CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 181:

    Which of the following attributes could be used to describe a protection mechanism of an open design methodology?

    A. lt must be tamperproof to protect it from malicious attacks.
    B. It can facilitate independent confirmation of the design security.
    C. It can facilitate blackbox penetration testing.
    D. It exposes the design to vulnerabilities and malicious attacks.

  • Question 182:

    HOTSPOT

    Which Web Services Security (WS-Security) specification maintains a single authenticated identity across multiple dissimilar environments? Click on the correct specification in the image below.

  • Question 183:

    Which of the following describes the BEST configuration management practice?

    A. After installing a new system, the configuration files are copied to a separate back-up system and hashed to detect tampering.
    B. After installing a new system, the configuration files are copied to an air-gapped system and hashed to detect tampering.
    C. The firewall rules are backed up to an air-gapped system.
    D. A baseline configuration is created and maintained for all relevant systems.

  • Question 184:

    According to best practice, which of the following is required when implementing third party software in a production environment?

    A. Scan the application for vulnerabilities
    B. Contract the vendor for patching
    C. Negotiate end user application training
    D. Escrow a copy of the software

  • Question 185:

    In fault-tolerant systems, what do rollback capabilities permit?

    A. Restoring the system to a previous functional state
    B. Identifying the error that caused the problem
    C. Allowing the system to an in a reduced manner
    D. Isolating the error that caused the problem

  • Question 186:

    A new internal auditor is tasked with auditing the supply chain. The system owner stated that the last internal auditor was terminated because the auditor discovered too many deficient controls. The auditor reports this conversation to their manager. Which of the following audit integrity principles BEST applies to this situation?

    A. Demonstrate competence while performing professional duties.
    B. Perform professional duties with honesty, diligence, and responsibility.
    C. Perform professional duties in accordance with company policy.
    D. Be aware of any influences that may be exerted on professional judgement.

  • Question 187:

    Which of the following is considered the FIRST step when designing an internal security control assessment?

    A. Create a plan based on recent vulnerability scans of the systems in question.
    B. Create a plan based on comprehensive knowledge of known breaches.
    C. Create a plan based on a recognized framework of known controls.
    D. Create a plan based on reconnaissance of the organization's infrastructure.

  • Question 188:

    An organization wants to enable uses to authenticate across multiple security domains. To accomplish this they have decided to use Federated Identity Management (F1M). Which of the following is used behind the scenes in a FIM deployment?

    A. Standard Generalized Markup Language (SGML)
    B. Extensible Markup Language (XML)
    C. Security Assertion Markup Language (SAML)
    D. Transaction Authority Markup Language (XAML)

  • Question 189:

    Which of the following is an example of two-factor authentication?

    A. Retina scan and a palm print
    B. Fingerprint and a smart card
    C. Magnetic stripe card and an ID badge
    D. Password and Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA)

  • Question 190:

    How can a security engineer maintain network separation from a secure environment while allowing remote users to work in the secure environment?

    A. Use a Virtual Local Area Network (VLAN) to segment the network
    B. Implement a bastion host
    C. Install anti-virus on all enceinte
    D. Enforce port security on access switches

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.