Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

CISSP CERTIFICATION PRACTICE TEST | STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED SOLUTIONS

Document preview thumbnail
Preview 4 out of 65 pages

CISSP CERTIFICATION PRACTICE TEST | STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED SOLUTIONS

Content preview

CISSP CERTIFICATION PRACTICE TEST | STUDY GUIDE | LATEST
UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS AND
ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS

This comprehensive 200-question practice examination is meticulously engineered for seasoned
information security professionals preparing for the rigorous Certified Information Systems
Security Professional (CISSP) credentialing assessment aligned with the 2026–2027 exam
outline refresh. Spanning the entire breadth of the eight CISSP Common Body of Knowledge
domains, this resource seamlessly integrates advanced theoretical precepts with complex
scenario-based applications encountered in enterprise security architecture, governance, risk
management, and incident response operations. Each question has been calibrated to reflect the
cognitive intricacy and adaptive difficulty parameters of the live Computer Adaptive Testing
(CAT) environment. Candidates will engage with nuanced troubleshooting vignettes, multi-
layered regulatory compliance dilemmas, cryptographic algorithm selection rationales, physical
security integration challenges, and business continuity planning scenarios. By rigorously
working through these 200 super-advanced questions, detailed answer rationales, and verified
solutions, you will systematically identify latent knowledge gaps, reinforce your command of
security management principles, and cultivate the analytical endurance and judgment required
to pass the official licensing examination on the first attempt.

Table of Contents
Security and Risk Management
Asset Security
Security Architecture and Engineering
Communication and Network Security
Identity and Access Management (IAM)
Security Assessment and Testing
Security Operations
Software Development Security

,Question 1
A multinational conglomerate is harmonizing its data protection framework to accommodate the
extraterritorial scope of the GDPR, sector-specific U.S. federal regulations, and emerging data
localization laws in Southeast Asia. The legal counsel advises that data residency and the
physical locale of backup repositories are non-negotiable. Which governance mechanism
optimally balances these divergent international data sovereignty mandates without imposing
unsustainable operational friction?
A) Implementing a monolithic global policy based strictly on the single most restrictive
regulation
B) Segmenting data stores by geographically defined sovereignty zones and applying localized
data handling matrices with conflict resolution rules
C) Relying on the defunct U.S.-EU Safe Harbor agreement to override conflicting international
privacy statutes
D) Centralizing all data processing in a third-party sovereign cloud that contractually claims
exemption from local jurisdictional subpoenas

Correct Answer: B
Segmenting data stores by geographic sovereignty zones enables a modular, scalable control
environment where a localized data handling matrix applies region-specific privacy rules
without paralyzing global operations. A uniform strictest policy (A) is often operationally
impossible and can conflict with local data access rights, while Safe Harbor (C) was invalidated.
Contractual exemption from subpoenas (D) is legally unenforceable when a nation-state
exercises its police powers.

Question 2
During a quantitative risk analysis for a tier-4 data center, the risk team calculates the
Annualized Rate of Occurrence (ARO) for a catastrophic total facility loss as 0.05. The Exposure
Factor (EF) is determined to be 100%, and the Single Loss Expectancy (SLE) is $12 million.
What is the maximum annualized budget the organization can logically approve for a
theoretically perfect mitigation control that reduces the ARO to absolute zero?
A) $600,000
B) $1.2 million

,C) $12 million
D) $240 million

Correct Answer: A
The Annualized Loss Expectancy (ALE) is derived by multiplying the SLE by the ARO ($12M ×
0.05 = $600,000). The intrinsic value of the risk is $600,000 annually; spending more than this
on mitigation would be fiscally irrational as the control cost would exceed the cost of the loss
itself. The $12 million figure (C) represents the SLE, not the annualized justification for control
expenditure.

Question 3
An internal audit reveals that a legacy relational database stores customer passwords using a one-
way SHA-1 hash function without a unique salt per credential. The audit finding cites a specific
cryptographic failure that allows adversaries to precompute vast mapping chains for near-
instantaneous plaintext recovery of unsalted hashes. Which attack technique does this
vulnerability primarily enable?
A) Rainbow table attack utilizing precomputed hash-to-plaintext mapping chains
B) Replay attack retransmitting valid network session tokens
C) Man-in-the-middle protocol downgrade to weak cipher suites
D) Side-channel timing analysis targeting the hash comparison function

Correct Answer: A
Unsalted hashes are uniquely susceptible to rainbow table attacks, which leverage precomputed
lookup tables of hash-to-plaintext pairs to reverse cryptographic hashing rapidly. A replay
attack (B) involves retransmitting captured session credentials, while a man-in-the-middle key
downgrade (C) targets protocol negotiation flaws. Side-channel timing analysis (D) targets
runtime variations in cryptographic operations, not static storage weaknesses.

Question 4
A security architect is designing an identity federation solution using Security Assertion Markup
Language (SAML) 2.0. The solution requires that the service provider (SP) trust the
authentication event without ever receiving the actual authentication secret. Which identity
propagation mechanism achieves this brokered trust by mediating the relationship between the
identity provider (IdP) and the SP?

, A) The service provider directly validates the user's X.509 certificate against a public Certificate
Revocation List
B) The identity provider issues a digitally signed XML token containing the authentication
context and subject confirmation
C) The service provider performs a reverse-DNS lookup to verify the endpoint domain of the
subject
D) The identity provider provisions a synchronized replicated password hash to the service
provider's vault

Correct Answer: B
In SAML federation, the IdP generates a signed assertion (a trusted XML token) that confirms
the user's authentication to the SP, establishing a brokered trust without sharing the password or
any long-term secret. Direct certificate mapping (A) implies a mutual PKI structure but doesn't
provide federation context attributes. Synchronizing password hashes (D) violates the security
model by exposing secrets outside the authoritative source.

Question 5
A forensic investigator acquires a memory image from a suspect Linux server running kernel
5.15. A malicious process has hidden its visibility from standard user-space tools by
manipulating the kernel's internal process accounting to remove its reference from the task list
while retaining execution rights. Which kernel data structure must the investigator analyze to
reconstruct the hidden process linkage?
A) The Virtual File System (VFS) inode cache
B) The Transmission Control Block (TCB) hash table
C) The slab allocator's linked list of active kernel objects
D) The process descriptor and run queue redirection pointers

Correct Answer: D
Advanced rootkits performing Direct Kernel Object Manipulation (DKOM) unlink the process's
task_struct from the visible process list but retain it in the scheduler's run queue. Analyzing these
redirection pointers allows the forensic investigator to reveal hidden execution threads. The VFS
inode cache (A) pertains to file objects, while the TCB (B) is a network socket structure
irrelevant to process hiding within the scheduler.

Document information

Uploaded on
August 2, 2026
Number of pages
65
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$21.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
111
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions