CISSP (Certified Information Systems Security Professional) — All Questions
14 questions
A vulnerability scan reports that a server may be vulnerable to a remote code execution flaw. What does a penetration test add that the scan does not?
- a.It rates the flaw's severity score
- b.It lists the hosts and open ports
- c.It applies the vendor patch to the server
- d.It tries to exploit the flaw to confirm it✓
NIST SP 800-115 treats penetration testing as a target vulnerability validation technique: testers try to exploit identified vulnerabilities to confirm their existence and show the impact, whereas scanning identifies potential vulnerabilities. Host and port discovery is a target identification step, patching is remediation rather than testing, and severity scoring is part of scan output.
In the NIST SP 800-115 four-phase model of penetration testing, what happens in the planning phase?
- a.Findings are rated and remediation is recommended
- b.Identified vulnerabilities are exploited to gain access
- c.Ports and services are scanned to find targets
- d.Rules and goals are set and approval documented✓
SP 800-115 states that in the planning phase rules are identified, management approval is finalized and documented, and testing goals are set, and that no actual testing occurs in this phase. Scanning belongs to the discovery phase, exploitation to the attack phase, and findings with recommendations to the reporting phase.
During an authorized penetration test, the team performs network port and service identification and compares discovered versions against vulnerability databases. According to NIST SP 800-115, which phase is this?
- a.Planning
- b.Attack
- c.Discovery✓
- d.Reporting
SP 800-115 describes the discovery phase as having two parts: information gathering and scanning, including port and service identification, followed by vulnerability analysis that compares discovered services and versions against vulnerability databases. Planning involves no testing, the attack phase tries to exploit what discovery found, and reporting documents the results.
An assessor examines a firewall's rule set for overly permissive and unused rules without sending any traffic to the firewall. How does NIST SP 800-115 classify this activity?
- a.A target identification technique
- b.A review technique✓
- c.A social engineering technique
- d.A target vulnerability validation technique
SP 800-115 groups documentation, log, ruleset and system configuration reviews as review techniques, which passively examine systems, policies and procedures. Target identification techniques actively probe the network, such as port scanning, vulnerability validation techniques such as penetration testing try to exploit weaknesses, and social engineering targets people.
Backup jobs have reported 'completed successfully' every night for a year. What provides the best evidence that data can actually be recovered?
- a.Checking that backup storage capacity is not exhausted
- b.Confirming that the backup media are stored offsite
- c.Reviewing the nightly job success messages
- d.Test restores of sample data✓
NIST SP 800-34 Rev. 1 calls for backups to be stored offsite, rotated and periodically validated, and only a test restore proves the copies are complete and usable; the ISC2 outline lists backup verification data as security process data. Job success messages, offsite storage and free capacity are all necessary but none shows that a restore will work.
A customer asks for assurance that a SaaS provider's security controls actually operated effectively over the past year, not just that they were well designed. Which report addresses this?
- a.A SOC 2 Type 2 report✓
- b.A penetration test summary from one week
- c.A SOC 2 Type 1 report
- d.The provider's own security policy
Under the AICPA SOC framework, a Type 1 report covers the description of the system and the suitability of control design as of a point in time, while a Type 2 report also covers the operating effectiveness of the controls over a period. A policy document is a self-statement, and a one-week penetration test examines exploitable weaknesses rather than whether controls operated over a year.
A researcher on your team finds a serious vulnerability in a vendor's widely used product during testing. Which course of action follows coordinated vulnerability disclosure practice?
- a.Publish full exploit details immediately to warn users
- b.Sell the details to the highest-bidding broker
- c.Report privately to the vendor, then publish after a fix✓
- d.Say nothing, since the product belongs to another company
ISO/IEC 29147 describes vulnerability disclosure in which the finder reports to the vendor, the vendor investigates and remediates, and advisories are published in coordination; the ISC2 outline lists ethical disclosure under test reporting. Immediate public release leaves users exposed with no fix, selling the details is contrary to the Code of Ethics duty to protect society, and silence leaves the flaw unaddressed.
An assessment finds that a legacy application cannot enforce multifactor authentication, and replacement is 18 months away. Which is the right way to handle this finding?
