CISSP Domain 1 Security and Risk Management 2025 — 50 Q&A
Verified
Series:
CrashCourses Professional Study Series
Author:
Dr Z. Moomba, MBChB, MRCPsych | BethelWellness Ltd
Exam Target:
ISC2 CISSP
Year:
2025/2026
Format:
50 Questions with Verified Answers and Rationales
>
Author's Note:
This document is an original work produced for the CrashCourses Professional Study Series.
Clinical questions and professional scenarios were composed by Dr Z. Moomba based on current
exam objectives, published guidelines, and evidence-based sources (2024–2025). All patient
names, ages, and case details are fictional. Any resemblance to existing published Q&A banks is
coincidental. For personal study use only — not for reproduction or redistribution.
PART 1: CORE PRINCIPLES & FOUNDATIONS
Question 1
A Director of Information Security at a London-based fintech firm requires all customer financial
records to be secured using AES-256 on storage arrays and TLS 1.3 during network transmission.
Which fundamental element of the CIA triad is this technical implementation primarily upholding?
A) System availability
B) Repudiation prevention
C) Data confidentiality
D) Information integrity
Answer: C
,Rationale:
Data confidentiality is directly enforced by using encryption to ensure that only authorized entities
can view the plaintext information.
The explicit specification of AES-256 (for data at rest) and TLS 1.3 (for data in transit) highlights
cryptographic mechanisms designed specifically to hide data content from unauthorized access.
Information integrity is an attractive distractor, but while certain encryption modes provide
integrity checks, the primary goal of these specific ciphers in this context is maintaining secrecy
rather than just preventing unauthorized modification.
Examiner Insight: Confidentiality protects data from unauthorized read access, whereas integrity
protects data from unauthorized write or modification access. [ISC2 CBK 2024]
Question 2
During a routine compliance review, an external auditor finds that five senior infrastructure
engineers at a telecommunications company are using a single shared "admin_root" credential to
perform emergency patches on core routers. Which foundational security tenet is fundamentally
broken by this workflow?
A) Identity authentication
B) User accountability
C) Access authorization
D) Service availability
Answer: B
Rationale:
User accountability is completely nullified when a generic or shared account is utilized, as it
becomes impossible to attribute specific actions to a uniquely identifiable human being.
The phrasing "using a single shared 'admin_root' credential" clearly indicates a lack of individual
tracing, destroying the audit trail.
Identity authentication is incorrect because the engineers are indeed authenticating successfully
(they know the password); the failure is the system's inability to hold a specific person responsible
post-authentication.
High-Yield Point: True accountability requires three distinct phases: unique identification, secure
authentication, and unalterable auditing. [NIST SP 800-53 Rev. 5]
Question 3
The executive board of a global logistics enterprise is overhauling its technology governance.
They require a comprehensive framework that explicitly maps IT performance metrics to
, overarching corporate business objectives. Which of the following governance frameworks is best
suited for this strategic alignment?
A) ISO/IEC 27001
B) COBIT
C) NIST Risk Management Framework
D) COSO Framework
Answer: B
Rationale:
COBIT (Control Objectives for Information and Related Technologies) is specifically engineered to
bridge the gap between technical IT operations and high-level business strategy, providing a
robust set of performance metrics.
The requirement to map "IT performance metrics to overarching corporate business objectives" is
the defining characteristic and primary design goal of COBIT.
The COSO Framework is a tempting choice for corporate governance and financial risk, but it
lacks the specialized, IT-centric performance mapping that COBIT provides for technology
environments.
Clinical Pearl: COBIT is the gold standard for IT governance precisely because it translates
technical risks and controls into business-focused language for executive boards. [ISACA COBIT
2019]
Question 4
A cybersecurity forensic investigator identifies that an outgoing lead developer transferred a
folder containing unreleased, proprietary trading algorithms to their personal cloud drive. The firm
intends to litigate to protect these corporate secrets. Under which intellectual property concept
are these internal algorithms legally guarded?
A) Patent law
B) Trademark protection
C) Trade secret
D) Copyright law
Answer: C
Rationale:
A trade secret legally protects proprietary business information, such as internal algorithms and
source code, that provides a competitive edge and is actively kept confidential by the
organization.
Verified
Series:
CrashCourses Professional Study Series
Author:
Dr Z. Moomba, MBChB, MRCPsych | BethelWellness Ltd
Exam Target:
ISC2 CISSP
Year:
2025/2026
Format:
50 Questions with Verified Answers and Rationales
>
Author's Note:
This document is an original work produced for the CrashCourses Professional Study Series.
Clinical questions and professional scenarios were composed by Dr Z. Moomba based on current
exam objectives, published guidelines, and evidence-based sources (2024–2025). All patient
names, ages, and case details are fictional. Any resemblance to existing published Q&A banks is
coincidental. For personal study use only — not for reproduction or redistribution.
PART 1: CORE PRINCIPLES & FOUNDATIONS
Question 1
A Director of Information Security at a London-based fintech firm requires all customer financial
records to be secured using AES-256 on storage arrays and TLS 1.3 during network transmission.
Which fundamental element of the CIA triad is this technical implementation primarily upholding?
A) System availability
B) Repudiation prevention
C) Data confidentiality
D) Information integrity
Answer: C
,Rationale:
Data confidentiality is directly enforced by using encryption to ensure that only authorized entities
can view the plaintext information.
The explicit specification of AES-256 (for data at rest) and TLS 1.3 (for data in transit) highlights
cryptographic mechanisms designed specifically to hide data content from unauthorized access.
Information integrity is an attractive distractor, but while certain encryption modes provide
integrity checks, the primary goal of these specific ciphers in this context is maintaining secrecy
rather than just preventing unauthorized modification.
Examiner Insight: Confidentiality protects data from unauthorized read access, whereas integrity
protects data from unauthorized write or modification access. [ISC2 CBK 2024]
Question 2
During a routine compliance review, an external auditor finds that five senior infrastructure
engineers at a telecommunications company are using a single shared "admin_root" credential to
perform emergency patches on core routers. Which foundational security tenet is fundamentally
broken by this workflow?
A) Identity authentication
B) User accountability
C) Access authorization
D) Service availability
Answer: B
Rationale:
User accountability is completely nullified when a generic or shared account is utilized, as it
becomes impossible to attribute specific actions to a uniquely identifiable human being.
The phrasing "using a single shared 'admin_root' credential" clearly indicates a lack of individual
tracing, destroying the audit trail.
Identity authentication is incorrect because the engineers are indeed authenticating successfully
(they know the password); the failure is the system's inability to hold a specific person responsible
post-authentication.
High-Yield Point: True accountability requires three distinct phases: unique identification, secure
authentication, and unalterable auditing. [NIST SP 800-53 Rev. 5]
Question 3
The executive board of a global logistics enterprise is overhauling its technology governance.
They require a comprehensive framework that explicitly maps IT performance metrics to
, overarching corporate business objectives. Which of the following governance frameworks is best
suited for this strategic alignment?
A) ISO/IEC 27001
B) COBIT
C) NIST Risk Management Framework
D) COSO Framework
Answer: B
Rationale:
COBIT (Control Objectives for Information and Related Technologies) is specifically engineered to
bridge the gap between technical IT operations and high-level business strategy, providing a
robust set of performance metrics.
The requirement to map "IT performance metrics to overarching corporate business objectives" is
the defining characteristic and primary design goal of COBIT.
The COSO Framework is a tempting choice for corporate governance and financial risk, but it
lacks the specialized, IT-centric performance mapping that COBIT provides for technology
environments.
Clinical Pearl: COBIT is the gold standard for IT governance precisely because it translates
technical risks and controls into business-focused language for executive boards. [ISACA COBIT
2019]
Question 4
A cybersecurity forensic investigator identifies that an outgoing lead developer transferred a
folder containing unreleased, proprietary trading algorithms to their personal cloud drive. The firm
intends to litigate to protect these corporate secrets. Under which intellectual property concept
are these internal algorithms legally guarded?
A) Patent law
B) Trademark protection
C) Trade secret
D) Copyright law
Answer: C
Rationale:
A trade secret legally protects proprietary business information, such as internal algorithms and
source code, that provides a competitive edge and is actively kept confidential by the
organization.