CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 861:

    A hospital has three data classification levels: shareable without restrictions, shareable with restrictions, and internal use only. Which of the following BEST demonstrates adhering to principles of good enterprise data classification?

    A. A printout of the employee code of conduct marked “shareable with restrictions” is posted in the hallway where patients have access.
    B. A printout of the employee code of conduct marked “internal use only” is posted in the waiting room.
    C. A memo regarding a newly discovered data breach marked as “internal use only” is posted on the wall in the employee lunchroom.
    D. An electronic health record (EHR) with personally identifiable information (PII) marked as “sharable with restrictions” is found in the employee lunchroom.

  • Question 862:

    When developing an organization's information security budget, it is important that the

    A. expected risk can be managed appropriately with the funds allocated.
    B. requested funds are at an equal amount to the expected cost of breaches.
    C. requested funds are part of a shared funding pool with other areas.
    D. expected risk to the organization does not exceed the funds allocated.

  • Question 863:

    What operations role is responsible for protecting the enterprise from corrupt or contaminated media?

    A. Information security practitioner
    B. Information librarian
    C. Computer operator
    D. Network administrator

  • Question 864:

    Which of the following is the BEST way to reduce the impact of an externally sourced flood attack?

    A. Have the service provider block the soiree address.
    B. Have the soiree service provider block the address.
    C. Block the soiree address at the firewall.
    D. Block all inbound traffic until the flood ends.

  • Question 865:

    A software architect has been asked to build a platform to distribute music to thousands of users on a global scale. The architect has been reading about content delivery networks (CDN). Which of the following is a principal task to undertake?

    A. Establish a service-oriented architecture (SOA).
    B. Establish a media caching methodology.
    C. Establish relationships with hundreds of Internet service providers (ISP).
    D. Establish a low-latency wide area network (WAN).

  • Question 866:

    Which of the following describes the BEST method of maintaining the inventory of software and hardware within the organization?

    A. Maintaining the inventory through a combination of desktop configuration, administration management, and procurement management tools
    B. Maintaining the inventory through a combination of asset owner interviews, open-source system management, and open-source management tools
    C. Maintaining the inventory through a combination of on-premise storage configuration, cloud management, and partner management tools
    D. Maintaining the inventory through a combination of system configuration, network management, and license management tools

  • Question 867:

    Which of the following attacks is dependent upon the compromise of a secondary target in order to reach the primary target?

    A. Watering hole
    B. Brute force
    C. Spear phishing
    D. Address Resolution Protocol (ARP) poisoning

  • Question 868:

    A security compliance manager of a large enterprise wants to reduce the time it takes to perform network, system, and application security compliance audits while increasing quality and effectiveness of the results. What should be implemented to BEST achieve the desired results?

    A. Configuration Management Database (CMDB)
    B. Source code repository
    C. Configuration Management Plan (CMP)
    D. System performance monitoring application

  • Question 869:

    Which of the following protocols would allow an organization to maintain a centralized list of users that can read a protected webpage?

    A. Lightweight Directory Access Control (LDAP)
    B. Security Assertion Markup Language (SAML)
    C. Hypertext Transfer Protocol (HTTP)
    D. Kerberos

  • Question 870:

    A network security engineer needs to ensure that a security solution analyzes traffic for protocol manipulation and various sorts of common attacks. In addition, all Uniform Resource Locator (URL) traffic must be inspected and users prevented from browsing inappropriate websites. Which of the following solutions should be implemented to enable administrators the capability to analyze traffic, blacklist external sites, and log user traffic for later analysis?

    A. Intrusion detection system (IDS)
    B. Circuit-Level Proxy
    C. Application-Level Proxy
    D. Host-based Firewall

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.