Isc

CISSP practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 481-question bank.

Provider
Isc
Question bank
481
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CISSP, a certification listed under Isc. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isc. The certification credential is issued by Isc, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Physical assets defined in an organization's business impact analysis (BIA) could include which of the following?

    Choose one answer.

    • Personal belongings of organizational staff members
    • Disaster recovery (DR) line-item revenues
    • Cloud-based applications
    • Supplies kept off-site a remote facility
  2. Question 2 · 1

    An organization has been collecting a large amount of redundant and unusable data and filling up the storage area network (SAN). Management has requested the identification of a solution that will address ongoing storage problems. Which is the BEST technical solution?

    Choose one answer.

    • Compression
    • Caching
    • Replication
    • Deduplication
  3. Question 3 · 1

    What is the PRIMARY purpose of creating and reporting metrics for a security awareness, training, and education program?

    Choose one answer.

    • Measure the effect of the program on the organization's workforce.
    • Make all stakeholders aware of the program's progress.
    • Facilitate supervision of periodic training events.
    • Comply with legal regulations and document due diligence in security practices.
  4. Question 4 · 1

    In a DevOps environment, which of the following actions is MOST necessary to have confidence in the quality of the changes being made?

    Choose one answer.

    • Prepare to take corrective actions quickly.
    • Automate functionality testing.
    • Review logs for any anomalies.
    • Receive approval from the change review board.
  5. Question 5 · 1

    What is the MAIN purpose of a security assessment plan?

    Choose one answer.

    • Provide education to employees on security and privacy, to ensure their awareness on policies and procedures.
    • Provide the objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments.
    • Provide guidance on security requirements, to ensure the identified security risks are properly addressed based on the recommendation.
    • Provide technical information to executives to help them understand information security postures and secure funding.
  6. Question 6 · 1

    What documentation is produced FIRST when performing an effective physical loss control process?

    Choose one answer.

    • Deterrent controls list
    • Security standards list
    • Asset valuation list
    • Inventory list
  7. Question 7 · 1

    Which organizational department is ultimately responsible for information governance related to e-mail and other e-records?

    Choose one answer.

    • Legal
    • Audit
    • Compliance
    • Security
  8. Question 8 · 1

    In Federated Identity Management (FIM), which of the following represents the concept of federation?

    Choose one answer.

    • Collection, maintenance, and deactivation of user objects and attributes in one or more systems, directories or applications
    • Collection of information logically grouped into a single entity
    • Collection of information for common identities in a system
    • Collection of domains that have established trust among themselves
  9. Question 9 · 1

    Which of the following is an indicator that a company's new user security awareness training module has been effective?

    Choose one answer.

    • There are more secure connections to internal e-mail servers.
    • More incidents of phishing attempts are being reported.
    • Fewer incidents of phishing attempts are being reported.
    • There are more secure connections to the internal database servers.
  10. Question 10 · 1

    An organization is trying to secure instant messaging (IM) communications through its network perimeter. Which of the following is the MOST significant challenge?

    Choose one answer.

    • IM clients can interoperate between multiple vendors.
    • IM clients can run as executables that do not require installation.
    • IM clients can utilize random port numbers.
    • IM clients can run without administrator privileges.
  11. Question 11 · 1

    Using the cipher text and resultant cleartext message to derive the monoalphabetic cipher key is an example of which method of cryptanalytic attack?

    Choose one answer.

    • Known-plaintext attack
    • Ciphertext-only attack
    • Frequency analysis
    • Probable-plaintext attack
  12. Question 12 · 1

    Which Wide Area Network (WAN) technology requires the first router in the path to determine the full path the packet will travel, removing the need for other routers in the path to make independent determinations?

    Choose one answer.

    • Synchronous Optical Networking (SONET)
    • Multiprotocol Label Switching (MPLS)
    • Fiber Channel Over Ethernet (FCoE)
    • Session Initiation Protocol (SIP)
  13. Question 13 · 1

    When developing an organization's information security budget, it is important that the:

    Choose one answer.

    • requested funds are at an equal amount to the expected cost of breaches.
    • expected risk can be managed appropriately with the funds allocated.
    • requested funds are part of a shared funding pool with other areas.
    • expected risk to the organization does not exceed the funds allocated.
  14. Question 14 · 1

    A subscription service which provides power, climate control, raised flooring, and telephone wiring but NOT the computer and peripheral equipment is BEST described as a:

    Choose one answer.

    • cold site.
    • warm site.
    • hot site.
    • reciprocal site.
  15. Question 15 · 1

    An international trading organization that holds an International Organization for Standardization (ISO) 27001 certification is seeking to outsource their security monitoring to a managed security service provider (MSSP). The trading organization's security officer is tasked with drafting the requirements that need to be included in the outsourcing contract. Which of the following MUST be included in the contract?

    Choose one answer.

    • A detailed overview of all equipment involved in the outsourcing contract
    • The right to perform security compliance tests on the MSSP's equipment
    • The MSSP having an executive manager responsible for information security
    • The right to audit the MSSP's security process

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free