CISSP Exam — Questions and Answers
Question 1: Which authentication factor is classified as "something you are"?
- Smart card
- Password
- Biometric data (Correct answer)
- Security token
Correct answer: Biometric data
Biometric data such as fingerprints, facial recognition, or retinal scans represents the "something you are" authentication factor.
Question 2: A security architect needs to ensure that a cloud-hosted application's API traffic is protected from volumetric DDoS attacks. Which solution is MOST appropriate?
- Use a cloud-based DDoS scrubbing service or CDN with DDoS mitigation (Correct answer)
- Deploy an on-premises IPS
- Implement IP reputation blacklists on the application server
- Increase server bandwidth capacity
Correct answer: Use a cloud-based DDoS scrubbing service or CDN with DDoS mitigation
Cloud-based DDoS scrubbing services absorb and filter volumetric attacks upstream, before traffic reaches the application, providing scalable mitigation beyond on-premises capacity.
Question 3: What is the most effective approach to security and risk management in the CISSP field?
- Maintaining the status quo
- Following competitors
- Reactive problem-solving
- Systematic planning and continuous improvement (Correct answer)
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 4: Which framework provides a structured approach to integrating security and privacy into the system development lifecycle using a risk management hierarchy of organization, mission, and system levels?
- OCTAVE Allegro
- NIST SP 800-37 RMF (Correct answer)
- COBIT 5
- ISO/IEC 27005
Correct answer: NIST SP 800-37 RMF
NIST SP 800-37 describes the Risk Management Framework (RMF) with a three-tier hierarchy spanning organization, mission/business process, and information system levels.
Question 5: Which directory protocol is most commonly used for querying and modifying user account information in enterprise environments?
- DIAMETER
- TACACS+
- RADIUS
- LDAP (Correct answer)
Correct answer: LDAP
LDAP (Lightweight Directory Access Protocol) is the standard protocol for reading and writing to directory services like Active Directory.
Question 6: Which metric is most useful for evaluating program effectiveness in CISSP?
- Number of meetings held
- Outcome-based performance indicators (Correct answer)
- Amount of money spent
- Number of staff involved
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 7: What is the purpose of a 'tiger team' in the context of security assessments?
- A team responsible for patch management
- A team that only performs compliance audits
- An incident response team that handles active breaches
- A group of security experts authorized to conduct aggressive, goal-based offensive testing (Correct answer)
Correct answer: A group of security experts authorized to conduct aggressive, goal-based offensive testing
A tiger team is a specialized group authorized to conduct adversarial testing using any means necessary to achieve defined objectives, simulating advanced threat actors.
Question 8: A security assessor finds that an organization rates all vulnerabilities as 'Critical' regardless of actual risk. Which CVSS component is the organization likely ignoring?
- Temporal Score
- Attack Vector
- Base Score
- Environmental Score (Correct answer)
Correct answer: Environmental Score
The Environmental Score adjusts the CVSS base score based on the organization's specific environment, asset criticality, and existing controls, enabling contextualized risk ratings.
Question 9: Which forensic acquisition method produces a bit-for-bit copy of storage media, including deleted files and unallocated space?
- Physical (raw) acquisition (Correct answer)
- File system acquisition
- Sparse acquisition
- Logical acquisition
Correct answer: Physical (raw) acquisition
Physical (raw) acquisition creates a sector-by-sector, bit-for-bit image of the entire storage device, capturing all data including deleted files and unallocated space.
Question 10: Which personnel security control requires that critical roles be filled by two or more employees to prevent knowledge concentration and ensure continuity?
- Cross-training / succession planning (Correct answer)
- Mandatory vacations
- Job rotation
- Background screening
Correct answer: Cross-training / succession planning
Cross-training and succession planning ensure that at least two people can perform each critical function, reducing single points of failure in human resources.
Question 11: What distinguishes a white-box penetration test from a black-box penetration test?
- White-box tests focus on networks; black-box tests focus on applications
- White-box tests are performed externally; black-box tests are performed internally
- White-box testers are given full knowledge of the environment; black-box testers receive no prior information (Correct answer)
- White-box tests use automated tools; black-box tests are fully manual
Correct answer: White-box testers are given full knowledge of the environment; black-box testers receive no prior information
White-box testing provides the tester with full knowledge including source code and architecture, while black-box testing simulates an external attacker with no prior information.
Question 12: Which of the following BEST describes a 'rainbow table' attack?
- Using precomputed hash values to reverse password hashes (Correct answer)
- Intercepting authentication tokens in transit
- Trying every possible password combination
- Injecting malicious scripts into web applications
Correct answer: Using precomputed hash values to reverse password hashes
A rainbow table attack uses precomputed tables of hash values to quickly look up the plaintext corresponding to a stolen password hash.
Question 13: Which Kerberos attack forges a TGT using the compromised KRBTGT account hash, granting the attacker persistent and nearly unlimited domain access?
- Silver ticket attack
- Pass-the-ticket
- Kerberoasting
- Golden ticket attack (Correct answer)
Correct answer: Golden ticket attack
A golden ticket attack uses the KRBTGT password hash to forge valid TGTs for any account, effectively giving the attacker domain-level persistence.
Question 14: Which threat modeling methodology focuses on identifying threats using attacker-centric categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
- PASTA
- DREAD
- STRIDE (Correct answer)
- VAST
Correct answer: STRIDE
STRIDE, developed by Microsoft, categorizes threats into six types and is widely used to systematically identify security threats during design.
Question 15: A security team discovers that backup tapes contain unencrypted PHI and are transported offsite by a courier. Which is the BEST immediate remediation?
- Replace courier with a more reputable company
- Require the courier to sign a BAA
- Store backups onsite only
- Encrypt backup data before writing to tape (Correct answer)
Correct answer: Encrypt backup data before writing to tape
Encrypting data on the tape before transport ensures that even if the tape is lost or stolen in transit, the PHI remains unreadable and the breach reporting obligation may not apply.
Question 16: What is the PRIMARY purpose of a call tree in a BCP?
- To document network topology for recovery teams
- To ensure rapid and structured notification of key personnel (Correct answer)
- To map application dependencies during failover
- To record vendor contact information for procurement
Correct answer: To ensure rapid and structured notification of key personnel
A call tree is a structured communication cascade that ensures key personnel are notified quickly during an incident.
Question 17: During a penetration test, the tester finds an application concatenating user input directly into SQL queries. Which vulnerability class is this?
- Cross-site scripting (XSS)
- SQL injection (Correct answer)
- Buffer overflow
- Path traversal
Correct answer: SQL injection
SQL injection occurs when untrusted input is inserted directly into SQL queries, allowing attackers to manipulate database commands.
Question 18: Which Kerberos component issues Ticket Granting Tickets (TGTs) after authenticating a user's credentials?
- Authentication Agent
- Service Principal
- Key Distribution Center (Correct answer)
- Ticket Granting Server
Correct answer: Key Distribution Center
The Key Distribution Center (KDC) contains the Authentication Server (AS) that validates credentials and issues TGTs used to request service tickets.
Question 19: Which type of law imposes obligations on organizations to protect personal data and can result in civil penalties paid to affected individuals?
- Contract law
- Tort law (civil law) (Correct answer)
- Criminal law
- Administrative law
Correct answer: Tort law (civil law)
Tort law allows individuals harmed by negligent data handling to sue for damages, making it a key driver of privacy obligations for organizations.
Question 20: The Gramm-Leach-Bliley Act (GLBA) primarily requires which type of organization to protect customer financial information?
- Federal government agencies
- Financial institutions (Correct answer)
- Educational institutions
- Healthcare providers
Correct answer: Financial institutions
GLBA mandates that banks, insurance companies, and other financial institutions implement safeguards to protect the privacy of consumer financial information.
Question 21: Which OAuth 2.0 grant type is most appropriate for a server-side web application that can securely store a client secret?
- Device Authorization Grant
- Implicit Grant
- Client Credentials Grant
- Authorization Code Grant (Correct answer)
Correct answer: Authorization Code Grant
The Authorization Code Grant is the most secure OAuth 2.0 flow for server-side apps because it exchanges a short-lived code for tokens without exposing them in the browser.
Question 22: When an organization uses an external IdP to authenticate users and the application trusts that IdP's assertions, what is the application called?
- Service Provider (Correct answer)
- Identity Broker
- Resource Server
- Identity Provider
Correct answer: Service Provider
In federated identity, the Service Provider (SP) relies on the Identity Provider (IdP) to authenticate users and accepts the IdP's identity assertions.
Question 23: Which governance framework uses a RACI matrix and focuses on aligning IT processes with business goals using 37 IT processes across five domains?
- COBIT 2019 (Correct answer)
- ITIL v4
- ISO/IEC 27001
- NIST CSF
Correct answer: COBIT 2019
COBIT (Control Objectives for Information and Related Technologies) provides a governance framework with process models and uses RACI charts to define accountability.
Question 24: A user is authenticated but the system checks additional attributes — department, project membership, and data sensitivity level — before granting access to a document. Which model is being applied?
- Attribute-based access control (Correct answer)
- Role-based access control
- Discretionary access control
- Mandatory access control
Correct answer: Attribute-based access control
ABAC evaluates multiple attributes of the subject, resource, and environment simultaneously to make fine-grained access decisions beyond simple role membership.
Question 25: A Recovery Time Objective (RTO) differs from a Recovery Point Objective (RPO) in that RTO defines:
- The point in time to which systems must be recovered
- The cost threshold for activating disaster recovery
- The maximum acceptable data loss measured in time
- The maximum tolerable downtime before a system must be restored (Correct answer)
Correct answer: The maximum tolerable downtime before a system must be restored
RTO specifies the maximum acceptable length of time a system can be offline, while RPO defines the maximum acceptable amount of data loss.
Question 26: Which security model defines a formal state machine and requires that the system always transitions to a secure state?
- Information Flow model
- State machine model (Correct answer)
- Noninterference model
- Take-Grant model
Correct answer: State machine model
The State Machine model defines all allowable system states and ensures every transition moves the system from one secure state to another.
Question 27: Which of the following best describes a Reference Monitor?
- A hardware module that encrypts memory
- A software agent that monitors user behavior
- An abstract machine that mediates all access between subjects and objects (Correct answer)
- A firewall rule set enforcing network policy
Correct answer: An abstract machine that mediates all access between subjects and objects
A Reference Monitor is an abstract machine concept that intercepts every access attempt between subjects and objects to enforce policy.
Question 28: Which risk analysis approach assigns probability and impact using descriptive scales, is faster to perform, and is well-suited when hard data is unavailable?
- Quantitative analysis
- Qualitative analysis (Correct answer)
- Annualized loss expectancy calculation
- Monte Carlo simulation
Correct answer: Qualitative analysis
Qualitative analysis uses descriptive ratings (e.g., High/Medium/Low) based on expert opinion, making it faster but more subjective than quantitative methods.
Question 29: Which protocol extends RADIUS capabilities to support mobile and distributed network authentication with better reliability and security?
- Kerberos
- TACACS+
- DIAMETER (Correct answer)
- LDAP
Correct answer: DIAMETER
DIAMETER is the successor to RADIUS, offering improved reliability (TCP/SCTP), better error handling, and enhanced security features for AAA services.
Question 30: To authenticate the company's public users, your CIO wishes to employ Lightweight Directory Access Protocol (LDAP). The following should be your initial consideration:
- Whether the Domain Component (DC) is included in the entry
- Whether the software can support LDAP using a hierarchical tree structure
- Whether the considered version of LDAP has sufficient support for transport layer security (Correct answer)
- Whether the LDAP entry includes the appropriate Common Name (CN)
Correct answer: Whether the considered version of LDAP has sufficient support for transport layer security
When using LDAP for authenticating public users, the primary concern should be the security of the credentials and data transmitted. LDAP itself is not inherently secure, so ensuring that the version considered has sufficient support for Transport Layer Security (TLS) or Secure Sockets Layer (SSL) is critical. This encryption protects the authentication process from eavesdropping and man-in-the-middle attacks, safeguarding user information.
Question 31: In CISSP practice, what is the primary purpose of strategic planning?
- To create paperwork
- To satisfy external auditors
- To align resources with goals and anticipate challenges (Correct answer)
- To reduce workforce
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 32: In PKI, what is the purpose of a Certificate Revocation List (CRL)?
- To enumerate certificates that have been invalidated before their expiry (Correct answer)
- To list certificates that will expire soon
- To publish certificates awaiting validation
- To store private keys of revoked users
Correct answer: To enumerate certificates that have been invalidated before their expiry
A CRL is a signed list published by the CA that identifies certificates that have been revoked and should no longer be trusted.
Question 33: What is the primary consideration when implementing changes to security architecture?
- Personal convenience
- Vendor preference
- Speed of implementation
- Impact assessment and change management (Correct answer)
Correct answer: Impact assessment and change management
Impact assessment and proper change management ensure that modifications do not introduce unexpected problems or service disruptions.
Question 34: Which control helps prevent sensitive data from leaving an organization via email or USB drives?
- Data Loss Prevention (DLP) (Correct answer)
- Security Information and Event Management (SIEM)
- Intrusion Detection System (IDS)
- Web Application Firewall (WAF)
Correct answer: Data Loss Prevention (DLP)
Data Loss Prevention (DLP) solutions monitor and block the unauthorized transmission of sensitive data across various egress channels including email, USB, and cloud uploads.
Question 35: What is the recommended approach when managing conflicting priorities in CISSP?
- Address them in alphabetical order
- Ignore lower-priority items
- Prioritize based on impact and urgency (Correct answer)
- Delegate all decisions upward
Correct answer: Prioritize based on impact and urgency
Prioritizing based on impact and urgency ensures the most critical issues receive attention first while maintaining progress on other goals.
Question 36: Which sanitization method is appropriate for reusing a hard drive within the SAME security domain?
- Purging (overwriting) (Correct answer)
- Degaussing
- Physical destruction
- Declassification
Correct answer: Purging (overwriting)
Purging (overwriting with multiple passes) is sufficient for media being reused within the same security domain where the classification level remains constant.
Question 37: A data center is located in a flood-prone area. Which site design choice BEST mitigates flood risk?
- Elevate critical equipment above the base flood elevation (Correct answer)
- Install sump pumps in the server room
- Use water-resistant server racks
- Deploy flood sensors and alarms
Correct answer: Elevate critical equipment above the base flood elevation
Elevating critical equipment above the base flood elevation prevents water from reaching hardware even if flooding occurs.
Question 38: Under which data classification level would government information whose unauthorized disclosure could cause serious damage to national security be placed?
- Secret (Correct answer)
- Confidential
- Top Secret
- Sensitive But Unclassified
Correct answer: Secret
The Secret classification applies to information whose unauthorized disclosure could cause serious damage to national security, while Top Secret applies when damage would be exceptionally grave.
Question 39: Which concept describes the practice of re-scanning or retesting systems after remediation to confirm vulnerabilities have been successfully addressed?
- Threat modeling
- Baseline scanning
- Continuous monitoring
- Verification testing (Correct answer)
Correct answer: Verification testing
Verification testing (also called remediation verification) confirms that patching or configuration changes have successfully closed the identified vulnerabilities.
Question 40: What is the MAIN security purpose of implementing Private VLANs (PVLANs)?
- Prevent VLAN hopping attacks via trunk ports
- Encrypt traffic between VLAN members
- Extend VLANs across WAN links
- Isolate hosts within the same VLAN from communicating directly with each other (Correct answer)
Correct answer: Isolate hosts within the same VLAN from communicating directly with each other
PVLANs use isolated, community, and promiscuous port types to restrict lateral communication between hosts sharing the same IP subnet.
Question 41: Which access provisioning approach reduces risk by granting users only the minimum permissions required for their specific job responsibilities?
- Least privilege (Correct answer)
- Separation of duties
- Need-to-know
- Zero trust
Correct answer: Least privilege
The principle of least privilege restricts user access rights to only what is necessary to perform their job, reducing the attack surface if the account is compromised.
Question 42: During a fire evacuation, which principle should override the normal physical security access controls?
- Mandatory access control
- Life safety takes precedence over asset protection (Correct answer)
- Defense in depth
- Least privilege
Correct answer: Life safety takes precedence over asset protection
Life safety is the highest priority; security controls must not impede safe evacuation even if they temporarily reduce physical security.
Question 43: Which physical security control uses two interlocking doors where the first must close before the second opens, preventing tailgating?
- Motion sensor
- Bollard
- Turnstile
- Mantrap (airlock) (Correct answer)
Correct answer: Mantrap (airlock)
A mantrap is a small room with two controlled doors that requires authentication and ensures only one person enters at a time, preventing tailgating.
Question 44: In CISSP practice, what is the primary purpose of strategic planning?
- To satisfy external auditors
- To align resources with goals and anticipate challenges (Correct answer)
- To create paperwork
- To reduce workforce
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 45: In CISSP certification, what does redundancy in system design primarily provide?
- Increased complexity
- Lower initial cost
- Fault tolerance and high availability (Correct answer)
- Simplified maintenance
Correct answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
Question 46: What cloud data security technique ensures that even if the provider is compromised, customer data remains unreadable?
- Client-side encryption with customer-managed keys (Correct answer)
- Access control lists
- Data masking
- TLS in transit
Correct answer: Client-side encryption with customer-managed keys
Encrypting data client-side before upload with customer-managed keys means the provider never possesses the decryption key.
Question 47: Which term describes the remaining risk after safeguards and controls have been applied?
- Residual risk (Correct answer)
- Inherent risk
- Total risk
- Control risk
Correct answer: Residual risk
Residual risk is the leftover risk exposure after all planned countermeasures have been implemented and accepted by management.
Question 48: What is the primary goal of the Gramm-Leach-Bliley Act (GLBA) in the context of information security?
- To mandate breach notification for all US businesses
- To establish cybersecurity standards for critical infrastructure
- To regulate healthcare data privacy
- To protect the personal financial information of consumers held by financial institutions (Correct answer)
Correct answer: To protect the personal financial information of consumers held by financial institutions
GLBA requires financial institutions to explain how they share and protect customers' private financial information.
Question 49: A company discovers that a former employee's Active Directory account was disabled but their VPN certificate was never revoked. Which process failed?
- User provisioning
- Role mining
- Account de-provisioning / offboarding (Correct answer)
- Access recertification
Correct answer: Account de-provisioning / offboarding
Incomplete de-provisioning — failing to revoke all credentials including certificates — leaves residual access vectors open after an employee departs.
Question 50: Which privacy principle requires that personal data collected for one specified purpose should not be used for a different, incompatible purpose?
- Purpose limitation (Correct answer)
- Data minimization
- Storage limitation
- Accuracy
Correct answer: Purpose limitation
Purpose limitation, a core GDPR principle, restricts use of personal data to the original stated purpose unless new consent is obtained.
Question 51: What is defense in depth in the context of CISSP security?
- Relying solely on encryption
- Using one strong security control
- Focusing only on perimeter security
- Implementing multiple layers of security controls (Correct answer)
Correct answer: Implementing multiple layers of security controls
Defense in depth uses multiple layers of security controls so that if one layer fails, additional layers continue to provide protection.
Question 52: What is the MAIN difference between a stateful packet inspection (SPI) firewall and a stateless packet filter?
- SPI firewalls operate faster than packet filters
- SPI firewalls track connection state and context; packet filters evaluate each packet in isolation (Correct answer)
- SPI firewalls only inspect inbound traffic
- Packet filters can block application-layer attacks; SPI cannot
Correct answer: SPI firewalls track connection state and context; packet filters evaluate each packet in isolation
Stateful inspection firewalls maintain a connection state table to evaluate packets in the context of their TCP/UDP session, while packet filters assess each packet independently.
Question 53: In a service-oriented architecture (SOA), which component is primarily responsible for routing messages between services and enforcing security policies?
- Enterprise Service Bus (ESB)
- Service registry
- Load balancer
- API gateway (Correct answer)
Correct answer: API gateway
An API gateway enforces authentication, authorization, rate limiting, and other security policies for services in an SOA or microservices environment.
Question 54: What is the fundamental principle behind communication and network security in the CISSP domain?
- Balancing performance, reliability, and efficiency (Correct answer)
- Cost minimization at all costs
- Following a single vendor solution
- Using the newest technology exclusively
Correct answer: Balancing performance, reliability, and efficiency
Effective technical design requires balancing performance requirements with reliability needs and operational efficiency.
Question 55: Which type of security policy provides the highest-level direction and is signed by executive leadership to express management commitment to security?
- Baseline policy
- Standard
- Procedure
- Organizational (master) security policy (Correct answer)
Correct answer: Organizational (master) security policy
The organizational or master security policy is the top-level document that expresses executive commitment and sets the strategic direction for the entire security program.
Question 56: Which type of token used in OAuth 2.0 / OIDC contains encoded claims about the user and can be validated without contacting the authorization server?
- Refresh token
- SAML assertion
- Opaque token
- JSON Web Token (JWT) (Correct answer)
Correct answer: JSON Web Token (JWT)
JWTs are self-contained tokens that embed claims as a signed JSON payload, allowing resource servers to validate them locally without a round-trip to the authorization server.
Question 57: What is the primary purpose of encryption in CISSP security?
- To compress data
- To make data transfer slower
- To protect data confidentiality during storage and transmission (Correct answer)
- To organize data more efficiently
Correct answer: To protect data confidentiality during storage and transmission
Encryption protects data confidentiality by converting information into an unreadable format that can only be decoded with the proper key.
Question 58: What is the primary purpose of a Web Application Firewall (WAF) in a software security architecture?
- Managing user authentication tokens
- Scanning source code for vulnerabilities
- Filtering malicious HTTP traffic before it reaches the application (Correct answer)
- Encrypting data at rest
Correct answer: Filtering malicious HTTP traffic before it reaches the application
A WAF inspects and filters HTTP/HTTPS requests to block common web attacks like SQLi and XSS before they reach the application.
Question 59: An organization uses 802.1X for wired network access control. Which component authenticates the end-user credentials?
- Certificate Authority
- Authenticator
- Authentication Server (RADIUS) (Correct answer)
- Supplicant
Correct answer: Authentication Server (RADIUS)
In 802.1X, the Authentication Server (typically RADIUS) validates supplicant credentials; the authenticator (switch) enforces the decision.
Question 60: During a penetration test, a tester discovers a critical vulnerability but the engagement scope explicitly excludes the affected system. What should the tester do?
- Ignore it since it is out of scope
- Exploit the vulnerability to demonstrate impact
- Expand the scope unilaterally to include the system
- Immediately report the finding to the client and halt testing on that system (Correct answer)
Correct answer: Immediately report the finding to the client and halt testing on that system
The tester must report out-of-scope findings to the client immediately without exploiting them, as the rules of engagement govern what systems can be tested.
Question 61: Which framework provides a standardized vocabulary for describing hardware and software asset information to support vulnerability management?
- Common Platform Enumeration (CPE) (Correct answer)
- NIST RMF
- ISO 27001
- COBIT
Correct answer: Common Platform Enumeration (CPE)
Common Platform Enumeration (CPE) is a structured naming scheme for IT systems, software, and packages that enables consistent identification of assets in vulnerability databases like NVD.
Question 62: Which of the following attacks targets the hypervisor in a virtualized environment?
- VM sprawl
- Hyperjacking (Correct answer)
- Container escape
- Side-channel attack
Correct answer: Hyperjacking
Hyperjacking involves compromising or replacing the hypervisor to gain control over all guest virtual machines.
Question 63: What is the key difference between a security audit and a security assessment?
- Audits are more expensive than assessments
- Audits measure compliance against defined standards; assessments evaluate overall security posture and risk (Correct answer)
- Assessments only cover technical controls; audits only cover people and process
- Audits are performed by internal teams; assessments are always external
Correct answer: Audits measure compliance against defined standards; assessments evaluate overall security posture and risk
Security audits verify adherence to specific standards or policies, while assessments take a broader view to identify risks, gaps, and improvement opportunities.
Question 64: Which of the following BEST describes the concept of 'scoping' in security baseline selection?
- Reducing the number of controls applied based on the specific environment and mission (Correct answer)
- Expanding controls to cover additional assets beyond minimum requirements
- Defining the boundary of the information system
- Selecting which regulatory framework applies to the organization
Correct answer: Reducing the number of controls applied based on the specific environment and mission
Scoping allows organizations to eliminate controls that are not applicable to their specific environment, technology, or operational requirements while maintaining the intent of the baseline.
Question 65: Which security operations principle requires that no single individual can complete a sensitive transaction without the involvement of at least one other person?
- Job rotation
- Least privilege
- Separation of duties (Correct answer)
- Need to know
Correct answer: Separation of duties
Separation of duties splits critical tasks among multiple people so that no one person can commit fraud or error without detection.
Question 66: What is the PRIMARY purpose of a network tap versus a SPAN port for security monitoring?
- SPAN ports capture more traffic than taps
- Taps require no additional hardware
- Taps provide passive, out-of-band full-duplex capture without affecting production traffic (Correct answer)
- Taps encrypt captured traffic; SPAN ports do not
Correct answer: Taps provide passive, out-of-band full-duplex capture without affecting production traffic
Network taps passively copy all traffic on a link out-of-band without introducing latency or risking dropped packets, unlike SPAN ports which share switch resources.
Question 67: In the context of security assessments, what does 'pivoting' refer to during a penetration test?
- Changing the test methodology mid-engagement
- Switching from automated to manual testing
- Using a compromised system as a launching point to attack other internal systems (Correct answer)
- Rotating through different vulnerability categories
Correct answer: Using a compromised system as a launching point to attack other internal systems
Pivoting uses an already-compromised host as an intermediary to reach and attack systems in network segments that would otherwise be inaccessible.
Question 68: What is the BEST practice for securing a wiring closet in a commercial office building?
- Install a UPS inside the closet
- Use color-coded cable management trays
- Lock the closet and restrict access to authorized IT personnel only (Correct answer)
- Label all cables clearly for easy identification
Correct answer: Lock the closet and restrict access to authorized IT personnel only
Wiring closets contain network and telephony infrastructure; physical access must be restricted to prevent tampering or wiretapping.
Question 69: An organization stores customer credit card data. Under PCI DSS, what is the MINIMUM protection required for stored Primary Account Numbers (PAN)?
- Any of: truncation, tokenization, hashing, or encryption (Correct answer)
- Encryption with AES-256
- Truncation to the last four digits only
- Hashing or tokenization
Correct answer: Any of: truncation, tokenization, hashing, or encryption
PCI DSS allows PANs to be rendered unreadable via truncation, tokenization, one-way hashing, or strong encryption — organizations may choose any of these approved methods.
Question 70: Which US federal law specifically requires federal agencies to protect information systems and mandates FISMA compliance?
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- HIPAA
- GLBA
- Sarbanes-Oxley Act
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA requires federal agencies to develop, document, and implement agency-wide programs to provide information security for their systems.
Question 71: Which federation standard allows identity assertions to be passed between domains using XML-based tokens?
- OAuth 2.0
- OpenID Connect
- SAML 2.0 (Correct answer)
- Kerberos
Correct answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) uses XML-based assertions to communicate identity information between identity providers and service providers across domains.
Question 72: Which security architecture concept requires every access request to be fully validated, regardless of the requester's previous authentication status?
- Complete mediation (Correct answer)
- Least privilege
- Psychological acceptability
- Separation of privilege
Correct answer: Complete mediation
Complete mediation requires every access to every object to be checked against access control policy, with no caching of permissions.
Question 73: Which of the following BEST describes a reciprocal agreement in business continuity planning?
- An insurance policy covering business interruption losses
- A contract with a vendor to provide hot-site facilities
- An arrangement between two organizations to host each other's operations during a disaster (Correct answer)
- A government mandate requiring critical infrastructure backup
Correct answer: An arrangement between two organizations to host each other's operations during a disaster
A reciprocal agreement is a mutual arrangement where two organizations agree to provide backup processing space for each other in case of disaster.
Question 74: An organization wants to prevent a single administrator from having both the ability to create accounts and approve their own access requests. Which principle addresses this?
- Need to know
- Defense in depth
- Least privilege
- Segregation of duties (Correct answer)
Correct answer: Segregation of duties
Segregation of duties (SoD) divides critical tasks between multiple people to prevent fraud and error by ensuring no single person controls an entire process.
Question 75: Configuration management is most likely handled during which phase (s) of the asset lifecycle?
- Secure (Correct answer)
- Monitor, Recover
- Secure, Monitor
- Identify and classify, Secure
Correct answer: Secure
Configuration management is the systematic process of managing changes to a system's configuration to maintain its integrity, security, and performance. While it impacts all phases, it is most critically handled during the 'Secure' phase of the asset lifecycle. This is where controls are implemented, maintained, and updated to protect the asset from unauthorized access, use, disclosure, disruption, modification, or destruction, ensuring its ongoing security posture.
Question 76: Which authentication method requires the user to prove identity using something they have (token) and something they know (PIN), but NOT a biometric factor?
- Risk-based authentication
- Multi-factor biometric
- Three-factor authentication
- Two-factor authentication (Correct answer)
Correct answer: Two-factor authentication
Two-factor authentication (2FA) combines exactly two distinct authentication factors; a hardware token plus a PIN uses 'something you have' and 'something you know'.
Question 77: Which XML-specific vulnerability allows an attacker to read arbitrary files on the server by referencing external entities in a crafted XML document?
- XPATH Injection
- JSON Hijacking
- SOAP Action Spoofing
- XML External Entity (XXE) Injection (Correct answer)
Correct answer: XML External Entity (XXE) Injection
XXE injection exploits misconfigured XML parsers that process external entity references, enabling attackers to read local files or perform SSRF attacks.
Question 78: Which vulnerability scanning technique sends crafted packets and analyzes responses to determine open ports and services without authenticating to the target?
- Credentialed scanning
- Agent-based scanning
- Passive scanning
- Active scanning (Correct answer)
Correct answer: Active scanning
Active scanning sends probes to targets and analyzes responses to discover open ports, services, and potential vulnerabilities without requiring credentials.
Question 79: Which network security concept ensures that all traffic, including internal east-west traffic, is inspected and no implicit trust is granted based on network location?
- Network Access Control (NAC)
- Defense in depth
- Microsegmentation
- Zero Trust Network Access (ZTNA) (Correct answer)
Correct answer: Zero Trust Network Access (ZTNA)
Zero Trust Network Access operates on the principle of 'never trust, always verify,' requiring authentication and authorization for all traffic regardless of source location.
Question 80: In OAuth 2.0, which grant type is considered MOST risky because it exposes access tokens in the browser URL fragment?
- Client credentials
- Authorization code
- Implicit (Correct answer)
- Device authorization
Correct answer: Implicit
The implicit grant type returns tokens directly in the URL fragment, making them visible in browser history and logs, and is now deprecated in OAuth 2.1.
Question 81: Which technique involves inserting instrumentation into a running application to detect attacks in real time without modifying the source code?
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Interactive Application Security Testing (IAST)
- Runtime Application Self-Protection (RASP) (Correct answer)
Correct answer: Runtime Application Self-Protection (RASP)
RASP embeds security controls directly into an application's runtime environment, detecting and blocking attacks as the application executes.
Question 82: What is the key benefit of evidence-based decision making in CISSP management?
- It reduces reliance on data
- It speeds up all processes
- It improves accuracy and reduces bias in decisions (Correct answer)
- It eliminates all risk
Correct answer: It improves accuracy and reduces bias in decisions
Evidence-based decision making uses data and research to improve the accuracy of decisions and reduce the influence of personal bias.
Question 83: In CISSP certification, what does redundancy in system design primarily provide?
- Fault tolerance and high availability (Correct answer)
- Simplified maintenance
- Increased complexity
- Lower initial cost
Correct answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
Question 84: In a zero trust architecture, what is the role of the Policy Decision Point (PDP)?
- Evaluates access requests against policy and grants or denies access (Correct answer)
- Encrypts data in transit between endpoints
- Monitors network traffic for anomalies
- Stores and manages cryptographic keys
Correct answer: Evaluates access requests against policy and grants or denies access
The PDP evaluates access requests using identity, context, and policy to make authorization decisions in a zero trust model.
Question 85: The Clark-Wilson integrity model primarily addresses which type of environment?
- Commercial transaction integrity (Correct answer)
- Military multilevel security
- Physical access control
- Network perimeter defense
Correct answer: Commercial transaction integrity
Clark-Wilson was designed for commercial environments, ensuring data integrity through well-formed transactions and separation of duties.
Question 86: Which authentication factor is classified as "something you are"?
- Biometric data (Correct answer)
- Password
- Smart card
- Security token
Correct answer: Biometric data
Biometric data such as fingerprints, facial recognition, or retinal scans represents the "something you are" authentication factor.
Question 87: Which concept describes the combination of policies, procedures, standards, and guidelines that collectively define how security is managed across an organization?
- Defense in depth
- Security posture
- Security governance framework (Correct answer)
- Security architecture
Correct answer: Security governance framework
A security governance framework integrates all security management elements—policies, processes, roles, and metrics—to ensure consistent, accountable security decision-making.
Question 88: What is the primary purpose of a security architecture review board?
- To approve individual user access requests
- To perform penetration testing on production systems
- To respond to security incidents and coordinate remediation
- To ensure new systems and changes align with the enterprise security architecture (Correct answer)
Correct answer: To ensure new systems and changes align with the enterprise security architecture
A security architecture review board evaluates proposed systems and changes against established architectural standards before implementation.
Question 89: Which attack surface analysis technique involves systematically identifying all entry points where untrusted data enters a system?
- Red teaming
- Penetration testing
- Vulnerability scanning
- Attack surface mapping / threat surface analysis (Correct answer)
Correct answer: Attack surface mapping / threat surface analysis
Attack surface mapping catalogs all points where an adversary could interact with a system, enabling prioritized hardening of the most exposed areas.
Question 90: Which routing protocol security feature prevents unauthorized routers from injecting false routing information into an OSPF domain?
- Route filtering with ACLs
- Spanning Tree Protocol BPDU Guard
- OSPF MD5 or SHA authentication (Correct answer)
- BGP route reflectors
Correct answer: OSPF MD5 or SHA authentication
OSPF neighbor authentication (MD5 or SHA) requires routers to prove identity before exchanging routing updates, preventing rogue router injection.
Question 91: Which security architecture principle ensures that a compromised component cannot be used to gain unauthorized access to other components?
- Defense in depth
- Fail-safe defaults
- Least privilege
- Isolation and containment (Correct answer)
Correct answer: Isolation and containment
Isolation and containment limits the blast radius of a compromise by preventing lateral movement between components.
Question 92: Which documentation is essential when working with security architecture in CISSP?
- Detailed technical specifications and as-built diagrams (Correct answer)
- Only verbal notes
- Marketing materials
- General descriptions without specifics
Correct answer: Detailed technical specifications and as-built diagrams
Detailed technical specifications and as-built diagrams provide the accurate reference information needed for maintenance and troubleshooting.
Question 93: Under GDPR, what is the maximum timeframe to notify supervisory authorities of a personal data breach?
- 7 days
- 72 hours (Correct answer)
- 48 hours
- 24 hours
Correct answer: 72 hours
GDPR Article 33 requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 94: Which element should be reviewed and updated FIRST when a significant organizational change occurs, such as a merger or new product launch?
- Insurance policies
- Disaster recovery runbooks
- Call tree contact lists
- Business Impact Analysis (BIA) (Correct answer)
Correct answer: Business Impact Analysis (BIA)
A new or changed business function requires an updated BIA to re-evaluate criticality, MTD, RTO, and RPO for the changed organization.
Question 95: An organization wants to prevent employees from exfiltrating data via encrypted DNS tunnels. Which control is MOST effective?
- Implement DNS over HTTPS for all clients
- Require all DNS queries to use DNSSEC
- Deploy a recursive DNS resolver with anomaly detection for high-volume or large TXT record queries (Correct answer)
- Block all UDP port 53 at the perimeter
Correct answer: Deploy a recursive DNS resolver with anomaly detection for high-volume or large TXT record queries
DNS tunneling detection relies on behavioral analysis—unusually high query volumes, large TXT records, and long subdomains—which a monitored internal resolver can identify.
Question 96: Which document formally authorizes a penetration test and protects the tester from legal liability?
- Authorization to Test / Permission to Attack letter (Correct answer)
- Statement of Work
- Rules of Engagement
- Non-Disclosure Agreement
Correct answer: Authorization to Test / Permission to Attack letter
An Authorization to Test letter (also called Permission to Attack) is signed by an authorized representative and explicitly grants legal permission to conduct the penetration test.
Question 97: A covert channel in a secure system is best described as:
- A backdoor installed by a malicious developer
- An encrypted tunnel used to bypass firewall rules
- An out-of-band management interface for administrators
- A communication path that was not intended for information transfer but can leak data (Correct answer)
Correct answer: A communication path that was not intended for information transfer but can leak data
Covert channels exploit unintended communication paths — such as timing or storage — to exfiltrate information in violation of security policy.
Question 98: What is the primary purpose of encryption in CISSP security?
- To make data transfer slower
- To protect data confidentiality during storage and transmission (Correct answer)
- To organize data more efficiently
- To compress data
Correct answer: To protect data confidentiality during storage and transmission
Encryption protects data confidentiality by converting information into an unreadable format that can only be decoded with the proper key.
Question 99: Which protocol vulnerability does the POODLE attack exploit?
- TLS 1.2 HMAC truncation
- SSL 3.0 CBC padding oracle (Correct answer)
- RC4 statistical bias in WEP
- MD5 collision in TLS certificates
Correct answer: SSL 3.0 CBC padding oracle
POODLE (Padding Oracle On Downgraded Legacy Encryption) exploits a padding oracle vulnerability in SSL 3.0's CBC mode encryption.
Question 100: Which risk treatment option involves sharing risk with a third party, such as through insurance or outsourcing?
- Risk mitigation
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as purchasing cyber liability insurance.
Question 101: Which network architecture principle is BEST demonstrated by placing database servers in a separate VLAN accessible only from the application tier?
- Network segmentation (Correct answer)
- Least privilege
- Zero trust
- Defense in depth
Correct answer: Network segmentation
Placing database servers in an isolated VLAN with restricted inter-tier access is a direct application of network segmentation.
Question 102: What is 'locard's exchange principle' and how does it apply to digital forensics?
- Digital evidence must be encrypted before transfer
- Every contact leaves a trace — digital actions leave artifacts behind (Correct answer)
- A forensic examiner must never access original evidence directly
- Every criminal leaves a digital signature that is unique
Correct answer: Every contact leaves a trace — digital actions leave artifacts behind
Locard's Exchange Principle states that every contact leaves a trace; in digital forensics, this means that whenever someone interacts with a system, artifacts such as logs and registry entries are left behind.
Question 103: What cryptographic concept does the Diffie-Hellman problem rely on for its security?
- The difficulty of factoring large prime numbers
- The difficulty of computing discrete logarithms (Correct answer)
- The difficulty of reversing hash functions
- The difficulty of solving elliptic curve equations
Correct answer: The difficulty of computing discrete logarithms
Diffie-Hellman security relies on the computational difficulty of the discrete logarithm problem: given g^x mod p, finding x is computationally infeasible.
Question 104: A company wants to assess whether employees follow clean desk and physical security policies. Which assessment technique is most appropriate?
- Web application penetration test
- Network vulnerability scan
- Physical security walkthrough / inspection (Correct answer)
- Social engineering phone call
Correct answer: Physical security walkthrough / inspection
A physical security walkthrough allows assessors to directly observe and document compliance with policies like clean desk, visitor management, and access control.
Question 105: Which type of assessment provides a snapshot of current status at a single point in time?
- Formative assessment
- Summative assessment
- Baseline assessment (Correct answer)
- Continuous assessment
Correct answer: Baseline assessment
A baseline assessment captures the current status at a specific point in time, establishing a reference point for measuring future changes.
Question 106: Which biometric error rate represents the probability that an unauthorized user is incorrectly granted access?
- False Acceptance Rate (Correct answer)
- Equal Error Rate
- Crossover Error Rate
- False Rejection Rate
Correct answer: False Acceptance Rate
The False Acceptance Rate (FAR) measures how often the biometric system accepts an unauthorized individual, representing a security failure.
Question 107: What is the primary purpose of conducting a gap analysis during a security assessment?
- To test employee phishing susceptibility
- To compare current security posture against a target framework or standard (Correct answer)
- To enumerate all network assets
- To identify zero-day vulnerabilities
Correct answer: To compare current security posture against a target framework or standard
A gap analysis compares the organization's current security controls and practices against a target baseline such as NIST CSF or ISO 27001 to identify deficiencies.
Question 108: Which type of data classification is MOST common in private sector organizations?
- Top Secret / Secret / Confidential / Unclassified
- Personal / Non-Personal / Sensitive / Open
- Class 1 / Class 2 / Class 3 / Class 4
- Public / Internal / Confidential / Restricted (Correct answer)
Correct answer: Public / Internal / Confidential / Restricted
Private sector organizations typically use a four-tier model of Public, Internal Use Only, Confidential, and Restricted (or similarly named tiers) as opposed to the government's classification scheme.
Question 109: What is the PRIMARY security concern with end-of-life (EOL) software still running in a production environment?
- It is incompatible with modern encryption standards
- It violates data retention policies
- It increases software licensing costs
- It no longer receives security patches, leaving vulnerabilities unmitigated (Correct answer)
Correct answer: It no longer receives security patches, leaving vulnerabilities unmitigated
EOL software no longer receives vendor security updates, so discovered vulnerabilities remain permanently unpatched and exploitable in production environments.
Question 110: Which secure disposal method is REQUIRED for solid-state drives (SSDs) when the data contains classified information?
- Degaussing
- ATA Secure Erase command
- Physical destruction or verified cryptographic erasure (Correct answer)
- Single-pass overwrite using zeros
Correct answer: Physical destruction or verified cryptographic erasure
SSDs are not effectively sanitized by degaussing (no magnetic media) or overwriting (wear leveling may leave residual data); physical destruction or cryptographic erasure are the only reliable methods for classified data.
Question 111: Which firewall architecture places a screened subnet (DMZ) between two firewalls to isolate public-facing servers?
- Packet filtering firewall
- Screened subnet (dual-firewall DMZ) architecture (Correct answer)
- Screened host architecture
- Bastion host architecture
Correct answer: Screened subnet (dual-firewall DMZ) architecture
The screened subnet architecture uses two firewalls creating a DMZ between them, isolating public services from the internal network even if the outer firewall is compromised.
Question 112: Which type of assessment involves authorized simulated attacks that replicate tactics of real-world threat actors to test detection and response capabilities?
- Red team exercise (Correct answer)
- Risk assessment
- Compliance audit
- Vulnerability assessment
Correct answer: Red team exercise
Red team exercises use adversary simulation techniques to test an organization's people, processes, and technology against realistic attack scenarios.
Question 113: A Business Impact Analysis (BIA) is primarily used to:
- Calculate the annual loss expectancy for each asset
- Determine the criticality and recovery priorities of business functions (Correct answer)
- Establish the organization's risk appetite
- Identify all threats that could affect an organization
Correct answer: Determine the criticality and recovery priorities of business functions
A BIA identifies critical business functions, their dependencies, and establishes recovery time objectives (RTOs) and recovery point objectives (RPOs).
Question 114: Which NIST Special Publication provides the primary guidelines for computer security incident handling?
- NIST SP 800-30
- NIST SP 800-53
- NIST SP 800-61 (Correct answer)
- NIST SP 800-137
Correct answer: NIST SP 800-61
NIST SP 800-61, 'Computer Security Incident Handling Guide,' provides guidelines for establishing and operating an incident response capability.
Question 115: Which network protocol allows multiple physical WAN links to be combined into a single logical channel for increased bandwidth and redundancy?
- OSPF equal-cost multipath (ECMP)
- Link Aggregation Control Protocol (LACP / 802.3ad) (Correct answer)
- Spanning Tree Protocol (STP)
- Border Gateway Protocol (BGP)
Correct answer: Link Aggregation Control Protocol (LACP / 802.3ad)
LACP (802.3ad) negotiates link aggregation between devices, bundling multiple physical links into a single logical interface for both throughput and redundancy.
Question 116: Which DNS security mechanism cryptographically signs DNS records to prevent cache poisoning attacks?
- DNS over HTTPS (DoH)
- DNSSEC (Correct answer)
- DNS RPZ (Response Policy Zone)
- DNS over TLS (DoT)
Correct answer: DNSSEC
DNSSEC uses digital signatures on DNS resource records to allow resolvers to verify data authenticity and integrity, directly countering cache poisoning.
Question 117: A parallel test of a DRP involves which key characteristic?
- Running both primary and alternate systems simultaneously (Correct answer)
- Discussing recovery steps without activating any systems
- Testing only a single department's recovery capability
- Completely shutting down primary systems to test recovery
Correct answer: Running both primary and alternate systems simultaneously
In a parallel test, the alternate site is activated and runs concurrently with the primary site to validate recovery without business interruption.
Question 118: Which security planning document defines the acceptable level of loss that an organization is willing to tolerate?
- Risk register
- Risk appetite statement (Correct answer)
- Security baseline
- Business impact analysis
Correct answer: Risk appetite statement
A risk appetite statement formally documents the amount and type of risk an organization is willing to accept in pursuit of its objectives.
Question 119: Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 10% of EU revenue
- $100 million or 5% of US revenue
Correct answer: €20 million or 4% of global annual turnover
GDPR Article 83(5) sets the maximum fine at €20 million or 4% of total worldwide annual turnover for the preceding year, whichever is higher.
Question 120: Which approach is recommended for troubleshooting communication and network security issues?
- Use systematic isolation and testing methods (Correct answer)
- Replace all components simultaneously
- Wait for the problem to resolve itself
- Rely solely on past experience
Correct answer: Use systematic isolation and testing methods
Systematic isolation and testing methodically narrows down the root cause, making troubleshooting efficient and accurate.
Question 121: What is defense in depth in the context of CISSP security?
- Focusing only on perimeter security
- Using one strong security control
- Relying solely on encryption
- Implementing multiple layers of security controls (Correct answer)
Correct answer: Implementing multiple layers of security controls
Defense in depth uses multiple layers of security controls so that if one layer fails, additional layers continue to provide protection.
Question 122: What does 'safe harbor' mean in the context of US-EU data transfers before Privacy Shield was invalidated?
- A legal immunity provision for accidental data breaches
- An encryption standard approved for cross-border transfers
- A self-certification framework allowing US companies to transfer EU personal data by agreeing to privacy principles (Correct answer)
- A physical secure facility for data storage
Correct answer: A self-certification framework allowing US companies to transfer EU personal data by agreeing to privacy principles
Safe Harbor was a self-certification program enabling US organizations to receive EU personal data by committing to FTC-enforced privacy standards.
Question 123: Which cryptographic property ensures that a sender cannot later deny having sent a message?
- Confidentiality
- Integrity
- Non-repudiation (Correct answer)
- Availability
Correct answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, prevents a party from denying the authenticity of their actions or communications.
Question 124: Which type of motion detector uses radar-like signals to detect movement through walls and objects?
- Vibration detector
- Photoelectric sensor
- Microwave detector (Correct answer)
- Passive infrared (PIR)
Correct answer: Microwave detector
Microwave detectors emit microwave pulses and measure reflections, allowing detection through non-metallic barriers.
Question 125: A legacy application uses MD5 to hash passwords. What is the PRIMARY cryptographic concern?
- MD5 is too slow for authentication systems
- MD5 lacks a salt parameter
- MD5 produces hashes that are too short for storage
- MD5 is cryptographically broken and collision-prone (Correct answer)
Correct answer: MD5 is cryptographically broken and collision-prone
MD5 is cryptographically broken, susceptible to collision attacks and extremely fast brute-force cracking, making it unsuitable for password hashing.
Question 126: Which metric is most useful for evaluating program effectiveness in CISSP?
- Outcome-based performance indicators (Correct answer)
- Amount of money spent
- Number of meetings held
- Number of staff involved
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 127: Which type of malware disguises itself as legitimate software but performs malicious actions when executed?
- Logic bomb
- Trojan horse (Correct answer)
- Rootkit
- Worm
Correct answer: Trojan horse
A Trojan horse masquerades as benign or useful software while secretly performing malicious functions when executed by the user.
Question 128: What does the term 'dead man's door' refer to in physical security?
- A mantrap that traps an intruder once unauthorized entry is detected (Correct answer)
- An emergency exit that triggers an alarm when opened
- A secondary exit used only during fire evacuations
- A door that automatically locks if power fails
Correct answer: A mantrap that traps an intruder once unauthorized entry is detected
A dead man's door (or mantrap) captures a person between two interlocked doors when unauthorized access is detected, preventing entry or exit.
Question 129: The principle of 'open design' in security architecture means:
- All source code must be open-source for community review
- Encryption algorithms must use publicly known keys
- Security controls are publicly documented so attackers cannot exploit unknown weaknesses
- System security should not depend on the secrecy of its design (Correct answer)
Correct answer: System security should not depend on the secrecy of its design
Open design means the security of a system should not rely on keeping its design secret — only keys/credentials should be secret.
Question 130: A security architect wants to ensure that no single administrator can make unauthorized changes to the system undetected. Which control best satisfies this?
- Privileged access workstations
- Dual control / two-person integrity (Correct answer)
- Role-based access control
- Mandatory access control
Correct answer: Dual control / two-person integrity
Dual control (two-person integrity) requires two authorized individuals to perform sensitive actions, preventing unilateral unauthorized changes.
Question 131: The concept that no single person should have complete control over a critical process is known as:
- Least privilege
- Need to know
- Defense in depth
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties divides critical tasks among multiple individuals to prevent fraud and error by ensuring no one person can complete a harmful act alone.
Question 132: A penetration tester uses a rogue AP broadcasting the same SSID as the corporate network to capture credentials. This attack is BEST described as:
- Bluejacking
- Evil twin attack (Correct answer)
- Deauthentication attack
- KRACK attack
Correct answer: Evil twin attack
An evil twin attack creates a fraudulent access point mimicking a legitimate SSID to intercept client connections and capture credentials.
Question 133: Which concept describes an architecture where processing occurs at the network edge rather than centralized data centers?
- Hyperconverged infrastructure
- Edge computing (Correct answer)
- Cloud bursting
- Software-defined networking
Correct answer: Edge computing
Edge computing moves compute resources closer to data sources, reducing latency and centralization risks.
Question 134: Which NIST publication provides a framework for conducting security and privacy risk assessments for federal information systems?
- NIST SP 800-30 (Correct answer)
- NIST SP 800-53
- NIST SP 800-137
- NIST SP 800-61
Correct answer: NIST SP 800-30
NIST SP 800-30 provides guidance for conducting risk assessments, including preparing for, conducting, communicating, and maintaining risk assessment results.
Question 135: An assessor wants to determine which vulnerabilities pose the greatest risk to the business. Which process combines vulnerability data with threat intelligence and asset criticality?
- Security benchmarking
- Patch management
- Risk-based vulnerability management (Correct answer)
- Vulnerability scanning
Correct answer: Risk-based vulnerability management
Risk-based vulnerability management prioritizes vulnerabilities by correlating scanner findings with threat intelligence, exploit availability, and business asset value.
Question 136: A company discovers that an attacker exploited a switch to access traffic on a VLAN they should not have access to by sending specially crafted 802.1Q frames. This attack is known as:
- VLAN hopping (double tagging) (Correct answer)
- ARP spoofing
- MAC flooding
- STP manipulation
Correct answer: VLAN hopping (double tagging)
VLAN hopping via double tagging embeds two 802.1Q tags so traffic crosses VLAN boundaries when the outer tag is stripped by the first switch.
Question 137: What does validity mean when selecting an assessment tool for CISSP certification purposes?
- The tool is widely used
- The tool is inexpensive
- The tool measures what it claims to measure (Correct answer)
- The tool is easy to administer
Correct answer: The tool measures what it claims to measure
Validity indicates that an assessment tool accurately measures the construct or ability it was designed to measure.
Question 138: Which approach to system design creates multiple layers of redundant security controls so that failure of one does not result in a breach?
- Defense in depth (Correct answer)
- Security by obscurity
- Minimal footprint
- Security through diversity
Correct answer: Defense in depth
Defense in depth implements layered security controls so an attacker must defeat multiple independent mechanisms to succeed.
Question 139: What security risk is most directly mitigated by using immutable infrastructure (replace rather than patch)?
- Insider threat from privileged administrators
- Zero-day vulnerability exploitation
- Configuration drift and unauthorized changes accumulating over time (Correct answer)
- Denial of service attacks against servers
Correct answer: Configuration drift and unauthorized changes accumulating over time
Immutable infrastructure eliminates configuration drift by replacing entire instances rather than patching running systems.
Question 140: What is the PRIMARY purpose of a data retention policy?
- To restrict who can access sensitive data
- To classify data according to sensitivity
- To ensure data is backed up daily
- To define how long data must be kept and when it must be destroyed (Correct answer)
Correct answer: To define how long data must be kept and when it must be destroyed
A data retention policy establishes the required storage duration for different data types and mandates secure destruction once that period expires, balancing legal requirements and risk.
Question 141: Which architectural component validates that all security controls are properly tested and verified before deployment?
- Evaluation Assurance Level (EAL)
- Trusted Computing Base (TCB) (Correct answer)
- Security baseline
- Security kernel
Correct answer: Trusted Computing Base (TCB)
The Trusted Computing Base encompasses all hardware, software, and firmware that enforce the system security policy.
Question 142: Which identity governance function periodically reviews whether existing user access rights remain appropriate and business-justified?
- User provisioning
- Role mining
- Access recertification (certification campaign) (Correct answer)
- Entitlement management
Correct answer: Access recertification (certification campaign)
Access recertification (also called access certification campaigns) requires managers to review and confirm or revoke their team members' existing access rights periodically.
Question 143: A privileged access management (PAM) solution stores administrator passwords and rotates them after each use. Which PAM capability does this describe?
- Just-in-time access
- Session recording
- Password vaulting with check-out (Correct answer)
- Privilege elevation
Correct answer: Password vaulting with check-out
Password vaulting with check-out allows admins to retrieve a password for one session; the vault automatically rotates it afterward, preventing password reuse.
Question 144: Which phase of a penetration test involves gathering publicly available information about the target without directly interacting with its systems?
- Passive reconnaissance (Correct answer)
- Scanning
- Post-exploitation
- Exploitation
Correct answer: Passive reconnaissance
Passive reconnaissance (OSINT) collects information from public sources like WHOIS, DNS records, and social media without sending traffic to the target.
Question 145: What is the MAIN risk of storing sensitive data in personally identifiable information (PII) beyond its required retention period?
- Increased storage costs
- Difficulty in data retrieval
- Higher exposure to breach liability and regulatory penalties (Correct answer)
- Reduced data quality over time
Correct answer: Higher exposure to breach liability and regulatory penalties
Retaining PII beyond the defined period unnecessarily increases breach exposure and violates privacy regulations like GDPR and CCPA, resulting in significant legal and financial penalties.
Question 146: A microkernel architecture improves security primarily by:
- Requiring multi-factor authentication for all system calls
- Running all OS services in privileged kernel mode
- Minimizing the amount of code running in the most privileged mode (Correct answer)
- Encrypting all inter-process communication
Correct answer: Minimizing the amount of code running in the most privileged mode
Microkernels keep the kernel minimal, moving services to user space to reduce the attack surface of privileged code.
Question 147: What is the key security advantage of using SNMPv3 over SNMPv2c for network device management?
- SNMPv3 operates over TCP instead of UDP
- SNMPv3 eliminates the need for a management station
- SNMPv3 provides authentication and encryption; SNMPv2c uses only community strings (Correct answer)
- SNMPv3 supports more OIDs
Correct answer: SNMPv3 provides authentication and encryption; SNMPv2c uses only community strings
SNMPv3 adds USM (User-based Security Model) providing message authentication (HMAC-MD5/SHA) and encryption (AES), unlike SNMPv2c's cleartext community strings.
Question 148: Which artifact should a penetration test final report always include to help the organization act on findings effectively?
- Detailed exploit code for all vulnerabilities
- Raw scanner output without analysis
- The tester's personal risk opinions
- An executive summary and a prioritized remediation roadmap (Correct answer)
Correct answer: An executive summary and a prioritized remediation roadmap
A quality penetration test report includes an executive summary for leadership and a technical remediation roadmap prioritized by risk to guide the security team's response.
Question 149: A qualitative risk assessment differs from a quantitative one in that it:
- Is only applicable to physical security risks
- Uses numerical monetary values for all calculations
- Always produces more accurate results
- Relies on expert judgment and descriptive categories like High/Medium/Low (Correct answer)
Correct answer: Relies on expert judgment and descriptive categories like High/Medium/Low
Qualitative risk assessments use subjective ratings and expert judgment rather than precise monetary calculations, making them faster but less precise.
Question 150: Which Agile security practice involves writing test cases for known attack scenarios before writing the feature code itself?
- Regression testing
- Penetration testing
- Abuse case development (Correct answer)
- Red team testing
Correct answer: Abuse case development
Abuse cases (or misuse cases) define how an attacker could misuse a feature, guiding developers to build defenses proactively.
Question 151: Which access control model assigns permissions based on rules evaluated against environmental conditions such as time of day or location?
- DAC
- MAC
- ABAC (Correct answer)
- RBAC
Correct answer: ABAC
Attribute-Based Access Control (ABAC) evaluates policies using attributes of the subject, resource, and environment — including contextual conditions like time or location.
Question 152: Which Bluetooth attack allows an attacker to send unsolicited messages to a discoverable Bluetooth device without pairing?
- Bluebugging
- Bluejacking (Correct answer)
- BIAS attack
- Bluesnarfing
Correct answer: Bluejacking
Bluejacking sends unsolicited messages (typically via vCard or messages) to nearby discoverable Bluetooth devices without requiring authentication or pairing.
CISSP Exam
The CISSP (Certified Information Systems Security Professional) Exam is a CAT-format exam covering eight domains of the ISC² CISSP CBK including security and risk management, asset security, security architecture, network security, IAM, security assessment, and security operations.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds