Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 51 pages
Exam (elaborations)

CISSP PRACTICE EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE

Document preview thumbnail
Preview 4 out of 51 pages

CISSP PRACTICE EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE

Content preview

CISSP PRACTICE EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE

Core Domains
1. Security and Risk Management
2. Asset Security
3. Security Architecture and Engineering
4. Communication and Network Security
5. Identity and Access Management (IAM)
6. Security Assessment and Testing
7. Security Operations
8. Software Development Security

Introduction
This comprehensive practice examination is meticulously designed to mirror the rigor and scope of the Certified
Information Systems Security Professional (CISSP) certification exam. It serves as a vital tool for assessing a candidate's
mastery of the eight domains of the (ISC)² Common Body of Knowledge (CBK). The assessment evaluates not only
foundational theory and technical knowledge but also the practical application of security principles in complex, real-
world scenarios. Candidates will be challenged to apply critical thinking and sound decision-making skills to solve
multifaceted problems, ensuring they are fully prepared for the demands of a senior-level security leadership role. This
test bank provides detailed rationales to solidify understanding and reinforce key concepts.




SECTION ONE: QUESTIONS 1 – 100

,Question 1
Which of the following is the PRIMARY purpose of conducting a Business Impact Analysis (BIA) within the context of
Business Continuity Planning (BCP)?
A. To identify all potential threats and vulnerabilities to the organization's assets.
B. To prioritize business functions and determine the potential impact of their disruption.
C. To develop and document the detailed recovery procedures for each critical system.
D. To assign recovery teams and define their roles and responsibilities during a crisis.

🟢B
🔴 Explanation: The primary purpose of a BIA is to identify and prioritize critical business functions and processes by
quantifying the potential impact (financial, operational, legal, etc.) of their disruption. This prioritization informs the
recovery time objectives (RTOs) and recovery point objectives (RPOs). While identifying threats (A) is part of risk
assessment, developing procedures (C) is part of the plan development, and assigning teams (D) is part of the plan's
organizational structure, these are all downstream activities driven by the BIA's core mission.

Question 2
An organization is implementing a new security policy and needs to ensure that employees understand their
responsibilities. What is the MOST effective method to achieve this?
A. Send a company-wide email with the policy attached.
B. Post the policy on the internal corporate intranet.
C. Provide mandatory, role-based training sessions with a knowledge check.
D. Have each employee sign an acknowledgement form without prior training.

🟢C
🔴 Explanation: Mandatory, role-based training is the most effective method because it ensures that all employees
are actively educated on the policy's specifics, their individual responsibilities, and the consequences of non-
compliance. A knowledge check verifies comprehension. An email (A) or intranet post (B) is passive and does not

,guarantee the information is read or understood. An acknowledgement form (D) confirms receipt but not
understanding, which is insufficient for enforcing accountability.

Question 3
A security architect is designing a network for a financial institution. Which of the following is the BEST approach to
protect a web server that must be accessible from the internet?
A. Place the web server on the internal network behind a stateful firewall.
B. Place the web server in a screened subnet (DMZ) with strict firewall rules.
C. Disable all unused ports and services on the web server.
D. Install a host-based intrusion detection system (HIDS) on the web server.

🟢B
🔴 Explanation: Placing the web server in a DMZ is the best practice for publicly accessible servers. The DMZ acts as
a buffer zone between the untrusted internet and the trusted internal network. Strict firewall rules can then be
applied to allow only necessary traffic (e.g., HTTP/HTTPS) to the server and to control the traffic that can originate
from the server to the internal network. While (C) and (D) are good security hardening practices, they are not as
comprehensive as network segmentation. Placing it on the internal network (A) is a direct violation of the principle
of least privilege and exposes internal assets to significant risk.

Question 4
Which of the following types of controls is a security awareness campaign for employees considered to be?
A. Administrative
B. Technical
C. Physical
D. Detective

🟢A
🔴 Explanation: A security awareness campaign is an administrative (or managerial) control because it is a policy,

, procedure, or program implemented to manage and guide employee behavior. Administrative controls are people-
oriented. Technical controls (B) are implemented via hardware and software. Physical controls (C) are physical
barriers like fences and locks. Detective controls (D) are designed to identify and record security events after they
occur, whereas awareness is a preventive measure.

Question 5
What is the fundamental difference between a threat and a vulnerability?
A. A threat is a weakness, while a vulnerability is a potential danger.
B. A threat is a potential danger, while a vulnerability is a weakness.
C. A threat is a countermeasure, while a vulnerability is an asset.
D. A threat is a realized risk, while a vulnerability is a risk assessment.

🟢B
🔴 Explanation: A threat is any potential danger to an asset, such as a malicious hacker (a threat agent) or a natural
disaster. A vulnerability is a weakness or flaw in a system, process, or control that could be exploited by a threat to
cause harm. The combination of a threat and a vulnerability creates a risk. (A) reverses the definitions. (C) confuses
the terms with countermeasures and assets. (D) incorrectly defines them as a realized risk and a risk assessment,
respectively.

Question 6
An organization is implementing a data classification scheme. Which of the following is the MOST critical factor in
determining the classification level of a dataset?
A. The volume of the data.
B. The age of the data.
C. The potential impact to the organization if the data is compromised.
D. The cost incurred to acquire the data.

Document information

Uploaded on
August 14, 2026
Number of pages
51
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Smartzen
4.8
(11)
Sold
59
Followers
0
Items
1537
Last sold
8 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions