Isc

CISSP-ISSMP practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 64-question bank.

Provider
Isc
Question bank
64
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CISSP-ISSMP, a certification listed under Isc. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isc. The certification credential is issued by Isc, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following fields of management focuses on establishing and maintaining consistency of a system's or product's performance and its functional and physical attributes with its requirements, design, and operational information throughout its life?

    Choose one answer.

    • Configuration management
    • Risk management
    • Procurement management
    • Change management
  2. Question 2 · 1

    Which of the following terms refers to a mechanism which proves that the sender really sent a particular message?

    Choose one answer.

    • Non-repudiation
    • Confidentiality
    • Authentication
    • Integrity
  3. Question 3 · 1

    Which of the following are examples of physical controls used to prevent unauthorized access to sensitive materials?

    Choose all answers that apply.

    • Thermal alarm systems
    • Closed circuit cameras
    • Encryption
    • Security Guards
  4. Question 4 · 1

    Which of the following security issues does the Bell-La Padula model focus on?

    Choose one answer.

    • Authentication
    • Confidentiality
    • Integrity
    • Authorization
  5. Question 5 · 1

    Which of the following are the examples of administrative controls? Each correct answer represents a complete solution. Choose all that apply.

    Choose all answers that apply.

    • Security awareness training
    • Security policy
    • Data Backup
    • Auditing
  6. Question 6 · 1

    Which of the following laws enacted in United States makes it illegal for an Internet Service Provider (ISP) to allow child pornography to exist on Web sites?

    Choose one answer.

    • Child Pornography Prevention Act (CPPA)
    • USA PATRIOT Act
    • Prosecutorial Remedies and Tools Against the Exploitation of Children Today Act (PROTECT Act)
    • Sexual Predators Act
  7. Question 7 · 1

    You work as a Web Administrator for Perfect World Inc. The company is planning to host an E-commerce Web site. You are required to design a security plan for it. Client computers with different operating systems will access the Web server. How will you configure the Web server so that it is secure and only authenticated users are able to access it? Each correct answer represents a part of the solution. Choose two.

    Choose all answers that apply.

    • Use encrypted authentication.
    • Use the SSL protocol.
    • Use the EAP protocol.
    • Use Basic authentication.
  8. Question 8 · 1

    Which of the following characteristics are described by the DIAP Information Readiness Assessment function? Each correct answer represents a complete solution. Choose all that apply.

    Choose all answers that apply.

    • It performs vulnerability/threat analysis assessment.
    • It identifies and generates IA requirements.
    • It provides data needed to accurately assess IA readiness.
    • It provides for entry and storage of individual system data.
  9. Question 9 · 1

    Your project has several risks that may cause serious financial impact should they happen. You have studied the risk events and made some potential risk responses for the risk events but management wants you to do more. They'd like for you to create some type of a chart that identified the risk probability and impact with a financial amount for each risk event. What is the likely outcome of creating this type of chart?

    Choose one answer.

    • Quantitative analysis
    • Contingency reserve
    • Risk response
    • Risk response plan
  10. Question 10 · 1

    Joseph works as a Software Developer for Web Tech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the following laws are used to protect a part of software?

    Choose one answer.

    • Code Security law
    • Trademark laws
    • Copyright laws
    • Patent laws
  11. Question 11 · 1

    Which of the following is the best method to stop vulnerability attacks on a Web server?

    Choose one answer.

    • Using strong passwords
    • Configuring a firewall
    • Implementing the latest virus scanner
    • Installing service packs and updates
  12. Question 12 · 1

    What course of action can be taken by a party if the current negotiations fail and an agreement cannot be reached?

    Choose one answer.

    • ZOPA
    • PON
    • Bias
    • BATNA
  13. Question 13 · 1

    Which of the following is NOT a valid maturity level of the Software Capability Maturity Model (CMM)?

    Choose one answer.

    • Managed level
    • Defined level
    • Fundamental level
    • Repeatable level
  14. Question 14 · 1

    Which of the following statements is related with the second law of OPSEC?

    Choose one answer.

    • If you are not protecting it (the critical and sensitive information), the adversary wins!
    • If you don't know what to protect, how do you know you are protecting it?
    • If you don't know about your security resources you could not protect your network.
    • If you don't know the threat, how do you know what to protect?
  15. Question 15 · 1

    Which of the following elements of BCP process includes the areas of plan implementation, plan testing, and ongoing plan maintenance, and also involves defining and documenting the continuity strategy?

    Choose one answer.

    • Business continuity plan development
    • Business impact assessment
    • Scope and plan initiation
    • Plan approval and implementation

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free