CISSP Security Practice

Practice 60 CISSP questions across governance, risk, asset security, architecture, network security, IAM, operations, and secure development.

Level: CISSP Difficulty: advanced 60 questions 60 min
Answer each CISSP question, choose or type your answer, then review the explanation. Wrong answers are saved locally for review.
Day streak: 0 days Saved only on this device
Progress 0 / 60
Question 1

Which CISSP domain covers security governance, risk management, and legal compliance?

Select an answer
Question 2

Which access principle means users receive only the permissions required for their role?

Select an answer
Question 3

Which type of security control detects and reports a security incident?

Select an answer
Question 4

What is the primary purpose of a risk assessment?

Select an answer
Question 5

What is residual risk?

Select an answer
Question 6

Which security document states management expectations and is typically high-level?

Select an answer
Question 7

What is separation of duties designed to prevent?

Select an answer
Question 8

What is defense in depth?

Select an answer
Question 9

Which security goal protects data from unauthorized disclosure?

Select an answer
Question 10

Which security goal ensures data is not modified without authorization?

Select an answer
Question 11

Which security goal ensures systems remain accessible to authorized users?

Select an answer
Question 12

What is authentication?

Select an answer
Question 13

What is authorization?

Select an answer
Question 14

Which mechanism provides non-repudiation?

Select an answer
Question 15

What is the main purpose of cryptography?

Select an answer
Question 16

Which encryption type uses the same key for encryption and decryption?

Select an answer
Question 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

Select an answer
Question 18

What is a cryptographic hash primarily used for?

Select an answer
Question 19

Which network device filters traffic based on rules?

Select an answer
Question 20

What is a VLAN used for?

Select an answer
Question 21

Which protocol provides encrypted communication for web traffic?

Select an answer
Question 22

Which technology creates an encrypted tunnel for remote network access?

Select an answer
Question 23

What is a DMZ?

Select an answer
Question 24

Which concept describes classifying data and applying protection based on its sensitivity?

Select an answer
Question 25

What is Identity and Access Management (IAM)?

Select an answer
Question 26

What is a directory service?

Select an answer
Question 27

Which authentication factor is described as something the user knows?

Select an answer
Question 28

Which authentication factor is described as something the user has?

Select an answer
Question 29

Which authentication factor is described as something the user is?

Select an answer
Question 30

What is single sign-on (SSO)?

Select an answer
Question 31

What is multi-factor authentication?

Select an answer
Question 32

What is privileged access management?

Select an answer
Question 33

What does SIEM provide?

Select an answer
Question 34

What does SOAR stand for?

Select an answer
Question 35

What is a vulnerability scan?

Select an answer
Question 36

What is a penetration test?

Select an answer
Question 37

Which incident response activity limits the scope of an incident?

Select an answer
Question 38

What is the purpose of a business continuity plan (BCP)?

Select an answer
Question 39

What is a disaster recovery plan (DRP)?

Select an answer
Question 40

Which secure coding practice prevents injection attacks?

Select an answer
Question 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

Select an answer
Question 42

Which of the following are access control models? Select all that apply.

Select an answer
Question 43

Which of the following are authentication factors? Select all that apply.

Select an answer
Question 44

Which of the following are symmetric encryption algorithms? Select all that apply.

Select an answer
Question 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

Select an answer
Question 46

Which of the following are phases of incident response? Select all that apply.

Select an answer
Question 47

Which of the following are secure development practices? Select all that apply.

Select an answer
Question 48

Confidentiality means information is available to everyone at all times.

Select an answer
Question 49

A vulnerability is the same thing as an exploit.

Select an answer
Question 50

Data remanence is a concern when decommissioning storage media.

Select an answer
Question 51

Symmetric encryption is generally faster than asymmetric encryption.

Select an answer
Question 52

The principle of least privilege means granting all users administrator access by default.

Select an answer
Question 53

The security goal that protects data from unauthorized modification is ___.

Question 54

The process of confirming a user claimed identity is ___.

Question 55

A ___ encrypts traffic between a user and a remote network.

Question 56

The access control model that grants rights based on user roles is ___.

Question 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

Question 58

Match each security control type to its example.

Question 59

Match each cryptography concept to its purpose.

Question 60

Match each IAM concept to its meaning.