• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

Isc2 Cissp Certified Information Systems Security Professional Actual Exam 2026/2027 Questions With Verified Answers & Complete Rationales

Document preview thumbnail
Preview 3 out of 22 pages

Isc2 Cissp Certified Information Systems Security Professional Actual Exam 2026/2027 Questions With Verified Answers & Complete Rationales

Content preview

1 | Page



ISC2 CISSP CERTIFIED INFORMATION
SYSTEMS SECURITY PROFESSIONAL
ACTUAL EXAM 2026/2027 QUESTIONS
WITH VERIFIED ANSWERS & COMPLETE
RATIONALES

**1. An organization discovers that a senior administrator has
been accessing highly sensitive customer records without a
documented business need. The administrator's account is
legitimately provisioned and authentication logs show
successful MFA. Which security principle is MOST directly
being violated?**


A. Separation of duties
B. Least privilege
C. Defense in depth
D. Need to know


**Correct answer:** B


**Rationale:** Least privilege requires users to receive only the
permissions necessary to perform their assigned
responsibilities. The administrator has legitimate access but is
using privileges beyond what is required for the job. Need to
know is related but focuses specifically on access to

,2 | Page

information rather than the broader set of privileges and
permissions .


---


**2. A security architect is designing controls for an application
that processes highly confidential information. Management
wants controls that remain effective even if one security
mechanism fails. Which architecture BEST represents this
requirement?**


A. Single sign-on
B. Compensating control
C. Defense in depth
D. Security through obscurity


**Correct answer:** C


**Rationale:** Defense in depth uses multiple independent or
complementary security controls so that failure of one control
does not result in complete security failure. For example,
network segmentation, strong authentication, encryption,
monitoring, and endpoint controls can collectively protect the
same information .


---

, 3 | Page



**3. During a risk assessment, a company identifies a
vulnerability with a potential annualized loss expectancy of
$180,000. A proposed control costs $75,000 annually and is
expected to reduce the expected loss by 70%. What is the
BEST conclusion?**


A. The control should automatically be implemented because it
reduces risk
B. The control should automatically be rejected because it
costs money
C. The organization should compare the expected risk
reduction with the control cost and consider other qualitative
factors
D. The organization should transfer the entire risk to the control
provider


**Correct answer:** C


**Rationale:** Security decisions should be based on risk and
business context rather than simply whether a control reduces
risk. A 70% reduction of $180,000 represents approximately
$126,000 in expected annual loss reduction, compared with a
$75,000 annual control cost. The resulting quantitative benefit
is favorable, but operational, legal, strategic, and
implementation considerations should also be evaluated .


---

Document information

Uploaded on
October 7, 2026
Number of pages
22
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TRUSTEDHUB
4.1
(11)
Sold
76
Followers
0
Items
4894
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions