CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 1251:

    A project requires the use of an authentication mechanism where playback must be protected and plaintext secret must be used. Which of the following should be used?

    A. Password Authentication Protocol (PAP)
    B. Challenge Handshake Authentication Protocol (CHAP)
    C. Extensible Authentication Protocol (EAP)
    D. Secure Hash Algorithm (SHA)

  • Question 1252:

    Which of the following is a key responsibility for a data steward assigned to manage an enterprise data lake?

    A. Ensure proper business definition, value, and usage of data collected and stored within the enterprise data lake.
    B. Ensure proper and identifiable data owners for each data element stored within an enterprise data lake.
    C. Ensure adequate security controls applied to the enterprise data lake.
    D. Ensure that any data passing within remit is being used in accordance with the rules and regulations of the business.

  • Question 1253:

    Which one of these risk factors would be the LEAST important consideration in choosing a building site for a new computer facility?

    A. Vulnerability to crime
    B. Adjacent buildings and businesses
    C. Proximity to an airline flight path
    D. Vulnerability to natural disasters

  • Question 1254:

    Which of the following is the name of an individual or group that is impacted by a change?

    A. Change agent
    B. Stakeholder
    C. Sponsor
    D. End User

  • Question 1255:

    What term is commonly used to describe hardware and software assets that are stored in a configuration management database (CMDB)?

    A. Configuration element
    B. Asset register
    C. Ledger item
    D. Configuration item

  • Question 1256:

    When using Generic Routing Encapsulation (GRE) tunneling over Internet Protocol version 4 (IPv4), where is the GRE header inserted?

    A. Into the options field
    B. Between the delivery header and payload
    C. Between the source and destination addresses
    D. Into the destination address

  • Question 1257:

    What is the MAIN purpose of a security assessment plan?

    A. Provide guidance on security requirements, to ensure the identified security risks are properly addressed based on the recommendation
    B. Provide the objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments.
    C. Provide technical information to executives to help them understand information security postures and secure funding.
    D. Provide education to employees on security and privacy, to ensure their awareness on policies and procedures

  • Question 1258:

    In a financial institution, who has the responsibility for assigning the classification to a piece of information?

    A. Chief Financial Officer (CFO)
    B. Chief Information Security Officer (CISO)
    C. Originator or nominated owner of the information
    D. Department head responsible for ensuring the protection of the information

  • Question 1259:

    An organization has outsourced its financial transaction processing to a Cloud Service Provider (CSP) who will provide them with Software as a Service (SaaS). If there was a data breach who is responsible for monetary losses?

    A. The Data Protection Authority (DPA)
    B. The Cloud Service Provider (CSP)
    C. The application developers
    D. The data owner

  • Question 1260:

    During the risk assessment phase of the project the CISO discovered that a college within the University is collecting Protected Health Information (PHI) data via an application that was developed in-house. The college collecting this data is fully aware of the regulations for Health Insurance Portability and Accountability Act (HIPAA) and is fully compliant.

    What is the best approach for the CISO?

    A. Document the system as high risk
    B. Perform a vulnerability assessment
    C. Perform a quantitative threat assessment
    D. Notate the information and move on

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.