80 QUESTIONS WITH MOST TESTED TOPICS (HARVARD
STYLE)
DESIGNED TO HELP CANDIDATES PREPARE FOR ISC2 CERTIFICATIONS, THIS 2025–2026 PRE-
ASSESSMENT INCLUDES HIGH-YIELD QUESTIONS COVERING CORE SECURITY CONCEPTS, ACCESS
CONTROL, NETWORK DEFENSE, AND INCIDENT RESPONSE. QUESTIONS INCLUDE HARVARD STYLE
CITATIONS FOR ACCURATE STUDY AND REVIEW.
The Triffid Corporation publishes a strategic overview of the company's intent to secure all the data
the company possesses. This document is signed by Triffid senior management. What kind of
document is this? (D1, L1.4.1)
Question options:
A) Policy
B) Procedure
C) Standard
D) Law
A) Policy
A is correct. This is an internal, strategic document, and is therefore a policy. B is incorrect; this is a
strategic overview, not a specific process or practice, so it is not a procedure. C is incorrect; this is an
internal document, not an industry-wide recognized set of practices, so it is not a standard. D is
incorrect; this is not a legal mandate issued by a government, so it is not a law.
Tina is an ISC2 member and is invited to join an online group of IT security enthusiasts. After
attending a few online sessions, Tina learns that some participants in the group are sharing malware
with each other, in order to use it against other organizations online. What should Tina do? (D1,
L1.5.1)
Question options:
A) Nothing
B) Stop participating in the group
C) Report the group to law enforcement
D) Report the group to ISC2
B) Stop participating in the group
, B is the best answer. The ISC2 Code of Ethics requires that members "protect society, the common
good, necessary public trust and confidence, and the infrastructure"; this would include a prohibition
against disseminating and deploying malware for offensive purposes. However, the Code does not
make ISC2 members into law enforcement officers; there is no requirement to get involved in legal
matters beyond the scope of personal responsibility. Tina should stop participating in the group, and
perhaps (for Tina's own protection) document when participation started and stopped, but no other
action is necessary on Tina's part.
A software firewall is an application that runs on a device and prevents specific types of traffic from
entering that device. This is a type of ________ control. (D1, L1.3.1)
Question options:
A) Physical
B) Administrative
C) Passive
D) Technical
D) Technical
D is correct. A software firewall is a technical control, because it is a part of the IT environment. A is
incorrect; a software firewall is not a tangible object that protects something. B is incorrect; a
software firewall is not a rule or process. Without trying to confuse the issue, a software firewall
might incorporate an administrative control: the set of rules which the firewall uses to allow or block
particular traffic. However, answer D is a much better way to describe a software firewall. C is
incorrect; "passive" is not a term commonly used to describe a particular type of security control,
and is used here only as a distractor.
We have an expert-written solution to this problem!
Aphrodite is a member of ISC2 and a data analyst for Triffid Corporation. While Aphrodite is
reviewing user log data, Aphrodite discovers that another Triffid employee is violating the acceptable
use policy and watching streaming videos during work hours. What should Aphrodite do? (D1, L1.5.1)
Question options:
A) Inform ISC2
B) Inform law enforcement
C) Inform Triffid management