Skip to main content

CISSP Real Exam Questions

Certified Information Systems Security Professional (CISSP)

1,703 questions available · Page 1 of 171

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which of the following is the PRIMARY objective of performing scans with an active discovery tool?

  1. A

    Discovering virus and malware activity

  2. B

    Discovering changes for security configuration management (CM)

  3. C

    Asset identification (ID) and inventory management

  4. D

    Vulnerability management and remediation

Show answer and explanation

Correct answer: C

Explanation

References:
https://www.camcode.com/blog/what-is-asset-identification/

Question 2 Single choice

When implementing a secure wireless network, which of the following supports authentication and authorization for individual client endpoints?

  1. A

    Temporal Key Integrity Protocol (TKIP)

  2. B

    Wi-Fi Protected Access (WPA) Pre-Shared Key (PSK)

  3. C

    Wi-Fi Protected Access 2 (WPA2) Enterprise

  4. D

    Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP)

Show answer and explanation

Correct answer: C

Question 3 Single choice

What balance MUST be considered when web application developers determine how information application error message should be constructed?

  1. A

    Risk versus benefit

  2. B

    Availability versus auditability

  3. C

    Performance versus user satisfaction

  4. D

    Confidentially versus integrity

Show answer and explanation

Correct answer: A

Question 4 Drag & drop

DRAG DROP

Drag the following Security Engineering terms on the left to the BEST definition on the right.

Question diagram
Show answer and explanation
Correct answer diagram
Question 5 Single choice

Which of the following access management procedures would minimize the possibility of an organization's employees retaining access to secure werk areas after they change roles?

  1. A

    User access modification

  2. B

    user access recertification

  3. C

    User access termination

  4. D

    User access provisioning

Show answer and explanation

Correct answer: B

Question 6 Single choice

When a flaw in Industrial control (ICS) software is discovered, what is the GREATEST impediment to deploying a patch?

  1. A

    Many IG systems have software that is no longer being maintained by the venders.

  2. B

    Compensating controls may impact IG performance.

  3. C

    Testing a patch in an IG may require more resources than the organization can commit.

  4. D

    vendors are required to validate the operability patches.

Show answer and explanation

Correct answer: D

Question 7 Single choice

When implementing a data classification program, why is it important to avoid too much granularity?

  1. A

    The process will require too many resources

  2. B

    It will be difficult to apply to both hardware and software

  3. C

    It will be difficult to assign ownership to the data

  4. D

    The process will be perceived as having value

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which one of the following operates at the session, transport, or network layer of the Open System Interconnection (OSI) model?

  1. A

    Data at rest encryption

  2. B

    Configuration Management

  3. C

    Integrity checking software

  4. D

    Cyclic redundancy check (CRC)

Show answer and explanation

Correct answer: D

Question 9 Single choice

Before allowing a web application into the production environment, the security practitioner performs multiple types of tests to confirm that the web application performs as expected. To test the username field, the security practitioner creates a test that enters more characters into the field than is allowed.

Which of the following BEST describes the type of test performed?

  1. A

    Misuse case testing

  2. B

    Penetration testing

  3. C

    Web session testing

  4. D

    Interface testing

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which one of the following documentation should be included in a Disaster Recovery (DR) package?

  1. A

    Source code, compiled code, firmware updates, operational log book and manuals

  2. B

    Data encrypted in original format, auditable transaction data, and recovery instructions tailored for future extraction on demand

  3. C

    Hardware configuration instructions, hardware configuration software, an operating system image, a data restoration option, media retrieval instructions, and contact information

  4. D

    System configuration including hardware, software hardware interfaces, software Application
    Programming Interface (API) configuration, data structure, and transaction data from the previous period

Show answer and explanation

Correct answer: C