CISSP (Certified Information Systems Security Professional) — All Questions
122 questions
An ISC2-certified security manager learns that another ISC2 member at a partner firm has falsified audit evidence. Under the ISC2 Code of Ethics, what is the manager obligated to do?
- a.Follow the ISC2 ethics complaint procedure✓
- b.Warn the member privately only
- c.Notify only the member's employer
- d.Wait for a client to report a loss
The ISC2 Code of Ethics page states that members are obligated to follow the ethics complaint procedure upon observing any action by an ISC2 member that breaches the Code, and that failing to do so may itself breach Canon IV. A private warning or a report only to the employer does not meet that obligation, and nothing in the Code makes the duty wait for a client loss.
A complaint alleges that an ISC2 member failed to provide diligent and competent service to a client (Canon III). According to the ISC2 complaint procedures, who has standing to file this complaint?
- a.Any certified professional who subscribes to a code of ethics
- b.Any member of the public who learns of the conduct
- c.Only an ISC2 board member acting on its own initiative
- d.A principal, such as the member's employer or client✓
ISC2's 'Standing of Complainant' rules say any member of the public may complain about Canons I or II, only principals (those with an employer/contractor relationship with the certificate holder) may complain about Canon III, and only other professionals who subscribe to a code of ethics may complain about Canon IV. The public and fellow professionals therefore lack standing for a Canon III complaint, and the procedure is complaint-driven rather than initiated by the board.
A buyer denies having sent a signed electronic purchase order. The seller needs proof that the order originated from that buyer. Which security property is the seller relying on?
- a.Authorization
- b.Nonrepudiation✓
- c.Confidentiality
- d.Availability
RFC 4949 describes non-repudiation with proof of origin as a service that gives the recipient evidence of the data's origin, protecting against the sender falsely denying having sent it; the ISC2 outline lists nonrepudiation among the five pillars. Availability concerns timely access, confidentiality concerns preventing disclosure, and authorization concerns what an identity is permitted to do; none of them proves who sent the order.
A newly hired CISO is asked to set priorities for the security program. According to the Govern Function of NIST CSF 2.0, what should inform cybersecurity risk management first?
- a.The control list of a recently breached competitor
- b.The feature roadmap of the main security vendor
- c.The organization's mission and objectives✓
- d.The preferences of the infrastructure team
NIST CSF 2.0 outcome GV.OC-01 states that the organizational mission is understood and informs cybersecurity risk management, and the ISC2 outline asks for alignment of security to business strategy, goals, mission and objectives. A vendor roadmap, a competitor's control list or one team's preferences may be useful inputs, but none reflects this organization's own mission and risk context.
Which NIST CSF 2.0 Function covers establishing, communicating and monitoring the organization's cybersecurity risk management strategy, expectations and policy?
- a.Respond
- b.Protect
- c.Identify
- d.Govern✓
CSF 2.0 added the GOVERN (GV) Function, defined as the organization's cybersecurity risk management strategy, expectations, and policy being established, communicated, and monitored. Identify is about understanding current risks and assets, Protect is about safeguards, and Respond is about actions on a detected incident.
During a business impact analysis, the payroll owner states that the payroll process can be unavailable for at most 72 hours before the harm to the organization becomes unacceptable. What does this 72-hour figure represent?
- a.Mean time between failures (MTBF)
- b.Maximum tolerable downtime (MTD)✓
- c.Recovery point objective (RPO)
- d.Recovery time objective (RTO)
NIST SP 800-34 Rev. 1 defines MTD as the total amount of time the process can be disrupted before the impact becomes unacceptable, as determined by the business owner. RTO is the maximum time a supporting system can be down and is set so that it fits within the MTD, RPO is the point in time to which data must be recoverable, and MTBF is a reliability measure rather than a BIA tolerance.
A BIA for the online ordering process finds that card payments depend on an external payment gateway. How should the BIA treat this?
- a.Record it as a dependency and assess its recovery capability✓
- b.Replace the provider before continuing the analysis
- c.Assume it recovers as quickly as the internal order system
- d.Exclude it because the provider is responsible for its own outages
The ISC2 outline lists external dependencies as part of business continuity requirements, and NIST SP 800-34 Rev. 1 has the BIA identify the resources a process depends on so recovery priorities are realistic. Excluding the gateway or assuming its recovery time hides a single point of failure, and replacing the provider is a possible treatment after analysis, not a precondition for doing it.
A database administrator is being dismissed for cause. When should the organization disable the administrator's system access?
