Sample questions
Certified Information Systems Security Professional CISSP practice questions
Which of the following is the primary purpose of the CIA triad in information security?
An organization is implementing role-based access control (RBAC). Which two components are fundamental to the RBAC model? (Select TWO.)
A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?
A hospital chain collects and stores electronic health records (EHR) for millions of patients. The EHR system is hosted in a private cloud and accessed by doctors, nurses, and admi…
An organization's security policy requires that privileged accounts have their passwords changed every 30 days and be monitored. Which solution effectively manages these requiremen…
An organization is developing a business continuity plan (BCP). The IT department has identified a critical application that must be restored within 4 hours of a disruption. Which…
A company wants to ensure that its security policy is effectively enforced across all departments. Currently, the policy is published on the intranet and included in the employee h…
A network analyst suspects a host on the internal network is sending abnormal amounts of traffic. Which tool should be used to capture and analyze the packets?
In the context of physical security, which of the following is an example of a preventive control?
Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)
Which THREE of the following are valid risk response strategies?
A multinational company must comply with the EU General Data Protection Regulation (GDPR) for processing personal data of EU citizens. The company's data protection officer (DPO) h…
A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finan…
A company implements a centralized authentication system using RADIUS for network devices. The security team notices that after a user's password is changed in Active Directory, th…
A security architect is reviewing a web application's design and identifies several potential vulnerabilities. Which TWO of the following are effective mitigations for cross-site s…
A security analyst discovers that an employee shared confidential customer data with an unauthorized third party. The analyst reports this to the CISO, who decides to terminate the…
After a recent security audit, a network administrator discovers that an attacker has been intercepting traffic by associating with a legitimate access point's MAC address and broa…
Which access control model allows the owner of a resource to determine who can access it and what permissions they have?
A company recently suffered a data breach where an attacker was able to intercept network traffic and read sensitive data. Which network security control should be implemented to p…
A large financial institution is migrating its core banking system to a private cloud. The architecture must protect against data leakage between different business units sharing t…
A network security analyst receives an alert from the intrusion detection system (IDS) indicating a high volume of TCP SYN packets to a single external IP address from a compromise…
A development team is adopting a secure SDLC. Which phase should include threat modeling to identify potential security vulnerabilities early?
A penetration tester is planning an engagement. Which of the following rules of engagement should be defined before testing begins? (Select TWO.)
A financial institution is implementing a data loss prevention (DLP) solution to protect customer financial information. The DLP system must detect and block the transmission of cr…