Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

Certified Information Systems Security Professional (CISSP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Rating
-
Sold
-
Pages
35
Grade
A+
Uploaded on
30-06-2026
Written in
2025/2026

Certified Information Systems Security Professional (CISSP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Institution
Certified Information Systems Security
Course
Certified Information Systems Security

Content preview

Certified Information Systems Security
Professional (CISSP) Questions And
Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
Question 1. An organization is establishing a new information security governance
framework. Which of the following elements is the most critical foundational
component to ensure the framework aligns with the business objectives? A.
Defining strict technical access controls for all database administrators. B.
Implementing an automated vulnerability scanning schedule. C. Securing explicit
commitment and defined roles from executive management. D. Conducting a
third-party penetration test of the external network perimeter.
Answer: C Rationale: Security governance must be driven from the top down.
Executive management commitment ensures that security strategies are aligned
with business goals, adequately funded, and properly enforced across
organizational boundaries. Without executive leadership, policies lack the
authority necessary for widespread compliance and strategic integration.
Question 2. An asset management policy requires classifying data based on
sensitivity. What is the primary purpose of data classification within a risk
management program? A. To guarantee that all data is encrypted both at rest and
in transit. B. To ensure that security controls are proportionally allocated based on
asset value and risk. C. To reduce the total volume of data stored within the
corporate data center. D. To eliminate the need for regular qualitative risk
assessments.
Answer: B Rationale: Data classification allows an organization to categorize
information assets based on the potential impact of unauthorized disclosure,

,modification, or destruction. This enables the security team to apply
appropriate, cost-effective safeguards proportional to the value and sensitivity
of the data, rather than applying uniform, expensive controls to all data
indiscriminately.
Question 3. During an internal audit, a security professional discovers that a single
system administrator has the authority to both approve a system configuration
change change-ticket and implement that same change in the production
environment. Which security principle is being violated? A. Least privilege B. Dual
control C. Separation of duties D. Need to know
Answer: C Rationale: Separation of duties requires that a critical process or
fraudulent activity cannot be completed by a single individual. By splitting the
authorization phase from the implementation phase, the organization prevents
conflicts of interest and unauthorized or accidental modifications to production
environments.
Question 4. An organization calculates that a major flood could damage its
primary data center, resulting in an estimated loss of $2,000,000. Meteorological
data suggests such a flood occurs once every 50 years in that region. What is the
calculated Annualized Loss Expectancy (ALE) for this scenario? A. $40,000 B.
$100,000 C. $400,000 D. $2,000,000
Answer: A Rationale: The Annualized Loss Expectancy (ALE) is calculated by
multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of
Occurrence (ARO). In this case, the SLE is $2,000,000 and the ARO is 1/50 (or
0.02). Multiplying $2,000,000 by 0.02 yields an ALE of $40,000.
Question 5. Following a comprehensive quantitative risk analysis, the Chief
Information Security Officer (CISO) decides to purchase a comprehensive cyber
insurance policy to cover potential losses from ransomware attacks. Which risk
handling strategy has the organization adopted? A. Risk Mitigating B. Risk
Avoidance C. Risk Acceptance D. Risk Transfer
Answer: D Rationale: Risk transfer involves shifting the financial burden of a
potential loss to a third party, such as an insurance company. This strategy does

,not eliminate the underlying vulnerability or threat, but mitigates the direct
financial impact on the organization if the adverse event occurs.
Question 6. A multi-national enterprise must comply with the European Union
General Data Protection Regulation (GDPR). Under GDPR, what is the role of an
entity that determines the purposes and means of processing personal data? A.
Data Processor B. Data Subject C. Data Controller D. Data Protection Officer
Answer: C Rationale: The GDPR defines a Data Controller as the natural or legal
person, public authority, agency, or other body which, alone or jointly with
others, determines the purposes and means of the processing of personal data.
The processor merely executes processing on behalf of the controller.
Question 7. Which of the following options represents a purely administrative
security control? A. Implementing an AI-driven Endpoint Detection and Response
(EDR) agent. B. Mandating annual security awareness training for all corporate
personnel. C. Installing a physical biometric access scanner at the server room
entrance. D. Configuring firewall rules to block inbound traffic from known
malicious IP ranges.
Answer: B Rationale: Administrative controls (also known as managerial
controls) consist of policies, procedures, training, and guidelines established by
management to define employee behavior and reduce organizational risk.
Security awareness training is a fundamental administrative control designed to
reduce human error.
Question 8. A software development firm wants to establish a framework that
provides a structured, iterative method for managing information security risks
and controls, using a Plan-Do-Check-Act cycle. Which standard series should they
primarily consult? A. NIST SP 800-53 B. ISO/IEC 27000 C. PCI DSS D. SOC 2
Answer: B Rationale: The ISO/IEC 27001 standard (part of the 27000 series)
outlines the requirements for establishing, implementing, maintaining, and
continually improving an Information Security Management System (ISMS).
Historically and conceptually, it relies heavily on the Plan-Do-Check-Act (PDCA)
continual improvement cycle.

, Question 9. An employee is terminated for violating corporate ethics policies. To
prevent retaliatory actions, the security team must ensure the employee's logical
access to all corporate systems is revoked immediately upon termination. Which
process is responsible for ensuring this occurs systematically? A. Identity
provisioning B. Offboarding C. Onboarding D. Privilege escalation
Answer: B Rationale: Offboarding is the administrative and operational process
governing the formal departure of an employee or contractor. A critical security
component of offboarding is the immediate, comprehensive revocation of all
physical and logical access privileges to protect corporate assets from
unauthorized access or malicious destruction.
Question 10. A security architect is selecting a threat modeling methodology that
categorizes threats based on six specific vectors: Spoofing, Tampering,
Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Which framework is the architect using? A. DREAD B. PASTA C. STRIDE D. OCTAVE
Answer: C Rationale: STRIDE is a threat modeling framework developed by
Microsoft. Its name is an acronym corresponding to the six threat categories it
evaluates: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of
Service, and Elevation of Privilege.
Question 11. An organization uses a mathematical formula to determine whether
to implement a specific firewall upgrade. The upgrade costs $15,000 annually. The
current risk exposure results in an ALE of $50,000. With the new firewall, the
modified ALE is projected to drop to $10,000. What is the value of this safeguard
to the organization? A. $10,000 B. $25,000 C. $35,000 D. $40,000
Answer: B Rationale: The value of a safeguard is calculated as: (ALE before
control - ALE after control) - Annual Cost of Safeguard. In this scenario, ($50,000
- $10,000) - $15,000 = $40,000 - $15,000 = $25,000. Because the result is positive,
the control provides a net financial benefit.
Question 12. Which document type provides a high-level, authoritative statement
of management's intentions, goals, and requirements regarding security, and is

Written for

Institution
Certified Information Systems Security
Course
Certified Information Systems Security

Document information

Uploaded on
June 30, 2026
Number of pages
35
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$23.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
elitelearninghub

Get to know the seller

Seller avatar
elitelearninghub Cambridge university
View profile
Follow You need to be logged in order to follow users or courses
Sold
-
Member since
3 weeks
Number of followers
0
Documents
28
Last sold
-
elitelearninghub

Welcome to elitelearninghub Welcome to elitelearninghub – your trusted source for high-quality academic and professional study materials. Our mission is to help students, job seekers, and professionals succeed by providing accurate, well-organized, and easy-to-understand study resources. Whether you\'re preparing for university exams, professional certification tests, licensing exams, or career advancement, our materials are designed to make your learning more effective and your preparation more confident. At elitelearninghub, you\'ll find: Comprehensive exam questions and answers Detailed explanations and rationales Study guides and revision notes Practice tests and mock exams Career certification preparation materials Academic resources for a wide range of subjects Every document is carefully formatted to save you time, improve your understanding, and help you perform at your best. Our goal is to provide reliable learning resources that support your academic and professional journey. Thank you for choosing elitelearninghub. We are committed to helping you study smarter, build confidence, and achieve success in your exams and career. Study Smart. Prepare Better. Succeed with Confidence.

Read more Read less
0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions