ACTUAL EXAM 2026/2027 | COMPLETE 125 VERIFIED Q&A’S | MULTIPLE-
CHOICE | SCENARIO-BASED | DETAILED RATIONALES – GRADED A+
DOMAIN 1: SECURITY AND RISK MANAGEMENT (20 Questions)
Questions 1-20
Question 1
Which of the following BEST describes the difference between a threat and a vulnerability?
A) A threat is a weakness in the system; a vulnerability is a potential attacker
B) A threat is a potential danger; a vulnerability is a weakness that can be exploited
C) A threat is always intentional; a vulnerability is always accidental
D) They are the same concept with different terminology
Correct Answer: B
Rationale: A threat is any potential danger to an asset, while a vulnerability is a weakness that could be
exploited by a threat to cause harm. Understanding the distinction is fundamental to risk management.
Question 2
Which of the following is a key component of the CIA triad?
A) Confidentiality, Integrity, Availability
B) Confidentiality, Identity, Authentication
C) Control, Integrity, Availability
D) Confidentiality, Integrity, Accountability
Correct Answer: A
Rationale: The CIA triad—Confidentiality, Integrity, and Availability—is the foundation of information
security. Confidentiality ensures data is accessible only to authorized parties, integrity ensures data is accurate
and unaltered, and availability ensures data is accessible when needed.
, CISSP (CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL)
ACTUAL EXAM 2026/2027 | COMPLETE 125 VERIFIED Q&A’S | MULTIPLE-
CHOICE | SCENARIO-BASED | DETAILED RATIONALES – GRADED A+
Question 3
What is the PRIMARY purpose of conducting a risk assessment?
A) To eliminate all security risks
B) To identify, evaluate, and prioritize risks to inform decision-making
C) To comply with regulatory requirements only
D) To assign blame for security incidents
Correct Answer: B
Rationale: A risk assessment identifies, evaluates, and prioritizes risks to inform organizational decision-
making and resource allocation for risk treatment.
Question 4
Which of the following is an example of a qualitative risk assessment technique?
A) Annualized Loss Expectancy (ALE) calculation
B) Single Loss Expectancy (SLE) calculation
C) Risk matrix with likelihood and impact ratings
D) Return on Investment (ROI) analysis
Correct Answer: C
Rationale: Qualitative risk assessment uses subjective ratings like High/Medium/Low for likelihood and
impact. Quantitative methods like ALE, SLE, and ROI use numerical calculations.
Question 5
Which of the following BEST describes the "defense in depth" principle?
, CISSP (CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL)
ACTUAL EXAM 2026/2027 | COMPLETE 125 VERIFIED Q&A’S | MULTIPLE-
CHOICE | SCENARIO-BASED | DETAILED RATIONALES – GRADED A+
A) Relying on a single, strong security control
B) Implementing multiple layers of security controls
C) Placing all security controls at the perimeter
D) Eliminating all security controls except the strongest
Correct Answer: B
Rationale: Defense in depth uses multiple layers of security controls so that if one layer fails, others provide
protection. This includes physical, technical, and administrative controls.
Question 6
Which of the following is a key component of an effective security policy framework?
A) A single policy document covering all topics
B) Tiered policies including policies, standards, guidelines, and procedures
C) Only technical controls
D) No need for periodic review
Correct Answer: B
Rationale: An effective policy framework is tiered, including high-level policies, specific standards, flexible
guidelines, and detailed procedures.
Question 7
The "separation of duties" control is designed to:
A) Reduce costs
B) Prevent fraud and error by requiring multiple individuals to complete tasks
C) Eliminate the need for supervision
D) Increase efficiency
, CISSP (CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL)
ACTUAL EXAM 2026/2027 | COMPLETE 125 VERIFIED Q&A’S | MULTIPLE-
CHOICE | SCENARIO-BASED | DETAILED RATIONALES – GRADED A+
Correct Answer: B
Rationale: Separation of duties requires that no single individual has control over a complete critical function,
preventing fraud and error.
Question 8
Which of the following is a key principle of privacy protection?
A) Collecting as much data as possible
B) Data minimization
C) Unlimited data retention
D) Sharing data with all partners
Correct Answer: B
Rationale: Data minimization is a key privacy principle stating that organizations should collect only the
minimum amount of personal data necessary for the intended purpose.
Question 9
Which of the following is a common security governance framework?
A) COBIT
B) ITIL
C) ISO 27001
D) All of the above
Correct Answer: D
Rationale: COBIT, ITIL, and ISO 27001 are all recognized security governance and management frameworks.