You must evaluate controls over information assets and recommend improvements. The most important thing is to apply risk-based thinking: identify the greatest risk, not just a technical flaw, and ensure recommendations are practical and aligned with business objectives.
Start practicing
Protection of Information Assets — choose a session length
Free · No account required
Domain overview
This domain covers the protection of information assets, including access controls, cryptography, network security, and incident response. For CISA, it is tested through scenario-based questions requiring you to evaluate controls, identify risks, and recommend appropriate safeguards across the information lifecycle.
Exam objectives
PKI certificate lifecycle, including revocation via CRL and OCSP.
Segregation of duties enforcement within ERP user provisioning and role design.
Firewall rule review, including any-any rules and least privilege.
Incident response plan effectiveness through testing and lessons learned.
Assuming certificate revocation is effective without checking CRL/OCSP implementation and timeliness.
Believing SoD conflicts are fully mitigated by provisioning-time checks alone, ignoring continuous monitoring.
Recommending rule deletion without assessing business need or change management approval.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
2During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
3An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?
4An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
5An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?
6An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
7During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?
8An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?
9An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?
10An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?
11An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?
12An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?
13During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?
14An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?
15An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?
16During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?
17An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?
18An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?
19An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?
20During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?
21An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?
22An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?
23An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?
24An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?
25An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?
26An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?
27An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?
28During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?
29An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?
30An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?
31During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?
32Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?
33During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?
34An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?
35An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?
36Which of the following is the PRIMARY objective of a penetration test?
37During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?
38An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?
39During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?
40An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?
41An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?
42During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?
43An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?
44An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?
45An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?
46During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?
47An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?
48An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?
49An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?
50An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?
51During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?
52Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?
53Which of the following is the BEST indicator of the effectiveness of a security awareness program?
54An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?
55During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?
56Which of the following is the PRIMARY reason for implementing network segmentation?
57An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?
58An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?
59An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?
60An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?
61During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?
62An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?
63An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?
64An IS auditor is reviewing how a data center protects its backup tapes while they are in transit to an offsite storage facility. Management states that tapes are encrypted before shipment and that a courier transports them in sealed containers. Which of the following is the MOST appropriate evidence to confirm that the tapes are protected in transit?
65An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?
66An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?
67An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?
68An IS auditor is reviewing the data backup strategy for a hospital's electronic health record (EHR) system. The auditor finds that full backups are performed weekly, with daily incremental backups, but the backup tapes are stored in the same server room as the production system. Which of the following is the MOST significant finding?
69An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?
70An IS auditor is reviewing the backup strategy for a critical database server. The database administrator states that a full backup is performed every Sunday, and transaction log backups are performed every hour. The auditor finds that the transaction log backups are stored on the same volume as the database data files. Which of the following is the MOST significant risk associated with this configuration?
71An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?
72An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication. The auditor discovers that the RADIUS server is configured to accept EAP-TLS certificates but does not validate the certificate revocation status. Which of the following is the MOST likely consequence of this configuration?
73An IS auditor is examining how a hospital enforces least privilege for its electronic health record (EHR) system. During walkthroughs, the auditor observes that nurses can access the billing module and that no formal process exists to request, approve, or periodically recertify role assignments. Which of the following is the MOST appropriate recommendation?
74An IS auditor is evaluating the network segmentation of a manufacturing company that separates its corporate network from the industrial control system (ICS) environment. The auditor finds that a firewall exists between the zones, but engineering workstations on the corporate network can reach programmable logic controllers directly over several open ports. Which TWO of the following findings should the auditor report as the MOST significant weaknesses? (Choose two.)
75An IS auditor is reviewing the physical security controls for a data center. The auditor observes that the data center has a raised floor, a fire suppression system, and biometric access controls. The auditor also notes that the data center is located in a region prone to flooding. Which of the following controls is MOST important to mitigate the risk of flooding?
76An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?
77An IS auditor is reviewing the physical security controls at a data center. The auditor observes that entry to the data center requires a smart card and a PIN, and that the door is a single-leaf door with a standard lock. Which of the following is the MOST important physical security control that the auditor should recommend?
78An IS auditor is reviewing an organization's data loss prevention (DLP) deployment. The auditor finds that the DLP solution is configured to monitor outbound email traffic at the network gateway, but endpoint agents are not installed on any workstations. Management states that this configuration is sufficient because all sensitive data leaves through email. Which of the following is the MOST significant risk arising from this configuration?
79An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)
80An IS auditor is evaluating a data loss prevention (DLP) deployment intended to stop sensitive customer records from leaving a bank's network. Management wants assurance that the solution is operating effectively. Which TWO of the following are the MOST important factors for the auditor to assess? (Choose two.)
81An IS auditor is reviewing an organization's data loss prevention (DLP) strategy. The organization has implemented a network DLP solution but has not yet deployed endpoint DLP. Which TWO of the following are the MOST significant risks of relying solely on network DLP? (Choose two.)
82An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication against a RADIUS server. The auditor discovers that the RADIUS server is configured to accept EAP-MD5 as an authentication method for legacy devices. Which of the following is the MOST significant security concern with this configuration?
83An IS auditor is examining how a data center protects its backup tapes while they are transported to an offsite vault. Management states that tapes are encrypted at rest using AES-256. Which of the following is the MOST important control the auditor should verify to protect the tapes during transit?
84An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?
85An IS auditor is reviewing a data center's environmental controls and observes that the fire suppression system uses water sprinklers in the main server room. The auditor learns that the sprinkler system was installed when the facility was a general office space. Management states that the sprinklers have never activated. Which of the following should the IS auditor recommend as the MOST appropriate control improvement?
86An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?
87An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?
88An IS auditor is reviewing an organization's backup and recovery procedures for a critical database. The backup policy states that full backups are performed weekly and transaction log backups every 15 minutes. The recovery point objective (RPO) for the database is 5 minutes. Which of the following is the MOST appropriate recommendation?
89An IS auditor is reviewing an organization's security monitoring architecture. The organization uses a SIEM to collect logs from servers, firewalls, and applications. Management reports that the SIEM is functioning as designed and alerts are generated. Which of the following findings would be of MOST concern to the auditor?
90An IS auditor is reviewing the network segmentation of a retail company's cardholder data environment (CDE). The auditor finds that the CDE and the corporate user VLAN are separated by a firewall, but the same flat Layer 2 domain spans both segments, and no internal segmentation firewall exists between the CDE web tier and the CDE database tier. Which of the following findings should the auditor report as the GREATEST risk?
91An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?
92An IS auditor is evaluating a wireless network deployed in a corporate headquarters. The auditor discovers that the network uses WPA2-Enterprise with 802.1X authentication, but the RADIUS server accepts any client presenting a valid domain user account, including accounts belonging to recently terminated employees that have not yet been disabled. Which of the following is the GREATEST risk arising from this configuration?
93An IS auditor is reviewing a software-as-a-service (SaaS) provider that hosts a company's customer relationship management (CRM) data. The contract states the provider will maintain a SOC 2 Type II report, but the most recent report covers a period ending 14 months ago, and the provider has not responded to requests for a bridge letter. Which of the following should the auditor conclude?
94An IS auditor is examining how a financial services firm enforces data loss prevention (DLP) for outbound email. The firm uses a network DLP appliance that inspects SMTP traffic and blocks messages containing unencrypted account numbers. The auditor discovers that employees can bypass the appliance by using a personal webmail account over HTTPS. Which of the following should the auditor recommend FIRST?
95An IS auditor is reviewing the physical security controls at a data center. The auditor observes that the data center has a single entrance with a biometric scanner, but the door is propped open by a cleaning cart while the cleaning staff works inside. Which of the following is the MOST appropriate action for the auditor to take?
96An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?
97An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?
98An IS auditor is assessing how an organization classifies and handles its information assets. The auditor finds that a data classification policy exists but is inconsistently applied across business units. Which TWO of the following are the MOST important elements the auditor should verify are present to support effective data classification? (Choose two.)
99An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?
100During a review of a data center, an IS auditor observes that backup tapes containing customer records are transported nightly by a courier to an offsite vault. The tapes are placed in sealed containers, but the auditor learns that the courier contract does not require background checks for drivers and that no encryption is applied to the tape contents. Which of the following should the auditor recommend as the MOST effective compensating control?
101An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?
102An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)
103An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)
104An IS auditor is reviewing the backup strategy for a transactional database that processes customer orders. The database is backed up nightly with full backups, and transaction log backups occur every 15 minutes. The recovery point objective (RPO) for the system is 5 minutes. Which of the following is the MOST significant finding the auditor should report?
105An IS auditor is reviewing how an organization manages its backup media. The auditor learns that full backups are written to tape each night, the tapes are stored in a cabinet in the data center, and the same cabinet is used to store cleaning supplies and spare hardware. Which of the following is the MOST significant risk the auditor should highlight?
106An IS auditor is examining how an organization classifies and handles its information assets. The auditor finds that the data classification policy defines four sensitivity levels and corresponding handling rules, but the asset inventory does not record a classification for most systems. Which of the following is the MOST likely consequence of this gap?
107An IS auditor is evaluating a cloud service provider's (CSP) security posture before the organization migrates a customer-facing application to the provider's infrastructure as a service (IaaS) environment. The auditor is reviewing the shared responsibility model and the provider's assurance documentation. Which TWO of the following are the auditor's MOST important considerations? (Choose two.)
108An IS auditor is reviewing the physical security of a data center that houses production servers. During a walkthrough, the auditor observes that the main entrance uses a badge reader, but the door to the network operations center (NOC) is propped open with a chair. Which of the following is the MOST appropriate action for the auditor to take?
109An IS auditor is reviewing the physical security of a data center. The auditor observes that the main entrance uses a proximity card reader, but the door to the server cage area is propped open with a box because the badge reader is malfunctioning. Staff state that the reader has been broken for two weeks and that a work order has been submitted. Which of the following should the IS auditor recommend FIRST?
110An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?
111An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?
112An organization's security team proposes deploying a network-based intrusion prevention system (IPS) inline at the internet perimeter. Management asks the IS auditor to comment on the operational implications before approving the purchase. Which of the following should the auditor identify as the MOST significant operational risk of the inline placement?
113An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)
114An IS auditor is assessing the physical and environmental controls of a primary data center located in a region subject to seasonal flooding. Management has installed a raised floor, a water detection system, and a pre-action fire suppression system. Which TWO of the following findings would the auditor consider MOST significant? (Choose two.)
You must evaluate controls over information assets and recommend improvements. The most important thing is to apply risk-based thinking: identify the greatest risk, not just a technical flaw, and ensure recommendations are practical and aligned with business objectives.
The Courseiva CISA question bank contains 114 questions in the Protection of Information Assets domain, covering the 26% of the exam attributed to this domain in the official ISACA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Protection of Information Assets domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included