Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Examen

Certified Information Systems Security Professional (CISSP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Puntuación
-
Vendido
-
Páginas
35
Grado
A+
Subido en
30-06-2026
Escrito en
2025/2026

Certified Information Systems Security Professional (CISSP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Institución
Certified Information Systems Security
Grado
Certified Information Systems Security

Vista previa del contenido

Certified Information Systems Security
Professional (CISSP) Questions And
Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
Question 1. An organization is establishing a new information security governance
framework. Which of the following elements is the most critical foundational
component to ensure the framework aligns with the business objectives? A.
Defining strict technical access controls for all database administrators. B.
Implementing an automated vulnerability scanning schedule. C. Securing explicit
commitment and defined roles from executive management. D. Conducting a
third-party penetration test of the external network perimeter.
Answer: C Rationale: Security governance must be driven from the top down.
Executive management commitment ensures that security strategies are aligned
with business goals, adequately funded, and properly enforced across
organizational boundaries. Without executive leadership, policies lack the
authority necessary for widespread compliance and strategic integration.
Question 2. An asset management policy requires classifying data based on
sensitivity. What is the primary purpose of data classification within a risk
management program? A. To guarantee that all data is encrypted both at rest and
in transit. B. To ensure that security controls are proportionally allocated based on
asset value and risk. C. To reduce the total volume of data stored within the
corporate data center. D. To eliminate the need for regular qualitative risk
assessments.
Answer: B Rationale: Data classification allows an organization to categorize
information assets based on the potential impact of unauthorized disclosure,

,modification, or destruction. This enables the security team to apply
appropriate, cost-effective safeguards proportional to the value and sensitivity
of the data, rather than applying uniform, expensive controls to all data
indiscriminately.
Question 3. During an internal audit, a security professional discovers that a single
system administrator has the authority to both approve a system configuration
change change-ticket and implement that same change in the production
environment. Which security principle is being violated? A. Least privilege B. Dual
control C. Separation of duties D. Need to know
Answer: C Rationale: Separation of duties requires that a critical process or
fraudulent activity cannot be completed by a single individual. By splitting the
authorization phase from the implementation phase, the organization prevents
conflicts of interest and unauthorized or accidental modifications to production
environments.
Question 4. An organization calculates that a major flood could damage its
primary data center, resulting in an estimated loss of $2,000,000. Meteorological
data suggests such a flood occurs once every 50 years in that region. What is the
calculated Annualized Loss Expectancy (ALE) for this scenario? A. $40,000 B.
$100,000 C. $400,000 D. $2,000,000
Answer: A Rationale: The Annualized Loss Expectancy (ALE) is calculated by
multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of
Occurrence (ARO). In this case, the SLE is $2,000,000 and the ARO is 1/50 (or
0.02). Multiplying $2,000,000 by 0.02 yields an ALE of $40,000.
Question 5. Following a comprehensive quantitative risk analysis, the Chief
Information Security Officer (CISO) decides to purchase a comprehensive cyber
insurance policy to cover potential losses from ransomware attacks. Which risk
handling strategy has the organization adopted? A. Risk Mitigating B. Risk
Avoidance C. Risk Acceptance D. Risk Transfer
Answer: D Rationale: Risk transfer involves shifting the financial burden of a
potential loss to a third party, such as an insurance company. This strategy does

,not eliminate the underlying vulnerability or threat, but mitigates the direct
financial impact on the organization if the adverse event occurs.
Question 6. A multi-national enterprise must comply with the European Union
General Data Protection Regulation (GDPR). Under GDPR, what is the role of an
entity that determines the purposes and means of processing personal data? A.
Data Processor B. Data Subject C. Data Controller D. Data Protection Officer
Answer: C Rationale: The GDPR defines a Data Controller as the natural or legal
person, public authority, agency, or other body which, alone or jointly with
others, determines the purposes and means of the processing of personal data.
The processor merely executes processing on behalf of the controller.
Question 7. Which of the following options represents a purely administrative
security control? A. Implementing an AI-driven Endpoint Detection and Response
(EDR) agent. B. Mandating annual security awareness training for all corporate
personnel. C. Installing a physical biometric access scanner at the server room
entrance. D. Configuring firewall rules to block inbound traffic from known
malicious IP ranges.
Answer: B Rationale: Administrative controls (also known as managerial
controls) consist of policies, procedures, training, and guidelines established by
management to define employee behavior and reduce organizational risk.
Security awareness training is a fundamental administrative control designed to
reduce human error.
Question 8. A software development firm wants to establish a framework that
provides a structured, iterative method for managing information security risks
and controls, using a Plan-Do-Check-Act cycle. Which standard series should they
primarily consult? A. NIST SP 800-53 B. ISO/IEC 27000 C. PCI DSS D. SOC 2
Answer: B Rationale: The ISO/IEC 27001 standard (part of the 27000 series)
outlines the requirements for establishing, implementing, maintaining, and
continually improving an Information Security Management System (ISMS).
Historically and conceptually, it relies heavily on the Plan-Do-Check-Act (PDCA)
continual improvement cycle.

, Question 9. An employee is terminated for violating corporate ethics policies. To
prevent retaliatory actions, the security team must ensure the employee's logical
access to all corporate systems is revoked immediately upon termination. Which
process is responsible for ensuring this occurs systematically? A. Identity
provisioning B. Offboarding C. Onboarding D. Privilege escalation
Answer: B Rationale: Offboarding is the administrative and operational process
governing the formal departure of an employee or contractor. A critical security
component of offboarding is the immediate, comprehensive revocation of all
physical and logical access privileges to protect corporate assets from
unauthorized access or malicious destruction.
Question 10. A security architect is selecting a threat modeling methodology that
categorizes threats based on six specific vectors: Spoofing, Tampering,
Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Which framework is the architect using? A. DREAD B. PASTA C. STRIDE D. OCTAVE
Answer: C Rationale: STRIDE is a threat modeling framework developed by
Microsoft. Its name is an acronym corresponding to the six threat categories it
evaluates: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of
Service, and Elevation of Privilege.
Question 11. An organization uses a mathematical formula to determine whether
to implement a specific firewall upgrade. The upgrade costs $15,000 annually. The
current risk exposure results in an ALE of $50,000. With the new firewall, the
modified ALE is projected to drop to $10,000. What is the value of this safeguard
to the organization? A. $10,000 B. $25,000 C. $35,000 D. $40,000
Answer: B Rationale: The value of a safeguard is calculated as: (ALE before
control - ALE after control) - Annual Cost of Safeguard. In this scenario, ($50,000
- $10,000) - $15,000 = $40,000 - $15,000 = $25,000. Because the result is positive,
the control provides a net financial benefit.
Question 12. Which document type provides a high-level, authoritative statement
of management's intentions, goals, and requirements regarding security, and is

Escuela, estudio y materia

Institución
Certified Information Systems Security
Grado
Certified Information Systems Security

Información del documento

Subido en
30 de junio de 2026
Número de páginas
35
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

$23.99
Accede al documento completo:

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Conoce al vendedor
Seller avatar
elitelearninghub

Conoce al vendedor

Seller avatar
elitelearninghub Cambridge university
Ver perfil
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
-
Miembro desde
3 semanas
Número de seguidores
0
Documentos
28
Última venta
-
elitelearninghub

Welcome to elitelearninghub Welcome to elitelearninghub – your trusted source for high-quality academic and professional study materials. Our mission is to help students, job seekers, and professionals succeed by providing accurate, well-organized, and easy-to-understand study resources. Whether you\'re preparing for university exams, professional certification tests, licensing exams, or career advancement, our materials are designed to make your learning more effective and your preparation more confident. At elitelearninghub, you\'ll find: Comprehensive exam questions and answers Detailed explanations and rationales Study guides and revision notes Practice tests and mock exams Career certification preparation materials Academic resources for a wide range of subjects Every document is carefully formatted to save you time, improve your understanding, and help you perform at your best. Our goal is to provide reliable learning resources that support your academic and professional journey. Thank you for choosing elitelearninghub. We are committed to helping you study smarter, build confidence, and achieve success in your exams and career. Study Smart. Prepare Better. Succeed with Confidence.

Lee mas Leer menos
0.0

0 reseñas

5
0
4
0
3
0
2
0
1
0

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes