CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 1121:

    An organization recently upgraded to a Voice over Internet Protocol (VoIP) phone system. Management is concerned with unauthorized phone usage. security consultant is responsible for putting together a plan to secure these phones. Administrators have assigned unique personal identification number codes for each person in the organization. What is the BEST solution?

    A. Use phone locking software to enforce usage and PIN policies.
    B. Inform the user to change the PIN regularly. Implement call detail records (CDR) reports to track usage.
    C. Have the administrator enforce a policy to change the PIN regularly. Implement call detail records (CDR) reports to track usage.
    D. Have the administrator change the PIN regularly. Implement call detail records (CDR) reports to track usage.

  • Question 1122:

    What security technique in the Software Development Life Cycle (SDLC) should be leveraged to BEST ensure secure development throughout a project?

    A. Dynamic application security testing (DAST)
    B. Waterfall
    C. Simple Object Access Protocol
    D. Static application security testing (SAST)

  • Question 1123:

    Which of the following protocols operates at the session layer (layer 5)?

    A. RPC
    B. IGMP
    C. LDP
    D. SPX

  • Question 1124:

    An application developer receives a report back from the security team showing their automated tools were able to successfully enter unexpected data into the organization's customer service portal, causing the site to crash. This is an example of which type of testing?

    A. Non-functional
    B. Positive
    C. Performance
    D. Negative

  • Question 1125:

    An information security consultant is asked to make recommendations for a small business to protect the access to information, stored on network drives. The small business supports several government agencies that manage highly sensitive information. Which of the following recommendations is BEST to achieve this objective?

    A. Develop and implement a security information and event monitoring system.
    B. Develop and implement access management policies and procedures.
    C. Develop and implement data center access policies and procedures.
    D. Develop and implement a security operations center (SOC) for access monitoring.

  • Question 1126:

    Which of the following does the security design process ensure within the System Development Life Cycle (SDLC)?

    A. Proper security controls, security goals, and fault mitigation are properly conducted.
    B. Proper security controls, security objectives, and security goals are properly initiated.
    C. Security goals, proper security controls, and validation are properly initiated.
    D. Security objectives, security goals, and system test are properly conducted.

  • Question 1127:

    All hosts on the network are sending logs via syslog-ng to the log collector. The log collector is behind its own firewall, The security professional wants to make sure not to put extra load on the firewall due to the amount of traffic that is passing through it. Which of the following types of filtering would MOST likely be used?

    A. Uniform Resource Locator (URL) Filtering
    B. Web Traffic Filtering
    C. Dynamic Packet Filtering
    D. Static Packet Filtering

  • Question 1128:

    Refer to the information below to answer the question.

    A security practitioner detects client-based attacks on the organization's network. A plan will be necessary to address these concerns.

    What MUST the plan include in order to reduce client-side exploitation?

    A. Approved web browsers
    B. Network firewall procedures
    C. Proxy configuration
    D. Employee education

  • Question 1129:

    What does a Synchronous (SYN) flood attack do?

    A. Forces Transmission Control Protocol /Internet Protocol (TCP/IP) connections into a reset state
    B. Establishes many new Transmission Control Protocol / Internet Protocol (TCP/IP) connections
    C. Empties the queue of pending Transmission Control Protocol /Internet Protocol (TCP/IP) requests
    D. Exceeds the limits for new Transmission Control Protocol /Internet Protocol (TCP/IP) connections

  • Question 1130:

    What is the FIRST step requird in establishing a records retention program?

    A. Identify and inventory all records.
    B. Identify and inventory all records storage locations
    C. Classify records based on sensitivity.
    D. Draft a records retention policy.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.