Sign In
Home/ISC2/CISSP: Certified Information Systems Security Professional/Free questions

CISSP: Certified Information Systems Security Professional — Free Practice Questions

10 free sample questions from a bank of 343, with the correct answers and explanations. No signup required — start practising right now.

1Physical assets defined in an organization's business impact analysis (BIA) could include which of the following?
  • Personal belongings of organizational staff members
  • Disaster recovery (DR) line-item revenues
  • Cloud-based applications
  • Supplies kept off-site a remote facility
Answer: D
2When assessing the audit capability of an application, which of the following activities is MOST important?
  • Identify procedures to investigate suspicious activity.
  • Determine if audit records contain sufficient information.
  • Verify if sufficient storage is allocated for audit records.
  • Review security plan for actions to be taken in the event of audit failure.
Answer: B
3An organization would like to implement an authorization mechanism that would simplify the assignment of various system access permissions for many users with similar job responsibilities. Which type of authorization mechanism would be the BEST choice for the organization to implement?
  • Role-based access control (RBAC)
  • Discretionary access control (DAC)
  • Content-dependent Access Control
  • Rule-based Access Control
Answer: A
4What is the PRIMARY reason for criminal law being difficult to enforce when dealing with cybercrime?
  • Jurisdiction is hard to define.
  • Law enforcement agencies are understaffed.
  • Extradition treaties are rarely enforced.
  • Numerous language barriers exist.
Answer: A
5Wi-Fi Protected Access 2 (WPA2) provides users with a higher level of assurance that their data will remain protected by using which protocol?
  • Extensible Authentication Protocol (EAP)
  • Internet Protocol Security (IPsec)
  • Secure Sockets Layer (SSL)
  • Secure Shell (SSH)
Answer: A
6Which part of an operating system (OS) is responsible for providing security interfaces among the hardware, OS, and other parts of the computing system?
  • Reference monitor
  • Trusted Computing Base (TCB)
  • Time separation
  • Security kernel
Answer: D
7What process facilitates the balance of operational and economic costs of protective measures with gains in mission capability?
  • Performance testing
  • Risk assessment
  • Security audit
  • Risk management
Answer: D
8Clothing retailer employees are provisioned with user accounts that provide access to resources at partner businesses. All partner businesses use common identity and access management (IAM) protocols and differing technologies. Under the Extended Identity principle, what is the process flow between partner businesses to allow this IAM action?
  • Clothing retailer acts as User Self Service, confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services.
  • Clothing retailer acts as identity provider (IdP), confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services.
  • Clothing retailer acts as Service Provider, confirms identity of user using industry standards, then sends credentials to partner businesses that act as an identity provider (IdP) and allows access to resources.
  • Clothing retailer acts as Access Control Provider, confirms access of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to resources.
Answer: B
9Which of the following statements BEST describes least privilege principle in a cloud environment?
  • A single cloud administrator is configured to access core functions.
  • Internet traffic is inspected for all incoming and outgoing packets.
  • Routing configurations are regularly updated with the latest routes.
  • Network segments remain private if unneeded to access the internet.
Answer: D
10An organization has been collecting a large amount of redundant and unusable data and filling up the storage area network (SAN). Management has requested the identification of a solution that will address ongoing storage problems. Which is the BEST technical solution?
  • Compression
  • Caching
  • Replication
  • Deduplication
Answer: D

Want the full bank of 343 questions for CISSP: Certified Information Systems Security Professional? See all practice exams.