Sample questions
Certified Information Systems Security Professional CISSP practice questions
An application authenticates users using session tokens. A security analyst finds that the application does not invalidate session tokens after logout, allowing session fixation at…
Which of the following is the primary purpose of the CIA triad in information security?
Your organization is a medium-sized e-commerce company with a hybrid infrastructure: on-premises datacenter and AWS cloud. The security team recently conducted an internal vulnerab…
An organization is implementing role-based access control (RBAC). Which two components are fundamental to the RBAC model? (Select TWO.)
A hospital chain collects and stores electronic health records (EHR) for millions of patients. The EHR system is hosted in a private cloud and accessed by doctors, nurses, and admi…
An organization's security policy requires that privileged accounts have their passwords changed every 30 days and be monitored. Which solution effectively manages these requiremen…
A network architect is designing a secure connection between two data centers across an untrusted WAN. The requirement is to encrypt all traffic and authenticate both endpoints. Wh…
An organization is developing a business continuity plan (BCP). The IT department has identified a critical application that must be restored within 4 hours of a disruption. Which…
A company wants to ensure that its security policy is effectively enforced across all departments. Currently, the policy is published on the intranet and included in the employee h…
A network analyst suspects a host on the internal network is sending abnormal amounts of traffic. Which tool should be used to capture and analyze the packets?
A security architect is designing a zero-trust network. Which principle is fundamental to a zero-trust architecture (ZTA) such as BeyondCorp?
Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)
Which THREE of the following are valid risk response strategies?
An organization is acquiring a third-party software product. Which THREE of the following should be included in the security assessment of the vendor?
A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implement…
A multinational company must comply with the EU General Data Protection Regulation (GDPR) for processing personal data of EU citizens. The company's data protection officer (DPO) h…
In a public key infrastructure (PKI), which component is responsible for issuing and revoking digital certificates?
After a recent security audit, a network administrator discovers that an attacker has been intercepting traffic by associating with a legitimate access point's MAC address and broa…
A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should th…
A company recently suffered a data breach where an attacker was able to intercept network traffic and read sensitive data. Which network security control should be implemented to p…
A large financial institution is migrating its core banking system to a private cloud. The architecture must protect against data leakage between different business units sharing t…
A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO sho…
A network security analyst receives an alert from the intrusion detection system (IDS) indicating a high volume of TCP SYN packets to a single external IP address from a compromise…
A development team is adopting a secure SDLC. Which phase should include threat modeling to identify potential security vulnerabilities early?