- a.A time-limited exception the risk owner approves✓
- b.Marking it closed because it cannot be fixed
- c.Leaving it out of the report to avoid confusion
- d.Letting the system administrator approve it informally
NIST SP 800-37 Rev. 2 has unremediated weaknesses tracked in a plan of action and milestones and risk accepted by the authorizing official, and SP 800-39 makes acceptance appropriate only within risk tolerance; the ISC2 outline lists exception handling in test reporting. The exception should also record compensating controls. Closing or omitting the finding hides the risk, and an administrator is not the official accountable for accepting it.
A scan produces 900 findings and the team can fix about 100 this month. According to NIST SP 800-40 Rev. 4, how should remediation be ordered?
- a.By the risk each fix removes, given asset importance✓
- b.Alphabetically by host name so no system is skipped
- c.Oldest finding first regardless of severity
- d.Easiest fixes first to reduce the total count quickly
SP 800-40 Rev. 4 says a patch may be a higher priority because deploying it would reduce cybersecurity risk more than others, and a lower priority when it addresses a low-risk vulnerability on a few low-importance assets. Alphabetical, oldest-first and easiest-first orderings reduce counts but can leave the most dangerous exposures open.
A system owner proposes that the engineers who built a system's controls should also perform the formal control assessment for its authorization. What concern does NIST SP 800-37 Rev. 2 raise?
- a.Control assessment may only happen after authorization
- b.Engineers are not allowed to read assessment plans
- c.Assessors need appropriate independence✓
- d.Assessments must always be performed by a government agency
SP 800-37 Rev. 2 Task A-1 says organizations consider both technical expertise and the level of independence required when selecting control assessors, because people assessing their own work have a conflict of interest. Engineers may read plans, assessors need not be a government agency, and assessment informs the authorization decision rather than following it.
Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
An investigator cannot build a timeline because web, database and firewall logs show the same event at times several minutes apart. Which log management practice from NIST SP 800-92 was missing?
- a.Compression of log files before archiving
- b.A common, synchronized time source✓
- c.Storage of each host's logs only on that host
- d.Rotation of log files every day at midnight
SP 800-92 identifies inconsistent timestamps as a log management challenge and recommends keeping each logging host's clock synchronized to a common time source, such as NTP servers, so events can be correlated. Compression and rotation manage storage, and keeping logs only locally makes correlation and protection harder, not easier.
An attacker who gains administrator rights on a server usually tries to erase that server's logs. Which design keeps a trustworthy record of the attacker's actions?
- a.Keeping logs only on a larger local disk
- b.Disabling logging on sensitive servers
- c.Forwarding logs to a central log server✓
- d.Letting each administrator choose what to log
NIST SP 800-92 recommends log management infrastructures with centralized log servers, which hold copies an intruder on the source host cannot easily alter. Larger local disks remain under the attacker's control, disabling logging removes the evidence entirely, and ad hoc per-administrator choices make logging inconsistent.
Which item of security process data best shows that the account deprovisioning process is working?
- a.The total number of accounts in the directory
- b.The number of password reset requests handled last month
- c.The number of new accounts created this quarter
- d.Share of leavers disabled within the policy limit✓
The ISC2 outline lists account management among security process data, and NIST SP 800-53 Rev. 5 AC-2 and PS-4 set organization-defined time periods for disabling access when users leave, so measuring timeliness against that limit tests the control. Account totals, reset counts and new-account counts describe volume, not whether leavers lose access on time.
A web application hides the 'delete invoice' button from ordinary users, and testers confirm the button is absent in the UI. Why should the test plan also call the underlying API directly?
- a.UI testing cannot be performed with automated tools
- b.APIs are not covered by any access control standard
- c.Attackers can call the API directly, skipping the UI✓
- d.APIs are faster to test than user interfaces
The OWASP Top 10 Broken Access Control category (A01 in both the 2021 and 2025 editions) states that access control is only effective when implemented in trusted server-side code or serverless APIs where the attacker cannot modify the check, and lists APIs with missing access controls as a common weakness; the ISC2 outline includes API interface testing. Speed and tooling are not the reason, and the claim that APIs fall outside access control standards is false.