ISC2 · Free Practice Questions · Last reviewed May 2026
48real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
16% of exam · 6 sample questions below
An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?
Authentication, Authorization, Accounting
This sequence correctly represents the foundational AAA framework. Authentication verifies the user's identity, establishing 'who you are.' Subsequently, Authorization determines the specific resources or actions the authenticated user is permitted to access, defining 'what you can do.' Finally, Accounting meticulously logs all user activities and resource consumption, providing a record of 'what you did' for auditing and accountability.
Authorization, Authentication, Accounting
Authentication, Accounting, Authorization
Accounting, Authentication, Authorization
A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?
$10,000
This value represents the Annualized Loss Expectancy (ALE), which is derived by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $50,000 and an ARO of 0.2 (meaning a 20% chance of the event occurring annually), the correct ALE calculation is $50,000 * 0.2, resulting in $10,000. This figure quantifies the expected financial loss from a specific risk over a one-year period.
$100,000
$50,000
$20,000
Under the ISC2 Code of Ethics, which canon takes precedence over all others?
Provide diligent and competent service to principals
Act honorably, honestly, justly, responsibly, and legally
Protect society, the common good, and the infrastructure
This is the correct answer because it represents the first and highest priority canon in the (ISC)² Code of Ethics. It mandates that certified professionals prioritize the safety, welfare, and security of the public, critical systems, and shared resources above all other considerations. This overarching responsibility ensures that individual or organizational interests never compromise the broader societal well-being or the integrity of essential information technology infrastructure.
Advance and protect the profession
A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?
Warm site
Cold site
Hot site
A hot site is a fully operational, mirrored facility that replicates the primary production environment with identical hardware, software, and up-to-date data, often synchronized in real-time. This comprehensive setup allows for immediate failover in the event of a disaster, ensuring minimal data loss and near-zero downtime. A hot site achieves the lowest Recovery Time Objective (RTO) and Recovery Point Objective (RPO), making it the optimal choice for critical applications requiring continuous availability and rapid business continuity.
Reciprocal agreement
Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?
ISO/IEC 27001
NIST Cybersecurity Framework
COBIT 2019
ITIL
ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing best practices for IT service management (ITSM). It specifically guides organizations through the entire service lifecycle, encompassing Service Strategy, Design, Transition, Operation, and Continual Service Improvement, making it ideal for managing the full journey of IT services.
In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?
High risk
In a qualitative risk assessment, "High risk" is assigned when both the likelihood of a threat event occurring and the potential impact of that event on organizational assets or operations are rated as high or critical. This combination signifies a significant exposure that demands immediate attention and substantial resource allocation for mitigation, as the potential for severe damage is both probable and substantial.
Medium risk
Low risk
De minimis risk
Want more Security and Risk Management practice?
Practice this domainA government contractor handles classified information up to the Secret level. The company's data classification policy recently changed, requiring that all documents marked as 'Confidential' be reclassified as 'Secret' after review. Who is ultimately accountable for ensuring that reclassification is performed correctly?
Data custodian
Data subject
Data steward
Data owner
The data owner holds ultimate organizational accountability for the protection and classification of specific data assets, often a senior business manager. They are responsible for determining the data's sensitivity (e.g., Top Secret, Confidential) and approving access requirements based on business needs and regulatory compliance. This role ensures appropriate security controls are defined and implemented to safeguard the information throughout its lifecycle, bearing the risk of mishandling.
An organization's data retention policy requires that financial records be kept for seven years. After that period, the records must be destroyed in a manner that prevents reconstruction. Which of the following is the best sanitization method for paper records containing sensitive financial data?
Cross-cut shredding
Cross-cut shredding is the most appropriate physical destruction method for paper records containing sensitive financial data. This process cuts paper into small, irregular, confetti-like pieces, making reconstruction practically impossible, unlike strip-cut shredding which leaves longer strips. It ensures that the information cannot be recovered or deciphered, thereby meeting stringent data retention and destruction policy requirements for physical documents.
Overwriting with random patterns multiple times
Cryptographic erasure
Degaussing with a strong magnetic field
A company collects PII from European customers for order processing. Under GDPR, they engage a third-party logistics provider to handle shipping. Which role does the logistics provider typically assume in this scenario?
Data controller
Data custodian
Data processor
Correct. The logistics provider is a data processor processing data on behalf of the controller.
