CYBERSECURITY EXAM — CISSP| ULTIMATE
ENGINEERING EXAM WITH CORRECT VERIFIED
ANSWERS AND RATIONALES
1. Which security principle ensures that users can access
only the resources for which they are authorized?
A. Non-repudiation
B. Integrity
C. Confidentiality
D. Least privilege
Correct Answer: D
Rationale: Least privilege limits access rights to only what is
necessary for the user’s role.
2. Which type of attack intercepts and possibly alters
communication between two parties without their
knowledge?
A. Phishing
B. Man-in-the-middle
C. Denial-of-service
D. SQL injection
Correct Answer: B
,Rationale: MITM attacks capture and manipulate
communication.
3. In risk management, the product of threat likelihood and
impact represents:
A. Risk
B. Vulnerability
C. Exposure
D. Residual risk
Correct Answer: A
Rationale: Risk = Threat × Vulnerability × Impact.
4. Which access control model is based on users, roles, and
permissions assigned to roles?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Rule-Based Access Control
Correct Answer: C
Rationale: RBAC assigns permissions through roles,
simplifying management.
5. The primary purpose of hashing in cybersecurity is to:
,A. Encrypt data for confidentiality
B. Ensure data integrity
C. Authenticate users
D. Mask IP addresses
Correct Answer: B
Rationale: Hash functions detect changes in data without
revealing the content.
6. Which type of malware is designed to replicate itself and
spread without user action?
A. Trojan
B. Worm
C. Virus
D. Spyware
Correct Answer: B
Rationale: Worms propagate independently across
networks.
7. The principle of defense in depth primarily involves:
A. Single-layer protection
B. Multiple overlapping security controls
C. Outsourcing all security to a vendor
D. Encrypting all data only
, Correct Answer: B
Rationale: Multiple layers reduce the probability of
successful attacks.
8. In disaster recovery planning, the maximum tolerable
downtime (MTD) defines:
A. Time to restore all systems
B. Time before unacceptable consequences occur
C. Recovery point objective
D. Recovery time objective
Correct Answer: B
Rationale: MTD sets the limit of downtime tolerable for the
business.
9. Which encryption algorithm is asymmetric?
A. AES
B. RSA
C. 3DES
D. SHA-256
Correct Answer: B
Rationale: RSA uses public/private key pairs; AES and 3DES
are symmetric, SHA-256 is a hash.
ENGINEERING EXAM WITH CORRECT VERIFIED
ANSWERS AND RATIONALES
1. Which security principle ensures that users can access
only the resources for which they are authorized?
A. Non-repudiation
B. Integrity
C. Confidentiality
D. Least privilege
Correct Answer: D
Rationale: Least privilege limits access rights to only what is
necessary for the user’s role.
2. Which type of attack intercepts and possibly alters
communication between two parties without their
knowledge?
A. Phishing
B. Man-in-the-middle
C. Denial-of-service
D. SQL injection
Correct Answer: B
,Rationale: MITM attacks capture and manipulate
communication.
3. In risk management, the product of threat likelihood and
impact represents:
A. Risk
B. Vulnerability
C. Exposure
D. Residual risk
Correct Answer: A
Rationale: Risk = Threat × Vulnerability × Impact.
4. Which access control model is based on users, roles, and
permissions assigned to roles?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Rule-Based Access Control
Correct Answer: C
Rationale: RBAC assigns permissions through roles,
simplifying management.
5. The primary purpose of hashing in cybersecurity is to:
,A. Encrypt data for confidentiality
B. Ensure data integrity
C. Authenticate users
D. Mask IP addresses
Correct Answer: B
Rationale: Hash functions detect changes in data without
revealing the content.
6. Which type of malware is designed to replicate itself and
spread without user action?
A. Trojan
B. Worm
C. Virus
D. Spyware
Correct Answer: B
Rationale: Worms propagate independently across
networks.
7. The principle of defense in depth primarily involves:
A. Single-layer protection
B. Multiple overlapping security controls
C. Outsourcing all security to a vendor
D. Encrypting all data only
, Correct Answer: B
Rationale: Multiple layers reduce the probability of
successful attacks.
8. In disaster recovery planning, the maximum tolerable
downtime (MTD) defines:
A. Time to restore all systems
B. Time before unacceptable consequences occur
C. Recovery point objective
D. Recovery time objective
Correct Answer: B
Rationale: MTD sets the limit of downtime tolerable for the
business.
9. Which encryption algorithm is asymmetric?
A. AES
B. RSA
C. 3DES
D. SHA-256
Correct Answer: B
Rationale: RSA uses public/private key pairs; AES and 3DES
are symmetric, SHA-256 is a hash.