CISSP (Certified Information Systems Security Professional) — All Questions
20 questions
An ISC2-certified security manager learns that another ISC2 member at a partner firm has falsified audit evidence. Under the ISC2 Code of Ethics, what is the manager obligated to do?
- a.Follow the ISC2 ethics complaint procedure✓
- b.Warn the member privately only
- c.Notify only the member's employer
- d.Wait for a client to report a loss
The ISC2 Code of Ethics page states that members are obligated to follow the ethics complaint procedure upon observing any action by an ISC2 member that breaches the Code, and that failing to do so may itself breach Canon IV. A private warning or a report only to the employer does not meet that obligation, and nothing in the Code makes the duty wait for a client loss.
A complaint alleges that an ISC2 member failed to provide diligent and competent service to a client (Canon III). According to the ISC2 complaint procedures, who has standing to file this complaint?
- a.Any certified professional who subscribes to a code of ethics
- b.Any member of the public who learns of the conduct
- c.Only an ISC2 board member acting on its own initiative
- d.A principal, such as the member's employer or client✓
ISC2's 'Standing of Complainant' rules say any member of the public may complain about Canons I or II, only principals (those with an employer/contractor relationship with the certificate holder) may complain about Canon III, and only other professionals who subscribe to a code of ethics may complain about Canon IV. The public and fellow professionals therefore lack standing for a Canon III complaint, and the procedure is complaint-driven rather than initiated by the board.
A buyer denies having sent a signed electronic purchase order. The seller needs proof that the order originated from that buyer. Which security property is the seller relying on?
- a.Authorization
- b.Nonrepudiation✓
- c.Confidentiality
- d.Availability
RFC 4949 describes non-repudiation with proof of origin as a service that gives the recipient evidence of the data's origin, protecting against the sender falsely denying having sent it; the ISC2 outline lists nonrepudiation among the five pillars. Availability concerns timely access, confidentiality concerns preventing disclosure, and authorization concerns what an identity is permitted to do; none of them proves who sent the order.
A newly hired CISO is asked to set priorities for the security program. According to the Govern Function of NIST CSF 2.0, what should inform cybersecurity risk management first?
- a.The control list of a recently breached competitor
- b.The feature roadmap of the main security vendor
- c.The organization's mission and objectives✓
- d.The preferences of the infrastructure team
NIST CSF 2.0 outcome GV.OC-01 states that the organizational mission is understood and informs cybersecurity risk management, and the ISC2 outline asks for alignment of security to business strategy, goals, mission and objectives. A vendor roadmap, a competitor's control list or one team's preferences may be useful inputs, but none reflects this organization's own mission and risk context.
Which NIST CSF 2.0 Function covers establishing, communicating and monitoring the organization's cybersecurity risk management strategy, expectations and policy?
- a.Respond
- b.Protect
- c.Identify
- d.Govern✓
CSF 2.0 added the GOVERN (GV) Function, defined as the organization's cybersecurity risk management strategy, expectations, and policy being established, communicated, and monitored. Identify is about understanding current risks and assets, Protect is about safeguards, and Respond is about actions on a detected incident.
During a business impact analysis, the payroll owner states that the payroll process can be unavailable for at most 72 hours before the harm to the organization becomes unacceptable. What does this 72-hour figure represent?
- a.Mean time between failures (MTBF)
- b.Maximum tolerable downtime (MTD)✓
- c.Recovery point objective (RPO)
- d.Recovery time objective (RTO)
NIST SP 800-34 Rev. 1 defines MTD as the total amount of time the process can be disrupted before the impact becomes unacceptable, as determined by the business owner. RTO is the maximum time a supporting system can be down and is set so that it fits within the MTD, RPO is the point in time to which data must be recoverable, and MTBF is a reliability measure rather than a BIA tolerance.
A BIA for the online ordering process finds that card payments depend on an external payment gateway. How should the BIA treat this?
- a.Record it as a dependency and assess its recovery capability✓
- b.Replace the provider before continuing the analysis
- c.Assume it recovers as quickly as the internal order system
- d.Exclude it because the provider is responsible for its own outages
The ISC2 outline lists external dependencies as part of business continuity requirements, and NIST SP 800-34 Rev. 1 has the BIA identify the resources a process depends on so recovery priorities are realistic. Excluding the gateway or assuming its recovery time hides a single point of failure, and replacing the provider is a possible treatment after analysis, not a precondition for doing it.
A database administrator is being dismissed for cause. When should the organization disable the administrator's system access?
- a.At the end of the contractual notice period
- b.After the exit interview has been fully completed
- c.At or before the time the administrator is notified✓
- d.Once the administrator has handed over all of the work
NIST SP 800-53 Rev. 5 control PS-4 requires disabling system access upon termination within an organization-defined time period, and for a privileged user dismissed for cause that period should close the window for sabotage. Waiting for the notice period, the exit interview or a handover leaves a hostile insider with privileged access.
A consulting firm will have remote access to a customer database for six months. Which measure best establishes the consultants' security obligations?
- a.A background check carried out after the engagement ends
- b.Contract terms setting security and confidentiality duties✓
- c.A visitor badge that expires when the engagement ends
- d.A verbal briefing from the project sponsor on the first day
The ISC2 outline covers vendor, consultant and contractor agreements, and NIST SP 800-53 Rev. 5 PS-7 (External Personnel Security) calls for establishing personnel security requirements for external providers and documenting them in contracts. A verbal briefing is not enforceable, a badge controls physical entry rather than data obligations, and a background check after the work is too late to inform access.
Expected annual loss from laptop theft is $40,000. A tracking-and-encryption control costing $12,000 per year would reduce the expected annual loss to $10,000. What is the net annual value of the control?
- a.$30,000
- b.$18,000✓
- c.$2,000
- d.$28,000
Net value = loss avoided minus the control's cost: ($40,000 − $10,000) − $12,000 = $30,000 − $12,000 = $18,000. $30,000 is the loss avoided before subtracting the cost, $28,000 subtracts the cost from the original loss rather than from the reduction, and $2,000 compares the control's cost to the residual loss.
Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →
A company buys a cyber insurance policy covering breach-response costs. According to NIST SP 800-39, what is true of this risk response?
- a.Harm to customers is reduced
- b.Breach likelihood goes down
- c.Only the liability shifts to the insurer✓
- d.The risky activity is removed
NIST SP 800-39 describes insurance as risk transfer and notes that risk transfer reduces neither the likelihood of harmful events occurring nor the consequences in terms of harm. Lowering likelihood is mitigation, removing the activity is avoidance, and the harm to customers is unchanged; only the financial liability moves to the insurer.
After controls are applied, the residual risk of a minor website defacement falls within the organization's documented risk tolerance. Which risk response is appropriate?
- a.Transfer the risk to an insurer
- b.Accept the risk✓
- c.Keep adding controls until the risk is zero
- d.Avoid the risk by taking the site offline
NIST SP 800-39 states that risk acceptance is the appropriate response when the identified risk is within the organizational risk tolerance. Taking the site offline removes business value to eliminate a tolerable risk, insurance is unnecessary for a risk already within tolerance, and zero risk is not an achievable or cost-effective goal.
A risk assessment shows that a planned network link between a classified enclave and the corporate network creates risk above tolerance, and no practical safeguard exists. Management replaces the link with a manual, air-gapped transfer process. Which response is this?
- a.Risk avoidance✓
- b.Risk sharing
- c.Risk transfer
- d.Risk acceptance
NIST SP 800-39 uses this very pattern as its example of risk avoidance: eliminating the networked connection and using an air gap with a manual transfer process when the risk exceeds tolerance. Acceptance would keep the link as is, and transfer or sharing would move liability or responsibility to another organization rather than removing the risky activity.
When in the development of a new customer portal is threat modeling most valuable?
- a.After the first security incident
- b.During the post-implementation audit
- c.During design, before the architecture is final✓
- d.After the penetration test report
NIST SP 800-218 (SSDF) practice PW.1 has teams use risk modeling such as threat modeling while designing software so that security requirements and mitigations shape the design. Waiting for a penetration test, an audit or an incident means design flaws are found when they are most expensive to fix.
A critical vulnerability is announced in a widely used open-source logging library. Which supplier-provided artifact would most quickly show which purchased products contain that library?
- a.A business impact analysis (BIA)
- b.A software bill of materials (SBOM)✓
- c.A certificate revocation list (CRL)
- d.A service level agreement (SLA)
NIST defines an SBOM as a formal record containing the details and supply chain relationships of the components used in building software, so it lets a buyer look up whether a product includes the vulnerable library; the ISC2 outline lists SBOMs among supply chain mitigations. An SLA sets service levels, a CRL lists revoked certificates, and a BIA ranks business processes; none enumerates software components.
Before signing with a cloud provider that will process regulated customer data, which source gives the best independent assurance about the provider's controls?
- a.The sales team's verbal assurances
- b.The provider's marketing white paper
- c.HTTPS on the provider's website
- d.An independent third-party assessment report✓
The ISC2 outline lists third-party assessment and monitoring as a supply chain risk mitigation, and NIST CSF 2.0 GV.SC-06 calls for planning and due diligence to reduce risks before entering into supplier relationships. White papers and verbal assurances are supplier self-statements, and HTTPS on a website says nothing about how customer data is protected in processing.
A controller discovers on Monday morning that a personal data breach has exposed EU customer records and is likely to pose a risk to individuals. Under GDPR Article 33, what must the controller do?
- a.Notify the authority within 30 days
- b.Notify only if a data subject complains
- c.Wait until the investigation is complete
- d.Notify the authority within 72 hours where feasible✓
GDPR Article 33(1) requires the controller to notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, giving reasons if later. Thirty days is not the GDPR deadline, and the notification is not contingent on finishing the investigation or on a complaint; Article 33(4) allows information to be provided in phases.
An EU company wants to transfer employee personal data to a service provider in a country for which the European Commission has issued an adequacy decision. What does GDPR require for this transfer?
- a.Prior approval from the supervisory authority for each transfer
- b.Explicit consent from every employee before each transfer
- c.No specific authorisation✓
- d.Binding corporate rules approved for the provider's group
GDPR Article 45(1) states that a transfer to a third country covered by an adequacy decision shall not require any specific authorisation. Consent, supervisory-authority approval and binding corporate rules are mechanisms or derogations used when no adequacy decision exists, not requirements layered on top of one.
A competitor independently writes its own code implementing the same sorting method used in your company's copyrighted software, without copying your code. Why does your copyright not stop this?
- a.Software cannot be registered for copyright
- b.It covers expression, not methods✓
- c.Copyright protection ends once software is sold
- d.Copyright only protects works that are published
17 U.S.C. 102(b) states that copyright protection does not extend to any idea, procedure, process, system or method of operation, regardless of how it is expressed; protecting a method would require a patent or trade secret approach. Sale does not end copyright, software is a literary work eligible for protection, and 104(a) makes works protected under 102 subject to protection while unpublished.
Which metric best shows whether a phishing-awareness program is changing employee behavior?
- a.Number of slides in the course
- b.Budget spent on awareness posters
- c.The trend in simulated-phishing report rates✓
- d.Number of staff who attended training
The ISC2 outline calls for program effectiveness evaluation, and NIST CSF 2.0 PR.AT outcomes aim for personnel to have the awareness to perform tasks with cybersecurity risks in mind; a rising report rate on simulations measures that behavior directly. Attendance, slide counts and spending measure activity or effort, not whether people act differently.