Question 1
An organization's leadership implements security controls based on industry best practices but never reviews them again. This represents:
Show answer & explanation
Correct answer: A - Due care without due diligence
10 free, exam-style Certified Information Systems Security Professional (CISSP) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CISSP practice test to study every exam domain.
An organization's leadership implements security controls based on industry best practices but never reviews them again. This represents:
Correct answer: A - Due care without due diligence
The Data Custodian is PRIMARILY responsible for:
Correct answer: B - Operating systems and protecting the data
A user with Top Secret clearance attempts to write a document classified at the Confidential level. Under the Bell-LaPadula model, the result is:
Correct answer: D - Denied by the star (★) property
The "harvest now, decrypt later" attack model assumes that:
Correct answer: C - Encrypted data captured today may be decrypted by future quantum computers
WPA2 is vulnerable to which notable attack on its 4-way handshake?
Correct answer: B - KRACK attack
A common security mistake in modern web architecture is to:
Correct answer: B - Treat OAuth 2.0 as an authentication protocol
A SOC 2 report focuses on which Trust Services Criteria?
Correct answer: C - Security, Availability, Processing Integrity, Confidentiality, Privacy
An analyst disconnects an infected host from the network during an active incident. According to the NIST SP 800-61 incident response lifecycle, this action is BEST classified as:
Correct answer: C - Containment of the threat
A development team needs to determine whether their application is exposed to the Log4Shell vulnerability (CVE-2021-44228). Which testing approach is BEST suited to find this exposure?
Correct answer: D - SCA scanning of third-party dependencies
A race condition exploit known as TOCTOU specifically targets:
Correct answer: D - The gap between time-of-check and time-of-use
Practice hundreds more CISSP questions with instant scoring, weak-area drills, and full exam simulations.