Certified Information Systems Security Professional
Exam (CISSP Exam) New Latest Version with 125
Questions from Actual Exam, Correct Answers and
Rationale
Question 1Which of the following is the PRIMARY goal of information security?
A. To ensure business continuity
B. To protect the confidentiality, integrity, and availability of information
C. To reduce operational costs
D. To comply with regulatory requirements Correct Answer: B
Rationale: The primary goal of information security is to protect the CIA triad (confidentiality,
integrity, availability). Business continuity, cost reduction, and compliance are secondary
objectives.
Question 2What is the BEST definition of a security policy?
A. A document that outlines specific security controls
B. A high-level statement of management’s intent for security
C. A technical guide for implementing firewalls
D. A list of acceptable software applications Correct Answer: B
Rationale: A security policy is a high-level document reflecting management’s intent and
direction for security. Controls, technical guides, and software lists are more specific.
Question 3Which risk management strategy involves accepting the risk as part of normal
operations?
A. Risk avoidance
B. Risk mitigation
C. Risk transference
D. Risk acceptance Correct Answer: D
Rationale: Risk acceptance involves acknowledging and living with the risk without further
action. Avoidance eliminates risk, mitigation reduces it, and transference shifts it (e.g., via
insurance).
Question 4What is the PRIMARY purpose of a nondisclosure agreement (NDA)?
A. To ensure employee compliance with security policies
B. To protect sensitive information from unauthorized disclosure
C. To define acceptable use of company assets
D. To outline disaster recovery procedures Correct Answer: B
Rationale: An NDA protects sensitive information by legally binding parties to confidentiality.
The other options address different aspects of security or operations.
Question 5Which of the following is a KEY component of a business impact analysis (BIA)?
A. Identifying critical business functions and their downtime tolerance
B. Defining firewall rules for network security
,C. Conducting penetration testing
D. Implementing encryption standards Correct Answer: A
Rationale: A BIA identifies critical functions and their acceptable downtime to prioritize
recovery efforts. The other options are unrelated to BIA.
Question 6Which of the following is an example of a deterrent control?
A. A firewall blocking unauthorized traffic
B. A security guard patrolling a facility
C. A warning sign indicating surveillance
D. A backup system for data recovery Correct Answer: C
Rationale: A deterrent control discourages violations (e.g., a warning sign). Firewalls are
preventive, guards are detective/physical, and backups are corrective.
Question 7What is the BEST way to classify data as confidential?
A. Based on its storage location
B. Based on its sensitivity and impact if disclosed
C. Based on the user’s job role
D. Based on its file format Correct Answer: B
Rationale: Data classification is based on sensitivity and the impact of unauthorized disclosure,
not location, user role, or file format.
Question 8Which of the following BEST describes data remanence?
A. Data that is encrypted on a hard drive
B. Residual data remaining after deletion attempts
C. Data stored in a backup system
D. Data transmitted over a network Correct Answer: B
Rationale: Data remanence refers to residual data left on storage media after deletion attempts,
posing a security risk.
Question 9Which encryption algorithm is considered裸裸 considered symmetric?
A. RSA
B. DES
C. AES
D. Diffie-Hellman Correct Answer: C
Rationale: AES (Advanced Encryption Standard) is a symmetric encryption algorithm. RSA and
Diffie-Hellman are asymmetric, and DES is outdated.
Question 10What is the PRIMARY purpose of a digital certificate?
A. To encrypt network traffic
B. To verify the identity of a user or device
C. To store private keys
D. To authenticate network access Correct Answer: B
Rationale: Digital certificates verify the identity of a user or device in secure communications,
typically using public key infrastructure (PKI).
Question 11Which of the following is a characteristic of a defense-in-depth strategy?
, A. Using a single security control for all threats
B. Implementing multiple layers of security controls
C. Relying solely on perimeter security
D. Encrypting all data at rest Correct Answer: B
Rationale: Defense-in-depth uses multiple layers of controls (e.g., firewalls, encryption, policies)
to protect assets comprehensively.
Question 12A company discovers an unauthorized device on its network. What is the FIRST step
to take?
A. Disconnect the device from the network
B. Conduct a forensic analysis
C. Update the firewall rules
D. Notify law enforcement Correct Answer: A
Rationale: Disconnecting the unauthorized device prevents further damage or data loss. Forensic
analysis follows, and updating rules or notifying law enforcement may come later.
Question 13Which access control model uses predefined rules based on job functions?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC) Correct Answer: C
Rationale: RBAC assigns permissions based on job roles. DAC is owner-based, MAC uses
labels, and ABAC uses attributes.
Question 14What is the PRIMARY purpose of a security awareness program?
A. To enforce compliance with regulations
B. To educate employees on security best practices
C. To monitor network activity
D. To implement encryption protocols Correct Answer: B
Rationale: Security awareness programs educate employees to recognize and prevent security
threats, improving overall security posture.
Question 15Which of the following is a KEY component of a risk assessment?
A. Identifying vulnerabilities and threats
B. Installing antivirus software
C. Configuring firewalls
D. Backing up data Correct Answer: A
Rationale: Risk assessment involves identifying vulnerabilities and threats to determine potential
risks. The other options are controls, not assessments.
Question 16Which of the following is an example of a physical security control?
A. Encryption
B. Biometric access control
C. Firewalls
D. Intrusion detection systems Correct Answer: B
Rationale: Biometric access control is a physical security measure. The others are logical
Exam (CISSP Exam) New Latest Version with 125
Questions from Actual Exam, Correct Answers and
Rationale
Question 1Which of the following is the PRIMARY goal of information security?
A. To ensure business continuity
B. To protect the confidentiality, integrity, and availability of information
C. To reduce operational costs
D. To comply with regulatory requirements Correct Answer: B
Rationale: The primary goal of information security is to protect the CIA triad (confidentiality,
integrity, availability). Business continuity, cost reduction, and compliance are secondary
objectives.
Question 2What is the BEST definition of a security policy?
A. A document that outlines specific security controls
B. A high-level statement of management’s intent for security
C. A technical guide for implementing firewalls
D. A list of acceptable software applications Correct Answer: B
Rationale: A security policy is a high-level document reflecting management’s intent and
direction for security. Controls, technical guides, and software lists are more specific.
Question 3Which risk management strategy involves accepting the risk as part of normal
operations?
A. Risk avoidance
B. Risk mitigation
C. Risk transference
D. Risk acceptance Correct Answer: D
Rationale: Risk acceptance involves acknowledging and living with the risk without further
action. Avoidance eliminates risk, mitigation reduces it, and transference shifts it (e.g., via
insurance).
Question 4What is the PRIMARY purpose of a nondisclosure agreement (NDA)?
A. To ensure employee compliance with security policies
B. To protect sensitive information from unauthorized disclosure
C. To define acceptable use of company assets
D. To outline disaster recovery procedures Correct Answer: B
Rationale: An NDA protects sensitive information by legally binding parties to confidentiality.
The other options address different aspects of security or operations.
Question 5Which of the following is a KEY component of a business impact analysis (BIA)?
A. Identifying critical business functions and their downtime tolerance
B. Defining firewall rules for network security
,C. Conducting penetration testing
D. Implementing encryption standards Correct Answer: A
Rationale: A BIA identifies critical functions and their acceptable downtime to prioritize
recovery efforts. The other options are unrelated to BIA.
Question 6Which of the following is an example of a deterrent control?
A. A firewall blocking unauthorized traffic
B. A security guard patrolling a facility
C. A warning sign indicating surveillance
D. A backup system for data recovery Correct Answer: C
Rationale: A deterrent control discourages violations (e.g., a warning sign). Firewalls are
preventive, guards are detective/physical, and backups are corrective.
Question 7What is the BEST way to classify data as confidential?
A. Based on its storage location
B. Based on its sensitivity and impact if disclosed
C. Based on the user’s job role
D. Based on its file format Correct Answer: B
Rationale: Data classification is based on sensitivity and the impact of unauthorized disclosure,
not location, user role, or file format.
Question 8Which of the following BEST describes data remanence?
A. Data that is encrypted on a hard drive
B. Residual data remaining after deletion attempts
C. Data stored in a backup system
D. Data transmitted over a network Correct Answer: B
Rationale: Data remanence refers to residual data left on storage media after deletion attempts,
posing a security risk.
Question 9Which encryption algorithm is considered裸裸 considered symmetric?
A. RSA
B. DES
C. AES
D. Diffie-Hellman Correct Answer: C
Rationale: AES (Advanced Encryption Standard) is a symmetric encryption algorithm. RSA and
Diffie-Hellman are asymmetric, and DES is outdated.
Question 10What is the PRIMARY purpose of a digital certificate?
A. To encrypt network traffic
B. To verify the identity of a user or device
C. To store private keys
D. To authenticate network access Correct Answer: B
Rationale: Digital certificates verify the identity of a user or device in secure communications,
typically using public key infrastructure (PKI).
Question 11Which of the following is a characteristic of a defense-in-depth strategy?
, A. Using a single security control for all threats
B. Implementing multiple layers of security controls
C. Relying solely on perimeter security
D. Encrypting all data at rest Correct Answer: B
Rationale: Defense-in-depth uses multiple layers of controls (e.g., firewalls, encryption, policies)
to protect assets comprehensively.
Question 12A company discovers an unauthorized device on its network. What is the FIRST step
to take?
A. Disconnect the device from the network
B. Conduct a forensic analysis
C. Update the firewall rules
D. Notify law enforcement Correct Answer: A
Rationale: Disconnecting the unauthorized device prevents further damage or data loss. Forensic
analysis follows, and updating rules or notifying law enforcement may come later.
Question 13Which access control model uses predefined rules based on job functions?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC) Correct Answer: C
Rationale: RBAC assigns permissions based on job roles. DAC is owner-based, MAC uses
labels, and ABAC uses attributes.
Question 14What is the PRIMARY purpose of a security awareness program?
A. To enforce compliance with regulations
B. To educate employees on security best practices
C. To monitor network activity
D. To implement encryption protocols Correct Answer: B
Rationale: Security awareness programs educate employees to recognize and prevent security
threats, improving overall security posture.
Question 15Which of the following is a KEY component of a risk assessment?
A. Identifying vulnerabilities and threats
B. Installing antivirus software
C. Configuring firewalls
D. Backing up data Correct Answer: A
Rationale: Risk assessment involves identifying vulnerabilities and threats to determine potential
risks. The other options are controls, not assessments.
Question 16Which of the following is an example of a physical security control?
A. Encryption
B. Biometric access control
C. Firewalls
D. Intrusion detection systems Correct Answer: B
Rationale: Biometric access control is a physical security measure. The others are logical