Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

CISSP PRACTICE TEST 2026 UPDATE WITH COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY GRADED A+|BRAND NEW VERSION!!

Document preview thumbnail
Preview 2 out of 5 pages

CISSP PRACTICE TEST 2026 UPDATE WITH COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY GRADED A+|BRAND NEW VERSION!!

Content preview

CISSP PRACTICE TEST 2026 UPDATE WITH COMPLETE QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY
GRADED A+|BRAND NEW VERSION!!



Which of the following best describes the relationship between CobiT and ITIL?

A. CobiT is a model for IT governance, whereas ITIL is a model for corporate governance.

B. CobiT provides a corporate governance roadmap, whereas ITIL is a customizable framework for
IT service management.

C. CobiT defines IT goals, whereas ITIL provides the process-level steps on how to achieve them.

D. CobiT provides a framework for achieving business goals, whereas ITIL defines a framework
for achieving IT service-level goals. - ANSWER-C. The Control Objectives for Information and
related Technology (CobiT) is a framework developed by the Information Systems Audit and
Control Association (ISACA) and the IT Governance Institute (ITGI). It defines goals for the
controls that should be used to properly manage IT and ensure IT maps to business needs, not
specifically just security needs. The Information Technology Infrastructure Library (ITIL) is the de
facto standard of best practices for IT service management. A customizable framework, ITIL
provides the goals, the general activities necessary to achieve these goals, and the input and
output values for each process required to meet these determined goals. In essence, CobiT
addresses "what is to be achieved," while ITIL addresses "how to achieve it."



Global organizations that transfer data across international boundaries must abide by guidelines
and transborder information flow rules developed by an international organization that helps
different governments come together and tackle the economic, social, and governance challenges
of a globalized economy. What organization is this?

A. Committee of Sponsoring Organizations of the Treadway Commission

B. The Organisation for Economic Co-operation and Development

C. CobiT

D. International Organization for Standardization - ANSWER-B. Almost every country has its own
rules pertaining to what constitutes private data and how it should be protected. As the digital and
information age came upon us, these different laws started to negatively affect business and
international trade. Thus, the Organisation for Economic Co-operation and Development (OECD)
developed guidelines for various countries so that data is properly protected and everyone
follows the same rules.



Steve, a department manager, has been asked to join a committee that is responsible for defining
an acceptable level of risk for the organization, reviewing risk assessment and audit reports, and
approving significant changes to security policies and programs. What committee is he joining?

A. Security policy committee

, B. Audit committee

C. Risk management committee

D. Security steering committee - ANSWER-D. Steve is joining a security steering committee, which
is responsible for making decisions on tactical and strategic security issues within the enterprise.
The committee should consist of individuals from throughout the organization and meet at least
quarterly. In addition to the responsibilities listed in the question, the security steering committee
is responsible for establishing a clearly defined vision statement that works with and supports the
organizational intent of the business. It should provide support for the goals of confidentiality,
integrity, and availability as they pertain to the organization's business objectives. This vision
statement should, in turn, be supported by a mission statement that provides support and
definition to the processes that will apply to the organization and allow it to reach its business
goals.



As head of sales, Jim is the information owner for the sales department. Which of the following is
not Jim's responsibility as information owner?

A. Assigning information classifications

B. Dictating how data should be protected

C. Verifying the availability of data

D. Determining how long to retain data - ANSWER-C. The responsibility of verifying the availability
of data is the only responsibility listed that does not belong to the information owner. Rather, it is
the responsibility of the information custodian. The information custodian is also responsible for
maintaining and protecting data as dictated by the information owner. This includes performing
regular backups of data, restoring data from backup media, retaining records of activity, and
fulfilling information security and data protection requirements in the company's policies,
guidelines, and standards. Information owners work at a higher level than the custodians. The
owners basically state, "This is the level of integrity, availability, and confidentiality that needs to
be provided—now go do it." The custodian must then carry out these mandates and follow up
with the installed controls to make sure they are working properly.



Assigning data classification levels can help with all of the following except:

A. The grouping of classified information with hierarchical and restrictive security

B. Ensuring that nonsensitive data is not being protected by unnecessary controls

C. Extracting data from a database

D. Lowering the costs of protecting data - ANSWER-C. Data classification does not involve the
extraction of data from a database. However, data classification can be used to dictate who has
access to read and write data that is stored in a database. Each classification should have
separate handling requirements and procedures pertaining to how that data is accessed, used,
and destroyed. For example, in a corporation, confidential information may only be accessed by
senior management. Auditing could be very detailed and its results monitored daily, and
degaussing or zeroization procedures may be required to erase the data. On the other hand,
information classified as public may be accessed by all employees, and no special auditing or
destruction methods required.

Document information

Uploaded on
July 6, 2026
Number of pages
5
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.98

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
DoctorDee
3.5
(6)
Sold
39
Followers
7
Items
5570
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions