Network Security, 4.1 Implement secure design principles in network architectures, 4.1.3 Secure network components, 4.1.3.1 Wireless access points;CISSP Exam Outline, Domain 4. Communication and Network Security, 4.1 Implement secure design principles in network architectures, 4.1.3 Secure network components, 4.1.3.1 Wireless access points


Question 13

Which one of the following describes granularity?

Question 14

Refer to the information below to answer the question.

A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes.

Following best practice, where should the permitted access for each department and job classification combination be specified?

Correct Answer: B. Security standards
Explanation:

The best place to specify the permitted access for each department and job classification combination is the security standards. Security standards are the documents that define the specific and measurable requirements or rules for the implementation and maintenance of the security policies and procedures. Security standards can help to ensure the consistency and the compliance of the security controls and measures across the organization, and to support the security objectives and principles, such as the least privilege and the separation of duties. Specifying the permitted access for each department and job classification combination in the security standards can help to enforce the role-based access control (RBAC) methodology, which assigns the permissions and privileges to the users or the devices based on their roles or functions in the organization. Security procedures, human resource policy, and human resource standards are not the best places to specify the permitted access for each department and job classification combination, as they are related to the steps or actions for the execution or operation of the security controls or measures, the general and strategic guidelines or objectives for the management or administration of the human resources, or the specific and measurable requirements or rules for the implementation and maintenance of the human resource policy, not the role-based access control methodology.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 1, Security and Risk Management, page 46.Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 1, Security and Risk Management, page 61.


Question 15

A post-implementation review has identified that the Voice Over Internet Protocol (VoIP) system was designed

to have gratuitous Address Resolution Protocol (ARP) disabled.

Why did the network architect likely design the VoIP system with gratuitous ARP disabled?