Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 53 pages
Exam (elaborations)

CISSP Exam Prep 2026 Comprehensive Information Security Certification Review Practice Questions with Detailed Rationales

Document preview thumbnail
Preview 4 out of 53 pages

CISSP Exam Prep 2026 Comprehensive Information Security Certification Review Practice Questions with Detailed Rationales

Content preview

CISSP Exam Prep 2026 Comprehensive Information
Security Certification Review Practice Questions with
Detailed Rationales

EXAM OVERVIEW
The Certified Information Systems Security Professional (CISSP) exam
validates your expertise in designing, implementing, and managing a best-in-class
cybersecurity program.

Attribute Details

Provider (ISC)²

Exam format Computer Adaptive Testing (CAT)

Number of questions 100-150 multiple-choice questions

Exam duration 3 hours

Passing score 700 out of 1000 points

Exam fee $749 USD

Validity 3 years

Prerequisites Minimum 5 years of cumulative paid work experience in 2+ of the 8 domains


Current outline April 15, 2024 (no new outline scheduled for 2026)

,DOMAIN 1: SECURITY AND RISK MANAGEMENT (16%) — Questions 1-
16


Question 1
A multinational corporation is implementing an AI-powered customer service
chatbot that processes sensitive customer data. The security team is tasked with
identifying and mitigating risks specific to this AI system. Which of the following
represents the MOST comprehensive approach to AI security governance?
A) Implement traditional security controls and conduct standard vulnerability scans
B) Establish an AI governance framework that addresses model integrity, data
poisoning, prompt injection, and algorithmic bias, integrated with the existing risk
management program
C) Deploy a firewall and intrusion detection system in front of the AI service
D) Rely solely on the AI vendor's security certifications and compliance
attestations
Answer: B
Rationale: The 2026 CISSP exam emphasizes AI security governance as a new
topic. A comprehensive approach requires establishing an AI governance
framework that addresses AI-specific risks including model integrity, data
poisoning, prompt injection attacks, algorithmic bias, and explainability. This
framework should be integrated with the organization's existing risk management
program to ensure consistent governance. Traditional security controls (Option A)
and basic network protections (Option C) do not address AI-specific threats.
Relying solely on vendor certifications (Option D) abdicates organizational
responsibility and does not account for unique deployment contexts or
configuration risks.


Question 2
A risk assessment identifies a critical vulnerability in a legacy payment processing
system. The cost to fully remediate the vulnerability is estimated at $500,000,
while the expected annual loss from a potential exploit is $200,000. The
organization has a risk appetite that tolerates moderate residual risk for non-critical
systems. Which risk response strategy is MOST appropriate?

,A) Accept the risk and monitor for changes
B) Transfer the risk through cyber insurance
C) Mitigate the risk by implementing compensating controls
D) Avoid the risk by decommissioning the system
Answer: A
Rationale: When the cost of remediation ($500,000) exceeds the expected annual
loss ($200,000), risk acceptance is the appropriate strategy, especially when the
organization's risk appetite tolerates moderate residual risk. Acceptance involves
acknowledging the risk, documenting the decision, and monitoring for changes in
the risk profile. Transfer (Option B) through insurance would still require premium
payments and may not cover all losses. Compensating controls (Option C) should
be considered but may not be cost-effective. Avoidance (Option D) would require
decommissioning a business-critical system, which is likely not feasible.


Question 3
A security manager is developing a business continuity plan (BCP) for a global
organization. The plan must address the organization's operations across multiple
regions and comply with various regulatory requirements. Which of the following
should be the FIRST step in the BCP development process?
A) Identify and prioritize critical business functions and their dependencies
B) Select recovery strategies for each critical function
C) Develop the BCP documentation and obtain executive approval
D) Test the BCP through tabletop exercises and simulations
Answer: A
Rationale: The first step in BCP development is conducting a Business Impact
Analysis (BIA) to identify and prioritize critical business functions, determine their
dependencies, and establish recovery time objectives (RTOs) and recovery point
objectives (RPOs). This foundational step informs all subsequent decisions about
recovery strategies, resource allocation, and testing. Selecting recovery strategies
(Option B) comes after understanding the requirements. Documentation and
approval (Option C) and testing (Option D) occur later in the process.

, Question 4
A Chief Information Security Officer (CISO) is evaluating the organization's
compliance posture against GDPR requirements. The organization processes
personal data of EU citizens and stores it on servers located in the United States.
Which of the following mechanisms is MOST appropriate for legitimizing this
international data transfer?
A) Standard Contractual Clauses (SCCs) approved by the European Commission
B) A data protection policy that requires all data to be encrypted
C) Consent obtained from each data subject at the time of data collection
D) Binding Corporate Rules (BCRs) for intra-group transfers
Answer: A
Rationale: For international data transfers from the EU to the US, Standard
Contractual Clauses (SCCs) approved by the European Commission are the most
widely used and practical mechanism for legitimizing the transfer when other
adequacy decisions (like the EU-US Data Privacy Framework) may not apply.
While consent (Option C) can be used, it is often difficult to manage and revoke at
scale. Encryption (Option B) addresses security but not the legal basis for transfer.
BCRs (Option D) are primarily for intra-group transfers within multinational
corporations and require extensive approval processes.


Question 5
A security architect is designing a threat modeling process for a new web
application. The team wants to identify threats early in the development lifecycle
and prioritize remediation efforts. Which threat modeling methodology is BEST
suited for identifying threats based on the system's data flows and trust boundaries?
A) STRIDE
B) DREAD
C) Attack trees
D) OCTAVE
Answer: A
Rationale: STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of Service, Elevation of Privilege) is a threat modeling methodology that
identifies threats based on the system's data flows, trust boundaries, and

Document information

Uploaded on
August 9, 2026
Number of pages
53
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
8
Followers
0
Items
2196
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions