CISSP PRACTICE TEST QUESTIONS
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
Question 1 Which of the following is NOT one of the four mandatory canons of
the ISC² (formerly International Information Systems Security Certification
Consortium) Code of Ethics?
ANSWER: Observation of information assurance local jurisdictions ✔✔
Note: The four actual canons of the ISC² Code of Ethics are:
1. Protect society, the common good, necessary public trust and confidence, and
the infrastructure.
2. Act honorably, honestly, justly, responsibly, and legally.
3. Provide diligent and competent service to principals.
4. Advance and protect the profession.
Question 2 Actively participating in ongoing information security training
classes and maintaining professional education directly validates which canon
of the ISC² Code of Ethics?
ANSWER: Advance and protect the profession ✔✔
Question 3 Regulatory laws designed to protect Personally Identifiable
Information (PII) from unauthorized access and disclosure satisfy what
primary component of the CIA Triad?
ANSWER: Confidentiality ✔✔
Question 4 Deploying redundant instances, hot sites, or failover systems for
critical organizational assets ensures the enforcement of what information
system requirement?
, ANSWER: Availability ✔✔
What management principle provides authorized system users with capabilities that
are minimal yet adequate?
least privilege
What management objectives does rotation of duties achieve?
fraud detection and cross-training
Why should management divide responsibility for critical systems between
multiple administrators?
Dividing responsibility prevents users from compromising
As your company’s CIO, your goal is to prevent any employee from having the
ability to single-handedly compromise an information system. Which activity will
satisfy this goal?
directing the system admin to create user accounts
,Who is responsible for reducing risk exposure to an organization’s supply chain?
The particular C-Level officer who oversees acquisition
What organizational role will define the value of an information resource?
Senior Management
What organizational role will administer the protection of an information system?
system admin
Which of the following is applicable under the European Union (EU) General Data
Protection Regulation (GDPR)?
Protection of PII is applicable to EU citizens outside the geographical boundaries of
the member states
Which of these rules are NOT part of Health Insurance Portability and
Accountability Act (HIPAA)?
Analysis rule
, Which of the following intellectual property protections secures a work of
authorship?
Copyright
Which of the following activities should be performed first to protect digital data
integrity during a security incident investigation?
Capture a message digest
Which of the following requires organizational compliance by its members?
policies and procedures
What is the PRIMARY objective of performing a business impact analysis?
to determine the risk exposure of an organization's critical operations
Why are security policies for organizational members critical to a security
program’s effectiveness?
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
Question 1 Which of the following is NOT one of the four mandatory canons of
the ISC² (formerly International Information Systems Security Certification
Consortium) Code of Ethics?
ANSWER: Observation of information assurance local jurisdictions ✔✔
Note: The four actual canons of the ISC² Code of Ethics are:
1. Protect society, the common good, necessary public trust and confidence, and
the infrastructure.
2. Act honorably, honestly, justly, responsibly, and legally.
3. Provide diligent and competent service to principals.
4. Advance and protect the profession.
Question 2 Actively participating in ongoing information security training
classes and maintaining professional education directly validates which canon
of the ISC² Code of Ethics?
ANSWER: Advance and protect the profession ✔✔
Question 3 Regulatory laws designed to protect Personally Identifiable
Information (PII) from unauthorized access and disclosure satisfy what
primary component of the CIA Triad?
ANSWER: Confidentiality ✔✔
Question 4 Deploying redundant instances, hot sites, or failover systems for
critical organizational assets ensures the enforcement of what information
system requirement?
, ANSWER: Availability ✔✔
What management principle provides authorized system users with capabilities that
are minimal yet adequate?
least privilege
What management objectives does rotation of duties achieve?
fraud detection and cross-training
Why should management divide responsibility for critical systems between
multiple administrators?
Dividing responsibility prevents users from compromising
As your company’s CIO, your goal is to prevent any employee from having the
ability to single-handedly compromise an information system. Which activity will
satisfy this goal?
directing the system admin to create user accounts
,Who is responsible for reducing risk exposure to an organization’s supply chain?
The particular C-Level officer who oversees acquisition
What organizational role will define the value of an information resource?
Senior Management
What organizational role will administer the protection of an information system?
system admin
Which of the following is applicable under the European Union (EU) General Data
Protection Regulation (GDPR)?
Protection of PII is applicable to EU citizens outside the geographical boundaries of
the member states
Which of these rules are NOT part of Health Insurance Portability and
Accountability Act (HIPAA)?
Analysis rule
, Which of the following intellectual property protections secures a work of
authorship?
Copyright
Which of the following activities should be performed first to protect digital data
integrity during a security incident investigation?
Capture a message digest
Which of the following requires organizational compliance by its members?
policies and procedures
What is the PRIMARY objective of performing a business impact analysis?
to determine the risk exposure of an organization's critical operations
Why are security policies for organizational members critical to a security
program’s effectiveness?