- a.At the end of the contractual notice period
- b.After the exit interview has been fully completed
- c.At or before the time the administrator is notified✓
- d.Once the administrator has handed over all of the work
NIST SP 800-53 Rev. 5 control PS-4 requires disabling system access upon termination within an organization-defined time period, and for a privileged user dismissed for cause that period should close the window for sabotage. Waiting for the notice period, the exit interview or a handover leaves a hostile insider with privileged access.
A consulting firm will have remote access to a customer database for six months. Which measure best establishes the consultants' security obligations?
- a.A background check carried out after the engagement ends
- b.Contract terms setting security and confidentiality duties✓
- c.A visitor badge that expires when the engagement ends
- d.A verbal briefing from the project sponsor on the first day
The ISC2 outline covers vendor, consultant and contractor agreements, and NIST SP 800-53 Rev. 5 PS-7 (External Personnel Security) calls for establishing personnel security requirements for external providers and documenting them in contracts. A verbal briefing is not enforceable, a badge controls physical entry rather than data obligations, and a background check after the work is too late to inform access.
Expected annual loss from laptop theft is $40,000. A tracking-and-encryption control costing $12,000 per year would reduce the expected annual loss to $10,000. What is the net annual value of the control?
- a.$30,000
- b.$18,000✓
- c.$2,000
- d.$28,000
Net value = loss avoided minus the control's cost: ($40,000 − $10,000) − $12,000 = $30,000 − $12,000 = $18,000. $30,000 is the loss avoided before subtracting the cost, $28,000 subtracts the cost from the original loss rather than from the reduction, and $2,000 compares the control's cost to the residual loss.
Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
A company buys a cyber insurance policy covering breach-response costs. According to NIST SP 800-39, what is true of this risk response?
- a.Harm to customers is reduced
- b.Breach likelihood goes down
- c.Only the liability shifts to the insurer✓
- d.The risky activity is removed
NIST SP 800-39 describes insurance as risk transfer and notes that risk transfer reduces neither the likelihood of harmful events occurring nor the consequences in terms of harm. Lowering likelihood is mitigation, removing the activity is avoidance, and the harm to customers is unchanged; only the financial liability moves to the insurer.
After controls are applied, the residual risk of a minor website defacement falls within the organization's documented risk tolerance. Which risk response is appropriate?
- a.Transfer the risk to an insurer
- b.Accept the risk✓
- c.Keep adding controls until the risk is zero
- d.Avoid the risk by taking the site offline
NIST SP 800-39 states that risk acceptance is the appropriate response when the identified risk is within the organizational risk tolerance. Taking the site offline removes business value to eliminate a tolerable risk, insurance is unnecessary for a risk already within tolerance, and zero risk is not an achievable or cost-effective goal.
A risk assessment shows that a planned network link between a classified enclave and the corporate network creates risk above tolerance, and no practical safeguard exists. Management replaces the link with a manual, air-gapped transfer process. Which response is this?
- a.Risk avoidance✓
- b.Risk sharing
- c.Risk transfer
- d.Risk acceptance
NIST SP 800-39 uses this very pattern as its example of risk avoidance: eliminating the networked connection and using an air gap with a manual transfer process when the risk exceeds tolerance. Acceptance would keep the link as is, and transfer or sharing would move liability or responsibility to another organization rather than removing the risky activity.
When in the development of a new customer portal is threat modeling most valuable?
- a.After the first security incident
- b.During the post-implementation audit
- c.During design, before the architecture is final✓
- d.After the penetration test report
NIST SP 800-218 (SSDF) practice PW.1 has teams use risk modeling such as threat modeling while designing software so that security requirements and mitigations shape the design. Waiting for a penetration test, an audit or an incident means design flaws are found when they are most expensive to fix.
A critical vulnerability is announced in a widely used open-source logging library. Which supplier-provided artifact would most quickly show which purchased products contain that library?
- a.A business impact analysis (BIA)
- b.A software bill of materials (SBOM)✓
- c.A certificate revocation list (CRL)
- d.A service level agreement (SLA)
NIST defines an SBOM as a formal record containing the details and supply chain relationships of the components used in building software, so it lets a buyer look up whether a product includes the vulnerable library; the ISC2 outline lists SBOMs among supply chain mitigations. An SLA sets service levels, a CRL lists revoked certificates, and a BIA ranks business processes; none enumerates software components.
Before signing with a cloud provider that will process regulated customer data, which source gives the best independent assurance about the provider's controls?
- a.The sales team's verbal assurances
- b.The provider's marketing white paper
- c.HTTPS on the provider's website
- d.An independent third-party assessment report✓
The ISC2 outline lists third-party assessment and monitoring as a supply chain risk mitigation, and NIST CSF 2.0 GV.SC-06 calls for planning and due diligence to reduce risks before entering into supplier relationships. White papers and verbal assurances are supplier self-statements, and HTTPS on a website says nothing about how customer data is protected in processing.
A controller discovers on Monday morning that a personal data breach has exposed EU customer records and is likely to pose a risk to individuals. Under GDPR Article 33, what must the controller do?
- a.Notify the authority within 30 days
- b.Notify only if a data subject complains
- c.Wait until the investigation is complete
- d.Notify the authority within 72 hours where feasible✓
GDPR Article 33(1) requires the controller to notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, giving reasons if later. Thirty days is not the GDPR deadline, and the notification is not contingent on finishing the investigation or on a complaint; Article 33(4) allows information to be provided in phases.
An EU company wants to transfer employee personal data to a service provider in a country for which the European Commission has issued an adequacy decision. What does GDPR require for this transfer?
- a.Prior approval from the supervisory authority for each transfer
- b.Explicit consent from every employee before each transfer
- c.No specific authorisation✓
- d.Binding corporate rules approved for the provider's group
GDPR Article 45(1) states that a transfer to a third country covered by an adequacy decision shall not require any specific authorisation. Consent, supervisory-authority approval and binding corporate rules are mechanisms or derogations used when no adequacy decision exists, not requirements layered on top of one.
A competitor independently writes its own code implementing the same sorting method used in your company's copyrighted software, without copying your code. Why does your copyright not stop this?
- a.Software cannot be registered for copyright
- b.It covers expression, not methods✓
- c.Copyright protection ends once software is sold
- d.Copyright only protects works that are published
17 U.S.C. 102(b) states that copyright protection does not extend to any idea, procedure, process, system or method of operation, regardless of how it is expressed; protecting a method would require a patent or trade secret approach. Sale does not end copyright, software is a literary work eligible for protection, and 104(a) makes works protected under 102 subject to protection while unpublished.
Which metric best shows whether a phishing-awareness program is changing employee behavior?
- a.Number of slides in the course
- b.Budget spent on awareness posters
- c.The trend in simulated-phishing report rates✓
- d.Number of staff who attended training
The ISC2 outline calls for program effectiveness evaluation, and NIST CSF 2.0 PR.AT outcomes aim for personnel to have the awareness to perform tasks with cybersecurity risks in mind; a rising report rate on simulations measures that behavior directly. Attendance, slide counts and spending measure activity or effort, not whether people act differently.
Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
A retailer uses a cloud payroll service that processes employee data only on the retailer's documented instructions. Under GDPR, which role does the payroll service hold?
- a.Processor✓
- b.Supervisory authority
- c.Controller
- d.Data subject
GDPR Article 4(8) defines a processor as a body that processes personal data on behalf of the controller, while Article 4(7) makes the controller the party that determines the purposes and means of processing, which here is the retailer. The employees are the data subjects, and a supervisory authority is the public regulator, not a service provider.
Who should decide how a new customer-analytics dataset is classified and what rules govern its use?
- a.The database administrator who maintains the servers
- b.The external auditor who reviews the controls
- c.The help desk that handles user access requests
- d.The information owner accountable for that data✓
NIST SP 800-37 Rev. 2 describes the information owner or steward as the official with authority for specified information and responsibility for establishing the policies governing its collection, processing, dissemination and disposal. A system administrator implements and maintains controls, the help desk executes requests, and an auditor evaluates independently; none of them owns the classification decision.
A system stores two information types. Type A is rated {C: Moderate, I: Low, A: Low}; Type B is rated {C: Low, I: High, A: Low}. Using FIPS 199, what is the system's security category?
- a.{C: Moderate, I: High, A: Low}✓
- b.{C: Low, I: High, A: Low}
- c.{C: Moderate, I: Moderate, A: Low}
- d.{C: High, I: High, A: High}
FIPS 199 assigns each security objective of a system the highest (high water mark) value among its information types, objective by objective: confidentiality takes Moderate from Type A, integrity takes High from Type B, and availability stays Low. Rating every objective High applies the single overall high-water mark to all three, the all-Moderate-and-Low answer averages rather than takes maxima, and copying Type B alone ignores Type A's confidentiality rating.
A department wants to reuse solid-state drives that held confidential data in another department. According to NIST SP 800-88 Rev. 2, which approach is most appropriate?
- a.Degauss each drive with a high-coercivity degausser
- b.Use the drive's built-in sanitize command to purge✓
- c.Overwrite free space several times with OS tools
- d.Delete the partitions and then reformat each drive
SP 800-88 Rev. 2 says purge should be used instead of clear when possible, and lists dedicated device sanitize commands including block erase and cryptographic erase as logical purge techniques that keep the device reusable. It states degaussing should not be used on non-magnetic media such as SSDs, reformatting leaves data recoverable, and overwriting through the normal interface cannot reach spare cells on wear-levelled flash.
An organization is ending a cloud storage contract and has no access to the provider's physical disks. Which purge technique does NIST SP 800-88 Rev. 2 note may be the only viable option for such logical storage?
- a.Shredding
- b.Cryptographic erase✓
- c.Degaussing
- d.Single-pass overwrite
SP 800-88 Rev. 2 states that for logical or virtual storage such as cloud storage, cryptographic erase may be the only viable purge technique, because the data owner has no direct access to the underlying physical media. Degaussing and shredding require physical possession, and an overwrite through a virtual interface is a clear technique that does not reach the abstracted physical storage.
Printed reports containing sensitive personal data must be disposed of. Which NIST SP 800-88 Rev. 2 sanitization method is appropriate for hard copy?
- a.Destroy✓
- b.Purge
- c.Clear
- d.Archive
SP 800-88 Rev. 2 states that the clear and purge methods are not appropriate for hard copy under any conditions, while destroy is appropriate for all hard copy and most information storage media. Archiving retains the data rather than sanitizing it.
An agency's security control baseline includes controls for wireless access, but the new system has no wireless capability. How should the team handle those controls under the NIST RMF?
- a.Delete the controls silently since they cannot apply
- b.Leave them as open findings in every future assessment
- c.Implement the wireless controls anyway to satisfy the baseline
- d.Scope them out during tailoring, with documented rationale✓
NIST SP 800-37 Rev. 2 Task S-2 describes tailoring the selected baseline, which includes applying scoping considerations to the remaining controls, with justification recorded for the decisions. Implementing irrelevant controls wastes resources, removing them without rationale breaks traceability, and treating them as permanent findings misstates the system's risk.
Under the HIPAA Security Rule, how long must a covered entity retain the security policies and procedures documentation it is required to maintain?
- a.Seven years from the end of the fiscal year
- b.Until the next risk analysis replaces the document
- c.Six years from creation or last effective date✓
- d.Three years from the date the document was created
45 CFR 164.316(b)(2)(i) requires retaining the documentation for 6 years from the date of its creation or the date when it last was in effect, whichever is later. Three and seven years are periods found in other regimes, and replacement by a later risk analysis does not end the retention obligation.
A business-critical application runs on an operating system whose vendor has ended security support. According to NIST SP 800-40 Rev. 4, why is continued patching not an option?
- a.End-of-life software cannot be scanned for vulnerabilities
- b.Patches for new vulnerabilities will never be released for it✓
- c.Patches for end-of-life software must be purchased individually
- d.End-of-life software is automatically disabled by the vendor
SP 800-40 Rev. 4 gives end-of-life as a reason immediate patching is not viable: the vendor no longer supports the software, so a patch will never be released; the organization must then use other risk responses such as isolation or replacement. Scanners can still detect vulnerabilities in unsupported software, and support ending does not disable the software or create a per-patch purchase path.
A new CISO finds that nobody can say which servers, laptops and cloud services the company operates. According to NIST CSF 2.0, which outcome should be established first to support asset security?
- a.A security awareness campaign for all staff
- b.A red-team exercise against the most exposed systems
- c.Maintained asset and data inventories✓
- d.A cyber insurance policy sized to the revenue
NIST CSF 2.0 Asset Management outcomes ID.AM-01, ID.AM-02 and ID.AM-07 call for maintained inventories of hardware, of software, services and systems, and of data; assets are then prioritized by classification and criticality (ID.AM-05). A red-team exercise, awareness campaign or insurance policy cannot be scoped sensibly when the organization does not know what it owns.
A team replaces customer names in a research dataset with random tokens and keeps the token-to-name table in a separate, access-controlled system. How does GDPR treat the tokenized dataset?
- a.It is anonymous data outside the scope of GDPR
- b.It becomes special-category data requiring explicit consent
- c.It is still personal data because it can be re-attributed✓
- d.It is personal data only while stored inside the EU
GDPR Article 4(5) defines this as pseudonymisation, and Recital 26 says pseudonymised data that could be attributed to a person by using additional information should be considered information on an identifiable natural person. It is therefore not anonymous, tokenization does not turn it into special-category data, and GDPR status does not depend on where the data is stored.
The marketing team wants the sign-up form to require full date of birth, although the service only needs to confirm that users are adults. Which GDPR principle does this conflict with most directly?
- a.Storage limitation
- b.Data minimisation✓
- c.Accuracy
- d.Data portability
GDPR Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary for the purposes of processing (data minimisation), and collecting a full birth date to confirm adulthood exceeds that need. Storage limitation is about how long data is kept, accuracy is about keeping data correct, and portability is a data subject right under Article 20.
In a system that enforces the Bell-LaPadula model, a process running at Secret attempts to write data into an Unclassified file. Which property blocks the write?
- a.The tranquility property
- b.The Biba integrity property
- c.The *-property✓
- d.The simple security property
RFC 4949 defines the confinement (*-) property as allowing write access only if the object's classification dominates the subject's clearance, so writing down from Secret to Unclassified is blocked to prevent leakage. The simple security property governs reading, tranquility concerns security levels not changing during processing, and Biba is a separate integrity model.
A user cleared for Confidential attempts to read a Secret document on a system enforcing Bell-LaPadula. Which rule denies the request?
- a.A Clark-Wilson certification rule
- b.The Brewer-Nash read rule
- c.The simple security property✓
- d.The *-property (confinement property)
RFC 4949 defines the simple security property as allowing read access only if the subject's clearance dominates the object's classification, so a Confidential user cannot read up to Secret. The *-property governs writing, Clark-Wilson is a commercial integrity model, and the Brewer-Nash rule addresses conflicts of interest between firms rather than clearance levels.
A laboratory system must prevent data from low-integrity sensors from being written into its high-integrity calibration records. Which model is designed for this goal?
- a.Biba✓
- b.Brewer-Nash
- c.Bell-LaPadula
- d.Take-Grant
RFC 4949 describes the Biba model as an integrity model in which each subject and object has an integrity level and a subject may not change information in an object at a higher or incomparable level. Bell-LaPadula protects confidentiality, Brewer-Nash enforces a Chinese wall against conflicts of interest, and Take-Grant models how access rights propagate.
A consultant who has read confidential files for Bank A is later blocked from opening files for Bank B, a competitor, but may still open files for an unrelated retailer. Which security model does this behavior implement?
- a.Biba
- b.Brewer-Nash✓
- c.Bell-LaPadula
- d.Clark-Wilson
RFC 4949 describes the Brewer-Nash model as enforcing the Chinese wall policy: a subject may read an object only if it is from a firm already accessed or belongs to a conflict-of-interest class the subject has not yet read from. Bell-LaPadula and Biba use fixed clearance and integrity levels, and Clark-Wilson focuses on commercial data integrity through controlled transactions.
A firewall appliance suffers a software fault. The design requires it to stop forwarding traffic rather than pass everything through unfiltered. Which design principle is being applied?
- a.Privacy by design
- b.Keep it simple and small
- c.Shared responsibility
- d.Fail securely✓
NIST SP 800-53 Rev. 5 control SC-24 requires components to fail to an organization-defined known state so that failures do not cause loss of confidentiality, integrity or availability, which the ISC2 outline lists as the fail-securely principle. Simplicity reduces attack surface, shared responsibility divides duties between a cloud provider and customer, and privacy by design embeds privacy protections; none of them defines behavior on failure.
A company moves to a zero trust architecture. Which assumption does NIST SP 800-207 reject?
- a.Access decisions can use device health and behavior
- b.Resources should be protected at a granular level
- c.Devices on the internal network can be trusted by location✓
- d.Every access request should be authenticated and authorized
NIST SP 800-207 states that zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location. Authenticating and authorizing each request, using device state and behavior in dynamic policy, and protecting resources individually are all tenets that SP 800-207 endorses.
In the NIST SP 800-207 zero trust logical architecture, which component makes and logs the decision to grant, deny or revoke access to a resource?
- a.The policy engine✓
- b.The public key infrastructure
- c.The policy enforcement point
- d.The data access policy store
SP 800-207 splits the policy decision point into the policy engine, which makes and logs the access decision, and the policy administrator, which executes it by setting up or shutting down the communication path. The policy enforcement point enables, monitors and terminates connections as instructed, while policy stores and PKI are supporting data sources, not decision makers.
A company runs its web servers on infrastructure as a service (IaaS). Which task remains the customer's responsibility under the NIST definition of IaaS?
- a.Controlling physical access to the provider's facility
- b.Replacing failed physical disks in the data center
- c.Maintaining the hypervisor on the provider's hosts
- d.Patching the guest operating systems✓
NIST SP 800-145 states that the IaaS consumer does not manage the underlying cloud infrastructure but has control over operating systems, storage and deployed applications, so guest OS patching stays with the customer. Physical disks, the virtualization layer and facility security are part of the underlying infrastructure the provider manages.
Showing 40 of 122