CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 1271:

    In software development, developers should use which type of queries to prevent a Structured Query Language (SQL) injection?

    A. Parameterised
    B. Dynamic
    C. Static
    D. Controlled

  • Question 1272:

    A senior security engineer has been tasked with ensuring the confidentiality and integrity of the organization’s most valuable personally identifiable information (PII). This data is stored on local file and database servers within the organization’s data center. The following security measures have been implemented to ensure that unauthorized access is detected and logged.

    Network segmentation and enhanced access logging of the database and file servers Implemented encryption of data at rest Implemented full packet capture of the network traffic in and out of the sensitive network segment Ensured all transaction log data and packet captures are backed up to corporate backup appliance within the corporate backup network segment

    Which of the following is the MOST likely way to exfiltrate PII while avoiding detection?

    A. Unauthorized access to the file server via Secure Shell (SSH)
    B. Unauthorized access to the database server via a compromised web application
    C. Unauthorized access to the database server via a compromised user account
    D. Unauthorized access to the backup server via a compromised service account

  • Question 1273:

    Which of the following is used by the Point-to-Point Protocol (PPP) to determine packet formats?

    A. Layer 2 Tunneling Protocol (L2TP)
    B. Link Control Protocol (LCP)
    C. Challenge Handshake Authentication Protocol (CHAP)
    D. Packet Transfer Protocol (PTP)

  • Question 1274:

    A web-based application known to be susceptible to attacks is now under review by a senior developer. The organization would like to ensure this application Is less susceptible to injection attacks specifically,

    What strategy will work BEST for the organization's situation?

    A. Do not store sensitive unencrypted data on the back end.
    B. Whitelist input and encode or escape output before it is processed for rendering.
    C. Limit privileged access or hard-coding logon credentials,
    D. Store sensitive data in a buffer that retains data in operating system (OS) cache or memory.

  • Question 1275:

    A system with Internet Protocol (IP) address 10.102.10.2 has a physical address of 00:00:08:00:12:13:14:2f. The following static entry is added to its Address Resolution Protocol (ARP) table: 10.102.10.6: 00:00:08:00:12:13:14:2f.

    What form of attack could this represent?

    A. A Denial of Service (DoS) attack against the gateway router because the router can no longer accept packets from 10.102.10.2
    B. A transport layer attack that prevents the resolution of 10.102.10.6 address
    C. A Denial of Service (DoS) attack against 10.102.10.2 because it cannot respond correctly to ARP requests
    D. A masquerading attack that sends packets intended for 10.102.10.6 to 10.102.10.2

  • Question 1276:

    What type of attack sends Internet Control Message Protocol (ICMP) echo requests to the target machine with a larger payload than the target can handle?

    A. Man-in-the-Middle (MITM)
    B. Denial of Service (DoS)
    C. Domain Name Server (DNS) poisoning
    D. Buffer overflow

  • Question 1277:

    Refer to the information below to answer the question.

    A new employee is given a laptop computer with full administrator access. This employee does not have a personal computer at home and has a child that uses the computer to send and receive e-mail, search the web, and use instant

    messaging. The organization's Information Technology (IT) department discovers that a peer-to-peer program has been installed on the computer using the employee's access.

    Which of the following methods is the MOST effective way of removing the Peer-to-Peer (P2P) program from the computer?

    A. Run software uninstall
    B. Re-image the computer
    C. Find and remove all installation files
    D. Delete all cookies stored in the web browser cache

  • Question 1278:

    Which of the following is a detective access control mechanism?

    A. Log review
    B. Least privilege
    C. Password complexity
    D. Non-disclosure agreement

  • Question 1279:

    Which of the following models uses unique groups contained in unique conflict classes?

    A. Chinese Wall
    B. Bell-LaPadula
    C. Clark-Wilson
    D. Biba

  • Question 1280:

    What type of wireless network attack BEST describes an Electromagnetic Pulse (EMP) attack?

    A. Radio Frequency (RF) attack
    B. Denial of Service (DoS) attack
    C. Data modification attack
    D. Application-layer attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.