CISSP (Certified Information Systems Security Professional) — All Questions
12 questions
A retailer uses a cloud payroll service that processes employee data only on the retailer's documented instructions. Under GDPR, which role does the payroll service hold?
- a.Processor✓
- b.Supervisory authority
- c.Controller
- d.Data subject
GDPR Article 4(8) defines a processor as a body that processes personal data on behalf of the controller, while Article 4(7) makes the controller the party that determines the purposes and means of processing, which here is the retailer. The employees are the data subjects, and a supervisory authority is the public regulator, not a service provider.
Who should decide how a new customer-analytics dataset is classified and what rules govern its use?
- a.The database administrator who maintains the servers
- b.The external auditor who reviews the controls
- c.The help desk that handles user access requests
- d.The information owner accountable for that data✓
NIST SP 800-37 Rev. 2 describes the information owner or steward as the official with authority for specified information and responsibility for establishing the policies governing its collection, processing, dissemination and disposal. A system administrator implements and maintains controls, the help desk executes requests, and an auditor evaluates independently; none of them owns the classification decision.
A system stores two information types. Type A is rated {C: Moderate, I: Low, A: Low}; Type B is rated {C: Low, I: High, A: Low}. Using FIPS 199, what is the system's security category?
- a.{C: Moderate, I: High, A: Low}✓
- b.{C: Low, I: High, A: Low}
- c.{C: Moderate, I: Moderate, A: Low}
- d.{C: High, I: High, A: High}
FIPS 199 assigns each security objective of a system the highest (high water mark) value among its information types, objective by objective: confidentiality takes Moderate from Type A, integrity takes High from Type B, and availability stays Low. Rating every objective High applies the single overall high-water mark to all three, the all-Moderate-and-Low answer averages rather than takes maxima, and copying Type B alone ignores Type A's confidentiality rating.
A department wants to reuse solid-state drives that held confidential data in another department. According to NIST SP 800-88 Rev. 2, which approach is most appropriate?
- a.Degauss each drive with a high-coercivity degausser
- b.Use the drive's built-in sanitize command to purge✓
- c.Overwrite free space several times with OS tools
- d.Delete the partitions and then reformat each drive
SP 800-88 Rev. 2 says purge should be used instead of clear when possible, and lists dedicated device sanitize commands including block erase and cryptographic erase as logical purge techniques that keep the device reusable. It states degaussing should not be used on non-magnetic media such as SSDs, reformatting leaves data recoverable, and overwriting through the normal interface cannot reach spare cells on wear-levelled flash.
An organization is ending a cloud storage contract and has no access to the provider's physical disks. Which purge technique does NIST SP 800-88 Rev. 2 note may be the only viable option for such logical storage?
- a.Shredding
- b.Cryptographic erase✓
- c.Degaussing
- d.Single-pass overwrite
SP 800-88 Rev. 2 states that for logical or virtual storage such as cloud storage, cryptographic erase may be the only viable purge technique, because the data owner has no direct access to the underlying physical media. Degaussing and shredding require physical possession, and an overwrite through a virtual interface is a clear technique that does not reach the abstracted physical storage.
Printed reports containing sensitive personal data must be disposed of. Which NIST SP 800-88 Rev. 2 sanitization method is appropriate for hard copy?
- a.Destroy✓
- b.Purge
- c.Clear
- d.Archive
SP 800-88 Rev. 2 states that the clear and purge methods are not appropriate for hard copy under any conditions, while destroy is appropriate for all hard copy and most information storage media. Archiving retains the data rather than sanitizing it.
An agency's security control baseline includes controls for wireless access, but the new system has no wireless capability. How should the team handle those controls under the NIST RMF?
- a.Delete the controls silently since they cannot apply
- b.Leave them as open findings in every future assessment
- c.Implement the wireless controls anyway to satisfy the baseline
- d.Scope them out during tailoring, with documented rationale✓
NIST SP 800-37 Rev. 2 Task S-2 describes tailoring the selected baseline, which includes applying scoping considerations to the remaining controls, with justification recorded for the decisions. Implementing irrelevant controls wastes resources, removing them without rationale breaks traceability, and treating them as permanent findings misstates the system's risk.
Under the HIPAA Security Rule, how long must a covered entity retain the security policies and procedures documentation it is required to maintain?
- a.Seven years from the end of the fiscal year
- b.Until the next risk analysis replaces the document
- c.Six years from creation or last effective date✓
- d.Three years from the date the document was created
45 CFR 164.316(b)(2)(i) requires retaining the documentation for 6 years from the date of its creation or the date when it last was in effect, whichever is later. Three and seven years are periods found in other regimes, and replacement by a later risk analysis does not end the retention obligation.
A business-critical application runs on an operating system whose vendor has ended security support. According to NIST SP 800-40 Rev. 4, why is continued patching not an option?
- a.End-of-life software cannot be scanned for vulnerabilities
- b.Patches for new vulnerabilities will never be released for it✓
- c.Patches for end-of-life software must be purchased individually
- d.End-of-life software is automatically disabled by the vendor
SP 800-40 Rev. 4 gives end-of-life as a reason immediate patching is not viable: the vendor no longer supports the software, so a patch will never be released; the organization must then use other risk responses such as isolation or replacement. Scanners can still detect vulnerabilities in unsupported software, and support ending does not disable the software or create a per-patch purchase path.
A new CISO finds that nobody can say which servers, laptops and cloud services the company operates. According to NIST CSF 2.0, which outcome should be established first to support asset security?
- a.A security awareness campaign for all staff
- b.A red-team exercise against the most exposed systems
- c.Maintained asset and data inventories✓
- d.A cyber insurance policy sized to the revenue
NIST CSF 2.0 Asset Management outcomes ID.AM-01, ID.AM-02 and ID.AM-07 call for maintained inventories of hardware, of software, services and systems, and of data; assets are then prioritized by classification and criticality (ID.AM-05). A red-team exercise, awareness campaign or insurance policy cannot be scoped sensibly when the organization does not know what it owns.
Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
A team replaces customer names in a research dataset with random tokens and keeps the token-to-name table in a separate, access-controlled system. How does GDPR treat the tokenized dataset?
- a.It is anonymous data outside the scope of GDPR
- b.It becomes special-category data requiring explicit consent
- c.It is still personal data because it can be re-attributed✓
- d.It is personal data only while stored inside the EU
GDPR Article 4(5) defines this as pseudonymisation, and Recital 26 says pseudonymised data that could be attributed to a person by using additional information should be considered information on an identifiable natural person. It is therefore not anonymous, tokenization does not turn it into special-category data, and GDPR status does not depend on where the data is stored.
The marketing team wants the sign-up form to require full date of birth, although the service only needs to confirm that users are adults. Which GDPR principle does this conflict with most directly?
- a.Storage limitation
- b.Data minimisation✓
- c.Accuracy
- d.Data portability
GDPR Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary for the purposes of processing (data minimisation), and collecting a full birth date to confirm adulthood exceeds that need. Storage limitation is about how long data is kept, accuracy is about keeping data correct, and portability is a data subject right under Article 20.