ISC2 CISSP Certification Sample Questions

ISC2 CISSP Sample Questions:

01. Which of the following entities is the individual human associated with a particular set of personally identifiable information (PII)?
a) Data owner
b) Data controller
c) Data subject
d) Data processor
02. According to the (ISC)2 ethics policy, complaints must be submitted ________.
a) through the (ISC)2 website
b) in writing
c) anonymously
d) within one year of the accused infraction
03. Which of the following security instruction options offers the most potential for real-time feedback?
a) Computer-based training
b) Rote memorization
c) Live training
d) Reward mechanisms
04. Alice runs a small online retail company; many of her customers are from the United States. Currently, she accepts only blockchain-based payment, but she is considering the use of credit cards.
After investigating Payment Card Industry Data Security Standard (PCI DSS) requirements, she decides that the cost of compliance would outweigh the additional revenue.
Which of the following best describes this decision?
a) Social engineering
b) PCI DSS Merchant Level 3
c) Card verification value (CVV)
d) Risk avoidance
05. The _______ is the length of time an organization can suffer the loss of its critical path before ceasing to be a viable enterprise.
a) recovery time objective (RTO)
b) recovery point objective (RPO)
c) maximum allowable downtime (MAD)
d) annual loss expectancy (ALE)
06. Which of the following is not a common trait of DRM solutions?
a) Persistence
b) Continuous audit trail
c) Automatic expiration
d) Virtual licensing
07. Organizations in which of the following countries are not allowed to process EU citizen personal data?
a) United States
b) Singapore
c) Argentina
d) Germany
08. Which of the following is a formal, detailed description of the responsibilities between an organization and an employee?
a) Nondisclosure agreement (NDA)
b) Employment contract
c) Acceptable use policy (AUP)
d) Security policy
09. Which of the following is promulgated by senior management and outlines the organization’s strategic vision and goals?
a) Policy
b) Procedures
c) Guidelines
d) Standards
10. The business impact analysis (BIA) should consider all of the following except:
a) The value of the organization’s assets
b) Industry standards
c) Threats specific to the organization
d) The likelihood of loss


Question: 01
Answer: c
Question: 02
Answer: b
Question: 03
Answer: c
Question: 04
Answer: d
Question: 05
Answer: c
Question: 06
Answer: d
Question: 07
Answer: a
Question: 08
Answer: b
Question: 09
Answer: a
Question: 10
Answer: b

