CISSP Exam Details

  • Exam Code
    :CISSP
  • Exam Name
    :Certified Information Systems Security Professional (CISSP)
  • Certification
    :ISC Certifications
  • Vendor
    :ISC
  • Total Questions
    :1703 Q&As
  • Last Updated
    :Jul 16, 2026

ISC CISSP Online Questions & Answers

  • Question 901:

    What is the FIRST step when developing an Information Security Continuous Monitoring (ISCM) program?

    A. Establish an ISCM technical architecture.
    B. Collect the security-related information required for metrics, assessments, and reporting.
    C. Establish an ISCM program determining metrics, status monitoring frequencies, and control assessment frequencies.
    D. Define an ISCM strategy based on risk tolerance.

  • Question 902:

    Which of the following BEST describes a chosen plaintext attack?

    A. The cryptanalyst can generate ciphertext from arbitrary text.
    B. The cryptanalyst examines the communication being sent back and forth.
    C. The cryptanalyst can choose the key and algorithm to mount the attack.
    D. The cryptanalyst is presented with the ciphertext from which the original message is determined.

  • Question 903:

    Including a Trusted Platform Module (TPM) in the design of a computer system is an example of a technique to what?

    A. Interface with the Public Key Infrastructure (PKI)
    B. Improve the quality of security software
    C. Prevent Denial of Service (DoS) attacks
    D. Establish a secure initial state

  • Question 904:

    A user has infected a computer with malware by connecting a Universal Serial Bus (USB) storage device. Which of the following is MOST effective to mitigate future infections?

    A. Develop a written organizational policy prohibiting unauthorized USB devices
    B. Train users on the dangers of transferring data in USB devices
    C. Implement centralized technical control of USB port connections
    D. Encrypt removable USB devices containing data at rest

  • Question 905:

    A security professional should ensure that clients support which secondary algorithm for digital signatures when a Secure Multipurpose Internet Mail Extension (S/MIME) is used?

    A. Triple Data Encryption Standard (3DES)
    B. Advanced Encryption Standard (AES)
    C. Digital Signature Algorithm (DSA)
    D. Rivest-Shamir-Adleman (RSA)

  • Question 906:

    Which of the following is an initial consideration when developing an information security management system?

    A. Identify the contractual security obligations that apply to the organizations
    B. Understand the value of the information assets
    C. Identify the level of residual risk that is tolerable to management
    D. Identify relevant legislative and regulatory compliance requirements

  • Question 907:

    A firm within the defense industry has been directed to comply with contractual requirements for encryption of a government client's Controlled Unclassified Information (CUI). What encryption strategy represents how to protect data at rest in the MOST efficient and cost-effective manner?

    A. Perform physical separation of program information and encrypt only information deemed critical by the defense client
    B. Perform logical separation of program information, using virtualized storage solutions with built-in encryption at the virtualization layer
    C. Perform logical separation of program information, using virtualized storage solutions with encryption management in the back-end disk systems
    D. Implement data at rest encryption across the entire storage area network (SAN)

  • Question 908:

    Which of the following attacks describes the intent behind the pivoting method used by attackers or penetration testers?

    A. Interrupt the communications flows on the network
    B. Use a compromised or obsolete system to traverse the network
    C. Extract sensitive data from resources on the network
    D. Escalate compromised user permissions within the network

  • Question 909:

    During the change management process, which of the following is used to identify and record new risks?

    A. Risk assessment
    B. Lessons learned register
    C. Risk register
    D. Risk report

  • Question 910:

    At a MINIMUM , audits of permissions to individual or group accounts should be scheduled

    A. annually
    B. to correspond with staff promotions
    C. to correspond with terminations
    D. continually

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only ISC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISSP exam preparations and ISC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.