CISSP PRACTICE EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE
Core Domains
1. Security and Risk Management
2. Asset Security
3. Security Architecture and Engineering
4. Communication and Network Security
5. Identity and Access Management (IAM)
6. Security Assessment and Testing
7. Security Operations
8. Software Development Security
Introduction
This comprehensive practice examination is meticulously designed to mirror the rigor and scope of the Certified
Information Systems Security Professional (CISSP) certification exam. It serves as a vital tool for assessing a candidate's
mastery of the eight domains of the (ISC)² Common Body of Knowledge (CBK). The assessment evaluates not only
foundational theory and technical knowledge but also the practical application of security principles in complex, real-
world scenarios. Candidates will be challenged to apply critical thinking and sound decision-making skills to solve
multifaceted problems, ensuring they are fully prepared for the demands of a senior-level security leadership role. This
test bank provides detailed rationales to solidify understanding and reinforce key concepts.
SECTION ONE: QUESTIONS 1 – 100
,Question 1
Which of the following is the PRIMARY purpose of conducting a Business Impact Analysis (BIA) within the context of
Business Continuity Planning (BCP)?
A. To identify all potential threats and vulnerabilities to the organization's assets.
B. To prioritize business functions and determine the potential impact of their disruption.
C. To develop and document the detailed recovery procedures for each critical system.
D. To assign recovery teams and define their roles and responsibilities during a crisis.
🟢B
🔴 Explanation: The primary purpose of a BIA is to identify and prioritize critical business functions and processes by
quantifying the potential impact (financial, operational, legal, etc.) of their disruption. This prioritization informs the
recovery time objectives (RTOs) and recovery point objectives (RPOs). While identifying threats (A) is part of risk
assessment, developing procedures (C) is part of the plan development, and assigning teams (D) is part of the plan's
organizational structure, these are all downstream activities driven by the BIA's core mission.
Question 2
An organization is implementing a new security policy and needs to ensure that employees understand their
responsibilities. What is the MOST effective method to achieve this?
A. Send a company-wide email with the policy attached.
B. Post the policy on the internal corporate intranet.
C. Provide mandatory, role-based training sessions with a knowledge check.
D. Have each employee sign an acknowledgement form without prior training.
🟢C
🔴 Explanation: Mandatory, role-based training is the most effective method because it ensures that all employees
are actively educated on the policy's specifics, their individual responsibilities, and the consequences of non-
compliance. A knowledge check verifies comprehension. An email (A) or intranet post (B) is passive and does not
,guarantee the information is read or understood. An acknowledgement form (D) confirms receipt but not
understanding, which is insufficient for enforcing accountability.
Question 3
A security architect is designing a network for a financial institution. Which of the following is the BEST approach to
protect a web server that must be accessible from the internet?
A. Place the web server on the internal network behind a stateful firewall.
B. Place the web server in a screened subnet (DMZ) with strict firewall rules.
C. Disable all unused ports and services on the web server.
D. Install a host-based intrusion detection system (HIDS) on the web server.
🟢B
🔴 Explanation: Placing the web server in a DMZ is the best practice for publicly accessible servers. The DMZ acts as
a buffer zone between the untrusted internet and the trusted internal network. Strict firewall rules can then be
applied to allow only necessary traffic (e.g., HTTP/HTTPS) to the server and to control the traffic that can originate
from the server to the internal network. While (C) and (D) are good security hardening practices, they are not as
comprehensive as network segmentation. Placing it on the internal network (A) is a direct violation of the principle
of least privilege and exposes internal assets to significant risk.
Question 4
Which of the following types of controls is a security awareness campaign for employees considered to be?
A. Administrative
B. Technical
C. Physical
D. Detective
🟢A
🔴 Explanation: A security awareness campaign is an administrative (or managerial) control because it is a policy,
, procedure, or program implemented to manage and guide employee behavior. Administrative controls are people-
oriented. Technical controls (B) are implemented via hardware and software. Physical controls (C) are physical
barriers like fences and locks. Detective controls (D) are designed to identify and record security events after they
occur, whereas awareness is a preventive measure.
Question 5
What is the fundamental difference between a threat and a vulnerability?
A. A threat is a weakness, while a vulnerability is a potential danger.
B. A threat is a potential danger, while a vulnerability is a weakness.
C. A threat is a countermeasure, while a vulnerability is an asset.
D. A threat is a realized risk, while a vulnerability is a risk assessment.
🟢B
🔴 Explanation: A threat is any potential danger to an asset, such as a malicious hacker (a threat agent) or a natural
disaster. A vulnerability is a weakness or flaw in a system, process, or control that could be exploited by a threat to
cause harm. The combination of a threat and a vulnerability creates a risk. (A) reverses the definitions. (C) confuses
the terms with countermeasures and assets. (D) incorrectly defines them as a realized risk and a risk assessment,
respectively.
Question 6
An organization is implementing a data classification scheme. Which of the following is the MOST critical factor in
determining the classification level of a dataset?
A. The volume of the data.
B. The age of the data.
C. The potential impact to the organization if the data is compromised.
D. The cost incurred to acquire the data.
RATIONALES | GUARANTEED PASS | LATEST EXAM UPDATE
Core Domains
1. Security and Risk Management
2. Asset Security
3. Security Architecture and Engineering
4. Communication and Network Security
5. Identity and Access Management (IAM)
6. Security Assessment and Testing
7. Security Operations
8. Software Development Security
Introduction
This comprehensive practice examination is meticulously designed to mirror the rigor and scope of the Certified
Information Systems Security Professional (CISSP) certification exam. It serves as a vital tool for assessing a candidate's
mastery of the eight domains of the (ISC)² Common Body of Knowledge (CBK). The assessment evaluates not only
foundational theory and technical knowledge but also the practical application of security principles in complex, real-
world scenarios. Candidates will be challenged to apply critical thinking and sound decision-making skills to solve
multifaceted problems, ensuring they are fully prepared for the demands of a senior-level security leadership role. This
test bank provides detailed rationales to solidify understanding and reinforce key concepts.
SECTION ONE: QUESTIONS 1 – 100
,Question 1
Which of the following is the PRIMARY purpose of conducting a Business Impact Analysis (BIA) within the context of
Business Continuity Planning (BCP)?
A. To identify all potential threats and vulnerabilities to the organization's assets.
B. To prioritize business functions and determine the potential impact of their disruption.
C. To develop and document the detailed recovery procedures for each critical system.
D. To assign recovery teams and define their roles and responsibilities during a crisis.
🟢B
🔴 Explanation: The primary purpose of a BIA is to identify and prioritize critical business functions and processes by
quantifying the potential impact (financial, operational, legal, etc.) of their disruption. This prioritization informs the
recovery time objectives (RTOs) and recovery point objectives (RPOs). While identifying threats (A) is part of risk
assessment, developing procedures (C) is part of the plan development, and assigning teams (D) is part of the plan's
organizational structure, these are all downstream activities driven by the BIA's core mission.
Question 2
An organization is implementing a new security policy and needs to ensure that employees understand their
responsibilities. What is the MOST effective method to achieve this?
A. Send a company-wide email with the policy attached.
B. Post the policy on the internal corporate intranet.
C. Provide mandatory, role-based training sessions with a knowledge check.
D. Have each employee sign an acknowledgement form without prior training.
🟢C
🔴 Explanation: Mandatory, role-based training is the most effective method because it ensures that all employees
are actively educated on the policy's specifics, their individual responsibilities, and the consequences of non-
compliance. A knowledge check verifies comprehension. An email (A) or intranet post (B) is passive and does not
,guarantee the information is read or understood. An acknowledgement form (D) confirms receipt but not
understanding, which is insufficient for enforcing accountability.
Question 3
A security architect is designing a network for a financial institution. Which of the following is the BEST approach to
protect a web server that must be accessible from the internet?
A. Place the web server on the internal network behind a stateful firewall.
B. Place the web server in a screened subnet (DMZ) with strict firewall rules.
C. Disable all unused ports and services on the web server.
D. Install a host-based intrusion detection system (HIDS) on the web server.
🟢B
🔴 Explanation: Placing the web server in a DMZ is the best practice for publicly accessible servers. The DMZ acts as
a buffer zone between the untrusted internet and the trusted internal network. Strict firewall rules can then be
applied to allow only necessary traffic (e.g., HTTP/HTTPS) to the server and to control the traffic that can originate
from the server to the internal network. While (C) and (D) are good security hardening practices, they are not as
comprehensive as network segmentation. Placing it on the internal network (A) is a direct violation of the principle
of least privilege and exposes internal assets to significant risk.
Question 4
Which of the following types of controls is a security awareness campaign for employees considered to be?
A. Administrative
B. Technical
C. Physical
D. Detective
🟢A
🔴 Explanation: A security awareness campaign is an administrative (or managerial) control because it is a policy,
, procedure, or program implemented to manage and guide employee behavior. Administrative controls are people-
oriented. Technical controls (B) are implemented via hardware and software. Physical controls (C) are physical
barriers like fences and locks. Detective controls (D) are designed to identify and record security events after they
occur, whereas awareness is a preventive measure.
Question 5
What is the fundamental difference between a threat and a vulnerability?
A. A threat is a weakness, while a vulnerability is a potential danger.
B. A threat is a potential danger, while a vulnerability is a weakness.
C. A threat is a countermeasure, while a vulnerability is an asset.
D. A threat is a realized risk, while a vulnerability is a risk assessment.
🟢B
🔴 Explanation: A threat is any potential danger to an asset, such as a malicious hacker (a threat agent) or a natural
disaster. A vulnerability is a weakness or flaw in a system, process, or control that could be exploited by a threat to
cause harm. The combination of a threat and a vulnerability creates a risk. (A) reverses the definitions. (C) confuses
the terms with countermeasures and assets. (D) incorrectly defines them as a realized risk and a risk assessment,
respectively.
Question 6
An organization is implementing a data classification scheme. Which of the following is the MOST critical factor in
determining the classification level of a dataset?
A. The volume of the data.
B. The age of the data.
C. The potential impact to the organization if the data is compromised.
D. The cost incurred to acquire the data.