1 | Page
ISC Certified in Cybersecurity Exam
Questions and Answers latest
Which of the following can be used to map data flows
through an organization and the relevant security
controls used at each point along the way? (D5.1, L5.1.1)
a. Encryption
b. Hashing
c. Hard Copy
d. Data Life Cycle Ans: Data Life Cycle
Why is an asset inventory so important?
a. It tells you what to encrypt
b. You can't protect what you don't know you have
c. The law requires it
d. It contains a price list Ans: You can't protect what you
don't know you have
Who is responsible for publishing and signing the
organization's policies? (D5.3, L5.3.1)
a. Security office
© 2025 All rights reserved
, 2 | Page
b. Human Resources
c. Senior Management
d. Legal Department Ans: Senior Mangagement
Which of the following is always true about logging?
(D5.1, L5.1.3)
a. Logs should be very detailed
b. Logs should be in English
c. Logs should be concise
d. Logs should be stored separately from the systems
they're logging Ans: Logs should be stored separately
from the systems they're logging
A mode of encryption for ensuring confidentiality
efficiently, with a minimum amount of processing
overhead (D5.1, L5.1.3)
a. Asymmetric
b. Symmetric
c. Hashing
d. Covert Ans: Symmetric
A ready visual cue to let anyone in contact with the data
know what the classification is. (D5.1, L5.1.1)
© 2025 All rights reserved
, 3 | Page
a. Encryption
b. Label
c. Graphics
d. Photos Ans: Label
A set of security controls or system settings used to
ensure uniformity of configuration throughout the IT
environment. (D5.2, L5.2.1)
a. Patches
b. Inventory
c. Baseline
d. Policy Ans: Baseline
What is the most important aspect of security
awareness/training? (D5.4, L5.4.1)
a. Protecting assets
b. Maximizing business capabilities
c. Ensuring the confidentiality of data
d. Protecting health and human safety Ans: Protecting
health and human safety
© 2025 All rights reserved
, 4 | Page
Which entity is most likely to be tasked with monitoring
and enforcing security policy? (D5.3, L5.3.1)
a. The Human Resources Office
b. The legal department
c. Regulators
d. The security office Ans: The security office
Which organizational policy is most likely to indicate
which types of smartphones can be used to connect to
the internal IT environment? (D5.3, L5.3.1)
a. The CM policy (change management)
b. The password policy
c. The AUP (acceptable use policy)
d. The BYOD policy (bring your own device) Ans: The
BYOD policy (bring your own device)
Common network device used to connect networks.
Server
Endpoint
Router
Switch Ans: Router
© 2025 All rights reserved
ISC Certified in Cybersecurity Exam
Questions and Answers latest
Which of the following can be used to map data flows
through an organization and the relevant security
controls used at each point along the way? (D5.1, L5.1.1)
a. Encryption
b. Hashing
c. Hard Copy
d. Data Life Cycle Ans: Data Life Cycle
Why is an asset inventory so important?
a. It tells you what to encrypt
b. You can't protect what you don't know you have
c. The law requires it
d. It contains a price list Ans: You can't protect what you
don't know you have
Who is responsible for publishing and signing the
organization's policies? (D5.3, L5.3.1)
a. Security office
© 2025 All rights reserved
, 2 | Page
b. Human Resources
c. Senior Management
d. Legal Department Ans: Senior Mangagement
Which of the following is always true about logging?
(D5.1, L5.1.3)
a. Logs should be very detailed
b. Logs should be in English
c. Logs should be concise
d. Logs should be stored separately from the systems
they're logging Ans: Logs should be stored separately
from the systems they're logging
A mode of encryption for ensuring confidentiality
efficiently, with a minimum amount of processing
overhead (D5.1, L5.1.3)
a. Asymmetric
b. Symmetric
c. Hashing
d. Covert Ans: Symmetric
A ready visual cue to let anyone in contact with the data
know what the classification is. (D5.1, L5.1.1)
© 2025 All rights reserved
, 3 | Page
a. Encryption
b. Label
c. Graphics
d. Photos Ans: Label
A set of security controls or system settings used to
ensure uniformity of configuration throughout the IT
environment. (D5.2, L5.2.1)
a. Patches
b. Inventory
c. Baseline
d. Policy Ans: Baseline
What is the most important aspect of security
awareness/training? (D5.4, L5.4.1)
a. Protecting assets
b. Maximizing business capabilities
c. Ensuring the confidentiality of data
d. Protecting health and human safety Ans: Protecting
health and human safety
© 2025 All rights reserved
, 4 | Page
Which entity is most likely to be tasked with monitoring
and enforcing security policy? (D5.3, L5.3.1)
a. The Human Resources Office
b. The legal department
c. Regulators
d. The security office Ans: The security office
Which organizational policy is most likely to indicate
which types of smartphones can be used to connect to
the internal IT environment? (D5.3, L5.3.1)
a. The CM policy (change management)
b. The password policy
c. The AUP (acceptable use policy)
d. The BYOD policy (bring your own device) Ans: The
BYOD policy (bring your own device)
Common network device used to connect networks.
Server
Endpoint
Router
Switch Ans: Router
© 2025 All rights reserved