CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 421:

    How does Encapsulating Security Payload (ESP) in transport mode affect the Internet Protocol (IP)?

    A. Encrypts and optionally authenticates the IP header, but not the IP payload
    B. Encrypts and optionally authenticates the IP payload, but not the IP header
    C. Authenticates the IP payload and selected portions of the IP header
    D. Encrypts and optionally authenticates the complete IP packet

  • Question 422:

    What access control scheme uses fine-grained rules to specify the conditions under which access to each data item or applications is granted?

    A. Mandatory Access Control (MAC)
    B. Discretionary Access Control (DAC)
    C. Role Based Access Control (RBAC)
    D. Attribute Based Access Control (ABAC)

  • Question 423:

    A manager identified two conflicting sensitive user functions that were assigned to a single user account that had the potential to result in financial and regulatory risk to the company. The manager MOST likely discovered this during which of the following?

    A. Security control assessment.
    B. Separation of duties analysis
    C. Network Access Control (NAC) review
    D. Federated identity management (FIM) evaluation

  • Question 424:

    In setting expectations when reviewing the results of a security test, which of the following statements is MOST important to convey to reviewers?

    A. The target's security posture cannot be further compromised.
    B. The results of the tests represent a point-in-time assessment of the target(s).
    C. The accuracy of testing results can be greatly improved if the target(s) are properly hardened.
    D. The deficiencies identified can be corrected immediately

  • Question 425:

    Knowing the language in which an encrypted message was originally produced might help a cryptanalyst to perform a

    A. clear-text attack.
    B. known cipher attack.
    C. frequency analysis.
    D. stochastic assessment.

  • Question 426:

    Which Hyper Text Markup Language 5 (HTML5) option presents a security challenge for network data leakage prevention and/or monitoring?

    A. Cross Origin Resource Sharing (CORS)
    B. WebSockets
    C. Document Object Model (DOM) trees
    D. Web Interface Definition Language (IDL)

  • Question 427:

    Which of the following is a security weakness in the evaluation of Common Criteria (CC) products?

    A. The manufacturer can state what configuration of the product is to be evaluated
    B. The product can be evaluated by labs in other countries
    C. The Target of Evaluation's (TOE) testing environment is identical to the operating environment
    D. The evaluations are expensive and time-consuming to perform

  • Question 428:

    During examination of Internet history records, the following string occurs within a Unique Resource Locator (URL):

    http://www.companysite.com/products/products.asp?productid=123 or 1=1

    What type of attack does this indicate?

    A. Directory traversal
    B. Structured Query Language (SQL) injection
    C. Cross-Site Scripting (XSS)
    D. Shellcode injection

  • Question 429:

    Configuring a Wireless Access Point (WAP) with the same Service Set Identifier (SSID) as another WAP in order to have users unknowingly connect is referred to as which of the following?

    A. Jamming
    B. Man-in-the-Middle (MITM)
    C. War driving
    D. Internet Protocol (IP) spoofing

  • Question 430:

    A financial services organization has employed a security consultant to review processes used by employees across various teams. The consultant interviewed a member of the application development practice and found gaps in their threat model. Which of the following correctly represents a trigger for when a threat model should be revised?

    A. A new data repository is added.
    B. is After operating system (OS) patches are applied
    C. After a modification to the firewall rule policy
    D. A new developer is hired into the team.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.