Data subject
A healthcare organization must decommission an old server containing patient health information (PHI) stored on solid-state drives (SSDs). Standard overwriting techniques are ineffective for SSDs due to wear-leveling and bad block mapping. Which sanitization method is most appropriate for these drives?
Cryptographic erasure by deleting the encryption key
Degaussing with a high-coercivity degausser
Physical destruction such as shredding or pulverizing
Physical destruction, through methods like shredding, pulverizing, or incineration, is the most secure and universally effective method for sanitizing Solid State Drives (SSDs). This process physically destroys the NAND flash memory chips and their individual cells, making data recovery absolutely impossible. Unlike other methods, physical destruction bypasses the complexities of wear-leveling, over-provisioning, and inaccessible blocks inherent to SSD architecture, guaranteeing complete data obliteration.
Overwriting with the DoD 5220.22-M 7-pass standard
A database administrator (DBA) is responsible for implementing access controls and backup procedures for a customer database containing PII. The DBA reports to the data owner regarding security measures. Which role best describes the DBA's responsibilities?
Data steward
Data owner
Data custodian
The data custodian, such as a Database Administrator (DBA), is responsible for the practical implementation and maintenance of security controls and data management tasks. They perform day-to-day operations like backups, access control enforcement, patching, and monitoring, ensuring the data's confidentiality, integrity, and availability as directed by the data owner. This role involves the technical execution of policies and procedures to safeguard the data assets.
Data processor
An organization is implementing privacy by design in a new application that collects user location data. Which practice best aligns with the data minimization principle?
Encrypting location data both at rest and in transit
Anonymizing location data after collection
Obtaining explicit consent from users before collection
Collecting location data only when the app is actively in use
This approach directly embodies the 'data minimization' principle of Privacy by Design by ensuring that location data is only acquired when it is essential for the application's active functionality. By limiting collection to periods of active use, the organization significantly reduces the overall volume of sensitive personal data held, thereby mitigating potential privacy risks and demonstrating a proactive commitment to user privacy.
Want more Asset Security practice?
Practice this domain13% of exam · 6 sample questions below
An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?
Reciprocal agreement
Warm site
Cold site
Hot site
A hot site is a fully operational, mirror image of the primary data center, equipped with all necessary hardware, software, and up-to-date data. It maintains real-time or near real-time synchronization with the production environment, allowing for immediate failover and seamless business continuity with minimal disruption. This immediate availability and readiness directly address stringent recovery time objectives (RTOs) that demand near-instantaneous resumption of critical operations following a disaster.
A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?
RAM contents
CPU registers
CPU registers represent the absolute most volatile data on a live system, holding the processor's current operational state, including instructions, memory addresses, and data actively being processed. Any interruption of power or even a context switch can instantly alter or erase this information. Capturing CPU registers first is paramount because they provide the most immediate and granular insight into what the system was doing at the precise moment of forensic interest, making them the highest priority in the order of volatility.
Hard disk contents
Network connections
Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
BCP deals with natural disasters, DRP deals with cyberattacks
BCP is for IT systems, DRP is for business processes
BCP is a subset of DRP
BCP ensures business functions continue, DRP restores IT operations
This statement accurately distinguishes between the primary objectives of Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP). BCP is the strategic, holistic program designed to ensure that an organization's essential business functions can continue operating at an acceptable level during and immediately after a disruptive event. DRP, on the other hand, is the tactical plan focused specifically on the systematic recovery and restoration of the organization's critical information technology systems, applications, and data to an operational state.
A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?
Vulnerability scanner
SOAR
Security Orchestration, Automation, and Response (SOAR) platforms are specifically designed to integrate with SIEM systems to automate and orchestrate incident response workflows. SOAR tools ingest alerts, enrich them with contextual data, and execute predefined playbooks, enabling a SOC team to rapidly respond to threats by automating tasks such as blocking malicious IPs, isolating compromised endpoints, or gathering additional forensic evidence, thereby significantly reducing manual effort and improving response times.
Endpoint detection and response (EDR)
Network-based IDS
An organization's data loss prevention (DLP) solution is configured to block emails containing credit card numbers. This is an example of which type of DLP control?
Classification-based DLP
Network DLP
Network DLP solutions are strategically deployed at network egress points, internal network segments, or as email gateways to monitor and analyze data in transit. They inspect network traffic, including email communications, web uploads, and file transfers, for sensitive content based on predefined policies, preventing unauthorized data exfiltration or policy violations before data leaves the organization's controlled network perimeter.
Cloud DLP
Endpoint DLP
During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
Verification
Reporting
Remediation
Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.
Risk acceptance
Want more Security Operations practice?
Practice this domain13% of exam · 6 sample questions below
A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?
Bell-LaPadula model
The Bell-LaPadula model is a state machine model primarily designed to enforce strict confidentiality in multi-level security environments, making it ideal for military systems handling classified information. It operates on two core rules: the "simple security property" (no read up), preventing subjects from reading data at a higher classification level, and the "*-property" (no write down), preventing subjects from writing data to a lower classification level. These rules ensure that information flows only upwards, effectively protecting classified data from unauthorized disclosure.
Biba model
Brewer-Nash model
Clark-Wilson model
A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?
Bell-LaPadula
Graham-Denning
Clark-Wilson
Biba
The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity. It operates on two core principles: the Simple Integrity Axiom (no read down) and the * (Star) Integrity Axiom (no write up). These rules ensure that subjects cannot read data of lower integrity (to prevent being corrupted) and cannot write to data of higher integrity (to prevent corrupting it), making it ideal for applications requiring strict integrity controls.
Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?
MAC
RBAC
ABAC
DAC
Discretionary Access Control (DAC) is an access control model where the owner of a resource (or an authorized administrator) has the discretion to grant or revoke access permissions to other users. This is typically implemented using Access Control Lists (ACLs) or capabilities, allowing owners to specify who can perform specific actions (read, write, execute) on their owned objects. DAC is highly flexible and widely used in commercial operating systems because it empowers data owners to manage access to their own data.
A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?
RC4
RSA
AES
AES (Advanced Encryption Standard) is a symmetric block cipher, widely recognized and adopted as the global standard for secure data encryption. It operates by encrypting data in fixed-size blocks (128 bits) using key sizes of 128, 192, or 256 bits, offering robust security against all known practical attacks when properly implemented. Its excellent balance of strong cryptographic properties, high performance, and efficiency makes it the optimal choice for encrypting bulk data in contemporary systems.
3DES
A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?
ASLR
ASLR (Address Space Layout Randomization) is a memory protection technique that randomly arranges the positions of key data areas, such as the base of the executable, the stack, heap, and libraries, within a process's virtual address space. This randomization makes it significantly more difficult for an attacker to predict target addresses for return-oriented programming (ROP) attacks or to reliably locate malicious code or useful gadgets. By introducing unpredictability, ASLR effectively mitigates the success rate of many memory corruption exploits that rely on known memory layouts.
SafeSEH
Stack canaries
DEP/NX bit
Which of the following is a primary function of a Trusted Platform Module (TPM)?
Encrypting network traffic
Providing antivirus protection
Enforcing access control policies
Storing cryptographic keys securely
Storing cryptographic keys securely is a core and primary function of a Trusted Platform Module (TPM). The TPM provides a tamper-resistant environment, often isolated from the main CPU, where sensitive cryptographic keys can be generated, stored, and used without being exposed to software vulnerabilities or physical attacks on the host system. This secure storage protects keys from unauthorized access and ensures their integrity, which is crucial for secure boot, disk encryption, and digital signing operations.
Want more Security Architecture and Engineering practice?
Practice this domain13% of exam · 6 sample questions below
A security analyst observes a network attack where an attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. This attack occurs at which layer of the OSI model?
Layer 3 – Network
Layer 1 – Physical
Layer 4 – Transport
Layer 2 – Data Link
The Data Link layer (Layer 2) is responsible for node-to-node data transfer and error correction from the physical layer, handling frame synchronization, flow control, and error checking. ARP (Address Resolution Protocol) operates at this layer, resolving Layer 3 IP addresses to Layer 2 MAC addresses within a local network segment to enable direct communication. ARP spoofing exploits this protocol by sending forged ARP messages, associating the attacker's MAC address with the IP address of another legitimate host, thereby redirecting traffic at the local network level.
An organization is deploying a VPN solution for remote employees. The security team requires a modern protocol with perfect forward secrecy, uses elliptic curve cryptography, and is known for its efficient, minimal codebase. Which VPN protocol should they choose?
WireGuard
WireGuard is a modern, high-performance VPN protocol distinguished by its extremely small codebase, which significantly reduces the attack surface and simplifies auditing. It leverages state-of-the-art cryptographic primitives, including ChaCha20 for symmetric encryption, Poly1305 for authentication, and Curve25519 for Elliptic Curve Cryptography (ECC) and Perfect Forward Secrecy (PFS) key exchange. This combination ensures robust security, exceptional speed, and efficient resource utilization, making it ideal for remote employees seeking a fast and secure connection.
L2TP/IPsec
PPTP
IPsec with IKEv2
A security engineer is configuring a firewall that makes decisions based on source/destination IP addresses and port numbers without tracking the state of connections. Which type of firewall is this?
Stateful inspection firewall
Application proxy firewall
Packet filter firewall
A packet filter firewall, often referred to as a stateless firewall, makes forwarding decisions solely based on the information contained within the network and transport layer headers of individual packets. It examines source and destination IP addresses, source and destination port numbers, and protocol types against a predefined set of rules. This method is stateless, meaning it does not track the state of ongoing connections, perfectly matching the scenario's implied basic filtering criteria.
Next-generation firewall
An organization wants to secure email communications by providing encryption and digital signatures. They require a solution that uses a web of trust model rather than a hierarchical PKI. Which protocol should they implement?
S/MIME
TLS
SSH
PGP/GPG
PGP (Pretty Good Privacy) and GPG (GNU Privacy Guard) are comprehensive cryptographic programs that provide end-to-end encryption and digital signing for email communications and files. They enable users to encrypt email content on their local machine before sending it, ensuring only the intended recipient with the corresponding private key can decrypt it. PGP/GPG uniquely employs a decentralized "web of trust" model for public key verification, allowing users to establish trust relationships without relying on a central Certificate Authority.
A network administrator is configuring SNMPv3 for monitoring network devices. The organization requires both authentication and encryption of SNMP traffic. Which combination of protocols should be used to meet this requirement?
MD5 for authentication, no privacy
SHA for authentication, no privacy
SHA for authentication, AES for privacy
This option is correct because it combines the strongest available security algorithms within SNMPv3's User-based Security Model (USM). SHA (Secure Hash Algorithm) provides robust message integrity and authentication, ensuring that messages have not been tampered with and originate from a legitimate source. AES (Advanced Encryption Standard) delivers strong confidentiality, encrypting the entire SNMP message to protect sensitive monitoring data from eavesdropping and unauthorized disclosure, aligning with current best practices for secure network management.
MD5 for authentication, DES for privacy
Which wireless security protocol replaces the pre-shared key (PSK) authentication with Simultaneous Authentication of Equals (SAE) to provide stronger security and forward secrecy?
WPA3
WPA3 significantly enhances wireless security by replacing the vulnerable Pre-Shared Key (PSK) 4-way handshake with the Simultaneous Authentication of Equals (SAE) protocol, also known as Dragonfly. SAE is a password-authenticated key agreement (PAKE) protocol that establishes a secure session key without ever transmitting the password directly. This robust cryptographic exchange provides stronger protection against offline dictionary attacks and ensures forward secrecy, making it the correct answer for replacing the PSK mechanism.
WEP
WPA2 with TKIP
WPA2 with CCMP
Want more Communication and Network Security practice?
Practice this domain12% of exam · 6 sample questions below
A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?
Security review
Vulnerability assessment
A vulnerability assessment systematically scans systems, applications, and networks for known security weaknesses, configuration errors, and missing patches. It utilizes automated tools and manual analysis to identify potential flaws without attempting to exploit them. The primary goal is to provide a prioritized list of vulnerabilities that could be exploited, enabling organizations to proactively address risks before they are leveraged by attackers.
Security audit
Penetration test
During a penetration test, the tester has obtained initial access and is now trying to move laterally to other systems. Which phase of the penetration testing process does this represent?
Reconnaissance
Reporting
Post-exploitation/lateral movement
Post-exploitation begins immediately after initial access is successfully gained on a target system. This crucial phase focuses on maintaining access, escalating privileges within the compromised system, gathering sensitive information, and establishing persistence mechanisms. Lateral movement is a key component, involving techniques to pivot from the initial compromised host to other systems within the network, expanding the tester's foothold and access to additional resources to simulate a real-world breach.
Exploitation
A company wants to ensure its internal web application is free from security flaws during development. Which testing approach analyzes source code without executing the program?
IAST
RASP
DAST
SAST
SAST (Static Application Security Testing) directly examines the application's source code, bytecode, or binary code without executing it, identifying potential security vulnerabilities like SQL injection or cross-site scripting. This "white-box" approach is ideal for finding flaws early in the development lifecycle, before the application is even compiled or deployed, making it highly effective for proactive security.
Which of the following is a key component of the rules of engagement for a penetration test?
Exploitation techniques to use
Emergency stop criteria
Emergency stop criteria are a critical component of the Rules of Engagement (RoE) because they explicitly define the conditions under which an engagement must be immediately halted to prevent unintended harm, legal issues, or excessive risk. These criteria ensure that testing can be safely terminated if unexpected system instability, unauthorized access to sensitive data, or other critical incidents occur, thereby protecting the target environment and the testing team. Establishing these clear boundaries is fundamental to responsible and controlled security assessments.
CVSS score of vulnerabilities
Number of vulnerabilities found
Which vulnerability scoring system provides a standardized severity rating for vulnerabilities based on exploitability and impact metrics?
NVD
CVE
CVSS
The Common Vulnerability Scoring System (CVSS) is an open industry standard designed to provide a qualitative and quantitative method for assessing the severity of software vulnerabilities. It generates a numerical score, ranging from 0.0 to 10.0, based on various metrics like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. This standardized scoring allows organizations to objectively prioritize vulnerability remediation efforts based on a consistent, globally recognized framework.
CWE
A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?
Patch compliance percentage
ROI of security controls
Mean time to remediate critical vulnerabilities
Mean time to remediate critical vulnerabilities is a direct and highly effective metric for measuring the operational speed and efficiency of an organization's vulnerability response program. It quantifies the average duration from the initial detection of a critical vulnerability to its complete resolution, including patching, configuration changes, or architectural redesigns. This metric precisely reflects how quickly the security team and supporting IT functions can address the most significant risks, directly indicating the effectiveness of their remediation processes.
Number of open vulnerabilities by severity
Want more Security Assessment and Testing practice?
Practice this domain10% of exam · 6 sample questions below
A security team is reviewing a web application that allows users to search for products. The application uses a SQL database and constructs queries by concatenating user input directly into the SQL statement. Which of the following is the most effective mitigation against SQL injection attacks?
Using parameterized queries with prepared statements
Parameterized queries with prepared statements are the most effective defense against SQL injection because they fundamentally separate the SQL code structure from user-provided data. The database engine treats all input as literal values, not executable commands, preventing malicious input from altering the query's intent. This architectural separation ensures that special characters in user input are never interpreted as SQL syntax, thereby eliminating the injection vector at its root.
Escaping all user input before concatenation
Input validation using a blacklist of known malicious patterns
Implementing a Web Application Firewall (WAF)
During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?
Information Disclosure
Tampering
Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.
Elevation of Privilege
Spoofing
A development team is fixing a stored cross-site scripting (XSS) vulnerability in a web application that displays user comments. The application stores comments in a database and renders them in HTML. Which of the following is the most secure approach to prevent XSS?
Use Content Security Policy (CSP) headers to restrict script execution
Sanitize input by removing all HTML tags before storing
Apply output encoding based on the context (e.g., HTML entity encoding)
Applying output encoding, specifically HTML entity encoding for HTML contexts, is the most effective and robust solution for preventing stored Cross-Site Scripting (XSS). This process transforms malicious characters (like <, >, &, ", ') into their safe, non-executable representations before rendering them in the browser. By ensuring that user-supplied data is treated as data, not executable code, the browser interprets the encoded script as harmless text, thereby neutralizing the XSS payload.
Store comments in a separate domain to isolate them
A security architect is designing a system that must continue to function even when a component fails. The architect implements multiple layers of security controls so that if one fails, others still provide protection. Which principle is being applied?
Separation of duties
Defense in depth
This robust security strategy involves implementing multiple, independent, and overlapping security controls across various layers of an information system's architecture. By integrating administrative, technical, and physical safeguards, it ensures that if one control fails or is circumvented, other controls are still in place to detect, delay, or prevent an attack. This layered approach significantly increases the complexity and resources required for an adversary to achieve their objectives.
Fail-secure
Least privilege
During a penetration test, a security analyst discovers that a web application allows an attacker to bypass authorization and view another user's private messages by simply changing a numeric ID in the URL. Which vulnerability is being exploited?
Broken authentication
Insecure direct object reference (IDOR)
Insecure direct object reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, database key, or directory, and fails to implement sufficient authorization checks. An attacker can manipulate these references, often found in URL parameters or request bodies, to access or modify resources belonging to other users or system components without explicit permission. This directly aligns with a penetration test discovery where an analyst accesses unauthorized objects by altering an identifier.
