Exam style questions across every CISSP domain
Last Update 3 days ago
Total Questions : 1486
Start with our free CISSP practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real ISC 2 Credentials exam. Each CISSP exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your ISC weak domains, see where you're losing marks, and build a focused study plan in minutes.
Refer to the information below to answer the question.
A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes.
Which of the following BEST describes the access control methodology used?
Which of the following provides effective management assurance for a Wireless Local Area Network (WLAN)?
Refer to the information below to answer the question.
A new employee is given a laptop computer with full administrator access. This employee does not have a personal computer at home and has a child that uses the computer to send and receive e-mail, search the web, and use instant messaging. The organization’s Information Technology (IT) department discovers that a peer-to-peer program has been installed on the computer using the employee's access.
Which of the following solutions would have MOST likely detected the use of peer-to-peer programs when the computer was connected to the office network?
Which of the following provides the MOST protection against data theft of sensitive information when a laptop is stolen?
Which of the following is a limitation of the Common Vulnerability Scoring System (CVSS) as it relates to conducting code review?
Which of the following is a security feature of Global Systems for Mobile Communications (GSM)?
When building a data center, site location and construction factors that increase the level of vulnerability to physical threats include
An internal Service Level Agreement (SLA) covering security is signed by senior managers and is in place. When should compliance to the SLA be reviewed to ensure that a good security posture is being delivered?
The Structured Query Language (SQL) implements Discretionary Access Controls (DAC) using
What is the MOST critical factor to achieve the goals of a security program?
Which of the following is a BEST practice when traveling internationally with laptops containing Personally Identifiable Information (PII)?
During an investigation of database theft from an organization's web site, it was determined that the Structured Query Language (SQL) injection technique was used despite input validation with client-side scripting. Which of the following provides the GREATEST protection against the same attack occurring again?
Which of the following is the MOST beneficial to review when performing an IT audit?
Refer to the information below to answer the question.
A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes.
In addition to authentication at the start of the user session, best practice would require re-authentication