Server-side request forgery (SSRF)
Security misconfiguration
A software development team is adopting secure coding practices. They decide to implement input validation for all user-supplied data. Which approach is recommended as the most effective for preventing injection attacks?
Encoding input before processing
Using regular expressions to sanitize input
Blacklist validation to block known malicious patterns
Whitelist validation to allow only known good patterns
Whitelist validation is considered the most robust and secure approach for handling user input. This method explicitly defines and permits only a specific set of known-good, expected characters, formats, or values that the application is designed to accept. Any input that deviates from this precisely defined safe set is rejected by default. This proactive "allow-by-default" strategy effectively prevents unknown or novel attack vectors, as anything not explicitly allowed is implicitly denied, making it highly resilient against various injection and manipulation attempts.
Want more Software Development Security practice?
Practice this domain13% of exam · 6 sample questions below
Which authentication factor type is a smart card?
Somewhere you are
Type 2 (something you have)
A smart card is a quintessential example of a "something you have" authentication factor because it is a tangible, physical item that the user must possess and present for authentication. This factor relies on the physical control of an object, such as a cryptographic token, USB key, or in this case, a smart card. The card securely stores cryptographic keys or digital certificates, which are accessed only when the card is physically inserted into a compatible reader, thereby proving possession.
Type 3 (something you are)
Type 1 (something you know)
An organization requires users to authenticate with a password and a one-time code sent to their mobile phone. This is an example of which authentication method?
Two-step verification
Single-factor authentication
Step-up authentication
Multi-factor authentication
Multi-factor authentication (MFA) is the correct choice because it mandates the use of two or more distinct authentication factor types to verify a user's identity. These factors typically include "something you know" (e.g., password), "something you have" (e.g., token, phone), and "something you are" (e.g., fingerprint). By combining different categories, MFA significantly enhances security, making it exponentially harder for unauthorized individuals to gain access even if one factor is compromised.
In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?
Domain Controller
Ticket Granting Server (TGS)
Key Distribution Center (KDC)
Authentication Server (AS)
The Authentication Server (AS) is the precise Kerberos component responsible for the initial authentication of a user or service principal. Upon successful authentication, typically involving a shared secret (like a password hash), the AS issues a Ticket Granting Ticket (TGT) to the client. This TGT is then used by the client to request service tickets from the Ticket Granting Server (TGS) without needing to re-authenticate with the AS, streamlining subsequent access.
An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:
Golden ticket attack
A golden ticket attack leverages a compromised Kerberos Key Distribution Center (KDC) account's NTLM hash (specifically, the krbtgt account) to forge a valid Ticket Granting Ticket (TGT). This forged TGT grants the attacker unlimited, domain-wide administrative access to all resources within the Active Directory environment. The attacker can impersonate any user, including non-existent ones, and request service tickets for any service without further authentication from the legitimate KDC.
Silver ticket attack
Pass-the-ticket attack
Kerberos poisoning attack
Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?
Resource owner password credentials grant
Authorization code grant with PKCE
The Authorization Code Grant with Proof Key for Code Exchange (PKCE) is the recommended flow for public clients, such as mobile and single-page applications. PKCE mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and a `code_challenge` derived from it. This ensures that only the legitimate client that initiated the authorization request can exchange the authorization code for an access token, even if the code is intercepted.
Implicit grant
Client credentials grant
OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?
Client credential management
Authorization delegation
Token introspection
User authentication
OpenID Connect (OIDC) primarily extends OAuth 2.0 by adding a standardized layer for user authentication. While OAuth 2.0 focuses solely on authorization, allowing a client to obtain delegated access to protected resources, OIDC introduces the concept of an ID Token. This ID Token, a JSON Web Token (JWT), provides verifiable claims about the authenticated user, enabling the client application to confirm the user's identity and retrieve basic profile information.
Want more Identity and Access Management practice?
Practice this domainThe CISSP exam has 125 questions and must be completed in 240 minutes. The passing score is 700/1000.
Scenario-based management and technical questions across security governance, risk, architecture, identity, network, application, and operations domains.
The exam covers 8 domains: Security and Risk Management, Asset Security, Security Operations, Security Architecture and Engineering, Communication and Network Security, Security Assessment and Testing, Software Development Security, Identity and Access Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISC2 CISSP exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.