Skip to content

CISSP Certification Guide / Chapter 11

Domain 2 Practice Test: Asset Security

Twenty-five original questions spanning the inventory, the ownership roles, classification and FIPS 199, privacy and data protection law, and the retention, handling, and disposal lifecycle, with an answer key, rationales, and score-based triage rules for Domain 2.

How to take this test

This test covers everything Domain 2 taught in Chapters 8 through 10: the inventory and the shadow IT problem, the ownership roles and the accountability line, classification on the sensitivity and criticality axes, the FIPS 199 categorization model, valuation and the risk mathematics, privacy as a claim rather than a property, the GDPR and the American sectoral laws, and the retention, handling, and disposal lifecycle. Twenty-five questions is a thin sample of what a 10 percent domain can draw from, but it is a fair sample of the decision patterns, because each question here is built on the reasoning move the real exam scores, not on a fact nobody would use twice.

Set the clock to thirty minutes before you read the first stem, which is about a minute and a quarter per item, the pace this book uses for a full 150-item session. Answer every question, including the ones you are unsure of, because an unanswered item is wrong and the engine does not care how you arrived at what you submitted. Do not flip to the answer key early, and do not go back to a question you have already answered. The adaptive exam gives you no item review, and the practice that transfers is the practice that reproduces the constraint. If a question makes you guess, guess, mark the number in your head, and keep moving; the score sheet will do the analysis afterward.

One reading habit governs how you attack the stems. Before you choose, name the machinery the scenario is really testing: is this an inventory question, an ownership question, a classification question, a privacy question, or a disposal question? Most stems here are written so that two options are technically familiar and only one fits the facts as stated. When you are torn, apply the tie-breaker from Chapter 2: which option would a responsible manager defend in front of the board, with the accountable role named, the decision documented, and the standard cited? Domain 2 is the domain of named roles and named standards, and the option that names the role and the standard is usually the option that is right.

When you are done, score yourself honestly and read the score interpretation before you touch anything else. The score is a triage instrument, not a verdict. A weak result in one slice of Domain 2 tells you exactly which of the three preceding chapters to re-read, and that is worth more than the number itself.

The 25 questions

  1. An organization completes an acquisition and inherits a subsidiary whose technology estate was never governed: no inventory, no standard provisioning, and a self-hosted analytics cluster that appears in no discovery tool. The security team needs the estate to stop being a blind spot. Which approach addresses the root cause first?

    A. Isolate the subsidiary network and deploy an intrusion detection system at its border B. Encrypt every endpoint in the subsidiary before any other step C. Run continuous asset discovery, and require that every asset be inventoried with an owner from acquisition through decommissioning D. Commission a penetration test of the subsidiary’s environment before integration

  2. A customer database is breached through a misconfigured interface. The investigation confirms that the custodian executed every assigned control correctly: labeling, backups, encryption, and monitoring were all in place. Which role remains ultimately accountable for the protection of the data?

    A. The data owner B. The data custodian C. The security analyst who performed the review D. The database administrator

  3. An agency categorizes a new system under FIPS 199. The assessment rates its confidentiality impact low, its integrity impact high, and its availability impact moderate. What is the system’s overall security category?

    A. Low, because confidentiality is low B. Moderate, because availability is moderate C. High, because the highest of the three objective ratings governs D. Undetermined until the control baseline is selected

  4. Under Executive Order 13526, information whose unauthorized disclosure reasonably could be expected to cause exceptionally grave damage to the national security is classified at which level?

    A. Secret B. Confidential C. Internal D. Top Secret

  5. An order management system holds no confidential information, but the business stops the moment the system stops. Which classification logic is correct?

    A. The system should be classified high on sensitivity because the harm of an outage is severe B. The system is low on sensitivity and high on criticality, and the two axes feed classification and handling separately C. Sensitivity and criticality are two names for the same property, so the system should be high on both D. A system that holds no secrets needs no classification

  6. Under PCI DSS version 4.0, which data must not be stored after authorization, even when every other cardholder data handling control is working?

    A. The full track data, the card validation code, and the PIN or PIN block B. The primary account number C. The cardholder name and expiration date D. The cardholder’s billing address

  7. Which of the following is most likely a special category of personal data under Article 9 of the GDPR?

    A. A customer’s purchase history B. A professional profile photo displayed on a public website C. Facial recognition templates used to verify a user’s identity during authentication D. A corporate email address

  8. A company rolls out an inventory platform and populates it with every server, application, and database: location, classification, criticality, and dependencies are all recorded. The owner field is left empty because managers say filling it in slows adoption. What is the best response?

    A. Proceed, because location and classification are the fields the standard requires B. The inventory must name an owner, because ISO/IEC 27001:2022 Annex A control 5.9 requires inventories to include owners, and accountability is what turns the list into a control C. Populate the owner field with the IT department’s name for every asset D. Abandon the structured inventory and rely on network discovery scans

  9. A risk analyst is computing the single loss expectancy for a customer database. Which figure is the most defensible asset value for the arithmetic?

    A. The current market price of the server hardware that hosts the database B. The annual license cost of the database software C. The depreciated book value carried by the finance team D. The cost to recreate the data, the revenue it supports, and the fines and liability its loss would trigger

  10. A subscription service collects addresses through pre-checked consent boxes, uses the addresses for an analytics purpose that was never stated at collection, and shares them with partners the subscribers were never told about. No unauthorized access has ever occurred. Which statement is correct?

    A. The subscribers’ privacy claims were violated even though confidentiality held B. No violation occurred because no data was stolen C. The only issue is the retention schedule D. A confidentiality breach occurred because the data was misused

  11. According to NIST SP 800-122, which statement best describes PII?

    A. Only information stored in federal agency systems B. Any data that contains a person’s name C. Information that requires authentication to access D. Information that can distinguish or trace an individual’s identity, plus information that is linked or linkable to the individual, with context determining what counts

  12. A retailer collects purchase data to fulfill orders and later reuses the same data to build behavioral advertising profiles, without informing customers or establishing a lawful basis for the new use. Which GDPR principle is violated first?

    A. Data minimization B. Purpose limitation C. Storage limitation D. Accuracy

  13. A company contracts a payroll vendor. The company decides what employee data is collected and how long it is kept, and the vendor processes the data under the company’s instructions per a written agreement. Which statement correctly assigns the roles?

    A. The company is the controller and the vendor is the processor B. The vendor is the controller because it operates the processing systems C. Both parties are controllers because both touch the data D. The vendor must appoint the data protection officer

  14. Which processing scenario most clearly requires a data protection impact assessment under Article 35 of the GDPR?

    A. A small retailer processing customer names for order fulfillment B. An employer holding salary records for 200 staff in a human resources system C. A health insurer processing large volumes of patient health data D. A five-person consultancy keeping sales contacts in a customer relationship system

  15. A controller becomes aware of a personal data breach that is likely to result in a risk to the rights and freedoms of the affected individuals. What does Article 33 require?

    A. Notification to the affected individuals within 24 hours B. Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of awareness C. Notification to law enforcement before any other party D. Notification within 30 days, unless more than 500 records are involved

  16. A hospital plans to send protected health information to a cloud vendor that will store and process the data on the hospital’s behalf. What must be in place before the vendor receives the data?

    A. A business associate agreement that meets HIPAA’s requirements B. A data protection impact assessment under the GDPR C. Written consent from every patient whose data is involved D. Certification by the Department of Health and Human Services

  17. A covered entity discovers a breach of unsecured protected health information affecting 800 individuals. Under the HIPAA Breach Notification Rule, when must the entity notify the Department of Health and Human Services?

    A. Within 72 hours of discovery B. Within 30 days of discovery C. Within 60 days of discovery D. Within 60 days after the end of the calendar year

  18. A company based outside the European Union, with no office in any member state, embeds tracking code in a website that monitors the behavior of visitors located in the Union. When does the GDPR apply?

    A. Never, because the company has no establishment in the Union B. Only if the company employs more than 250 people C. Only if the company charges for its service D. When the processing relates to offering goods or services to data subjects in the Union or monitoring their behavior in the Union, regardless of where the company is established

  19. A company deploys a customer service portal configured so that, by default, every chat transcript is retained indefinitely and shared with an analytics vendor unless an administrator opts out. A DPIA concludes the configuration is incompatible with the GDPR. What is the most direct flaw?

    A. There is no breach notification plan for the portal B. No data protection officer has been appointed for the portal C. The defaults process more personal data than necessary, contrary to Article 25’s requirement that by default only necessary data is processed D. The transcripts are not pseudonymized

  20. A controller replaces customer names with tokens and stores the mapping table under strict access control. Which statement is correct?

    A. The data is pseudonymized and remains personal data subject to the GDPR, because the link to individuals still exists B. The data is anonymized and falls outside the GDPR’s scope C. Pseudonymization removes the need for a lawful basis for processing D. Because the tokens are random, the data cannot be linked back and is anonymous

  21. A company’s retention schedule calls for e-mail to be destroyed 90 days after receipt. In week six, legal is served with a complaint in a matter that could involve those messages. What must the company do?

    A. Destroy the messages on schedule, because the schedule was management-approved B. Destroy everything except the messages explicitly named in the complaint C. Suspend destruction of potentially relevant messages until the matter resolves or legal lifts the hold D. Continue destruction but keep a log for the court

  22. NIST SP 800-88 Revision 1 organizes media sanitization into which three categories?

    A. Delete, degauss, destroy B. Overwrite, erase, incinerate C. Clear, archive, dispose D. Clear, purge, destroy

  23. A team proposes degaussing a batch of solid-state drives before the drives leave the facility. What is wrong with this plan?

    A. Degaussing works on SSDs but leaves the firmware intact B. Degaussing acts on magnetic domains, so drives that store charge in flash cells will retain their data C. Degaussing is too slow to be practical for more than a few drives D. Nothing; degaussing is the standard method for every drive type

  24. A company decommissions laptops that use self-encrypting drives. The plan is crypto erase: delete the local encryption keys and reset the laptops. The drives were encrypted with validated encryption, but the recovery keys are stored in a central escrow service that the help desk uses to unlock laptops remotely. What is the flaw?

    A. The escrowed recovery key copies survive the local deletion, so the data remains recoverable B. Self-encrypting drives cannot be crypto-erased C. Crypto erase works only on spinning hard drives D. Decommissioned laptops may not be resold regardless of sanitization

  25. A cloud team deletes the current version of an object containing customer data from an object store. Under what circumstances can the data still exist?

    A. The data is gone once the current version pointer is removed B. The data survives only if the bucket is publicly readable C. The data survives only if the provider has failed its service obligations D. Prior object versions, snapshots, automated backups, or replicas can still hold copies of the data

Answer key

Question Answer Question Answer
1 C 14 C
2 A 15 B
3 C 16 A
4 D 17 C
5 B 18 D
6 A 19 C
7 C 20 A
8 B 21 C
9 D 22 D
10 A 23 B
11 D 24 A
12 B 25 D
13 A

Rationales

  1. C. The root cause is the inventory gap, and the control family for it is discovery plus an owner-bearing inventory with records created at acquisition and removed at decommissioning, the discipline of NIST SP 800-53 CM-8 and ISO/IEC 27001:2022 Annex A control 5.9, with CM-8(3)’s automated detection of unauthorized components as the ongoing mechanism. Segmentation and encryption protect assets the organization already knows about (options A and B), and a penetration test finds exploitable weaknesses, not ungoverned assets (option D).

  2. A. Accountability never transfers. The custodian executes the controls, but the data owner decides classification, approves access, and answers for the protection of the data, so a flawless custodian does not move the line of accountability. The analyst reviews and the administrator operates (options C and D), and the custodian implements (option B), but the owner is the accountable party.

  3. C. Under FIPS 199, the overall security category is the high-water mark, the highest of the three objective ratings, so a system with high integrity impact is a high-impact system regardless of the other two. The category is not the low or moderate rating (options A and B), and it is determined before control selection, which is what the category drives (option D).

  4. D. Executive Order 13526 sets three levels distinguished by expected damage from unauthorized disclosure: Confidential for damage, Secret for serious damage, and Top Secret for exceptionally grave damage. “Internal” is a commercial scheme class name, not an EO 13526 level (option C), and the other two are mismatched to the damage description (options A and B).

  5. B. Sensitivity is the harm from unauthorized disclosure, and criticality is the harm from loss or unavailability, separate axes that both feed classification and handling. The system is low on sensitivity, it holds no secrets, and high on criticality, the business stops without it. Raising the sensitivity class (option A), collapsing the axes (option C), or skipping classification (option D) all misread the scenario.

  6. A. PCI DSS version 4.0 defines cardholder data as the primary account number plus, in combination, the cardholder name, expiration date, or service code, and treats the full track data, the card validation code, and the PIN or PIN block as sensitive authentication data that must not be stored after authorization. The PAN (option B) is stored only under the standard’s protections, the name and expiration date are cardholder data (option C), and the billing address is not part of the definition (option D).

  7. C. Article 9 lists biometric data processed for the purpose of uniquely identifying a natural person among the special categories, so facial recognition templates used to verify identity are special category data. Purchase history (option A), a profile photo that is not used for unique identification (option B), and a corporate email address (option D) are ordinary personal data in these contexts.

  8. B. ISO/IEC 27001:2022 Annex A control 5.9 requires the inventory of information and other associated assets to include owners, and the owner is what makes the list an accountability structure rather than a catalog. Location and classification alone (option A) miss the requirement, a generic IT owner (option C) names nobody accountable, and dropping the structured inventory (option D) removes the control instead of fixing it.

  9. D. Asset value for risk mathematics is the full business meaning of the asset: the cost to recreate the data, the revenue it supports, and the fines and liability its loss would trigger, which is the figure that feeds SLE equals asset value times exposure factor. Hardware price, license cost, and depreciated book value (options A, B, and C) omit the components that make the arithmetic meaningful.

  10. A. Privacy is a claim held by a person about how their information is collected, used, and shared, and it can be violated with no confidentiality failure: pre-checked consent is not a clear affirmative act, the analytics use drifted from the stated purpose, and the sharing was undisclosed. Option B treats theft as the only harm, option C ignores the collection and use violations, and option D mistakes a privacy failure for a confidentiality breach.

  11. D. NIST SP 800-122 defines PII as information that can distinguish or trace an individual’s identity, such as name, social security number, or biometric records, plus information that is linked or linkable to the individual, such as medical, educational, financial, or employment information, and the definition is contextual. PII is not limited to government systems (option A), a name alone may not be PII (option B), and authentication is not the test (option C).

  12. B. Purpose limitation under Article 5(1)(b) requires collection for specified, explicit, and legitimate purposes and forbids further processing incompatible with those purposes. Order fulfillment and behavioral advertising are different purposes, so the reuse violates purpose limitation first, compounded by the missing lawful basis. Minimization, storage, and accuracy (options A, C, and D) are secondary or unrelated here.

  13. A. Article 4(7) defines the controller as the party that determines the purposes and means of processing, and Article 4(8) defines the processor as the party that processes on the controller’s behalf. The company decides what is collected and how long it is kept, so it is the controller and the vendor is the processor. Operating the systems does not make the vendor the controller (option B), shared access is not joint controllership (option C), and the DPO requirement is a separate statutory trigger (option D).

  14. C. Article 35 requires a DPIA where processing is likely to result in a high risk to rights and freedoms, with a mandatory case being large-scale processing of special categories, and patient health data is a special category under Article 9. Order names, salary records for 200 staff, and a small CRM (options A, B, and D) do not reach the high-risk threshold the mandatory cases describe.

  15. B. Article 33 requires the controller to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a breach that is likely to result in a risk to rights and freedoms. Individual notification under Article 34 applies only when the risk is high and does not come first (option A), there is no police-first priority (option C), and the 30-day and 500-record thresholds belong to no GDPR provision (option D).

  16. A. HIPAA allows a covered entity to share protected health information with a business associate only under a business associate agreement that meets the regulatory requirements, which must be in place before the data flows. A DPIA is a GDPR instrument, not a HIPAA one (option B), consent is not required for every claim-related disclosure (option C), and HHS does not certify individual vendors (option D).

  17. C. Under the HIPAA Breach Notification Rule, a breach affecting 500 or more individuals must be reported to the Department of Health and Human Services within 60 days of discovery; individuals must be notified without unreasonable delay and no later than 60 days. The 72-hour figure belongs to the GDPR (option A), 30 days matches no HIPAA deadline (option B), and the year-end deadline applies to smaller breaches (option D).

  18. D. Article 3(2) extends the GDPR to controllers and processors outside the Union when their processing relates to offering goods or services to data subjects in the Union or to monitoring the behavior of data subjects in the Union, so establishment is not the test. Options A, B, and C each import a test, no EU office, headcount, or payment, that the regulation does not use.

  19. C. Article 25 requires data protection by design and by default: by default, only personal data necessary for each specific purpose is processed, especially regarding the amount collected, the period of storage, and accessibility. A portal that retains everything indefinitely and shares it unless someone opts out inverts that requirement. A breach plan (option A) is a separate duty, a DPO may not be required at all here (option B), and pseudonymization (option D) is a measure, not the core default failure.

  20. A. Article 4(5) defines pseudonymization as replacing identifying attributes so the data cannot be attributed to a specific subject without additional information kept separately, and pseudonymized data remains personal data subject to the GDPR because the link exists. Anonymization, which irreversibly removes the link, is the operation that exits the regime (option B), tokens with a mapping table are not anonymous (option D), and a lawful basis is still required (option C).

  21. C. Once litigation is reasonably anticipated, the duty to preserve suspends scheduled destruction of potentially relevant records, and the hold outranks every retention schedule; destroying held records is spoliation. The approved schedule (option A), selective destruction (option B), and deletion with a log (option D) all continue the destruction the hold forbids.

  22. D. NIST SP 800-88 Revision 1 organizes sanitization into clear, purge, and destroy, the three categories selected by the confidentiality of the information and the media type. Delete, degauss, overwrite, erase, incinerate, archive, and dispose (options A, B, and C) are techniques and lifecycle words, not the standard’s categories.

  23. B. Degaussing works by randomizing magnetic domains and applies only to magnetic media. Solid-state drives store data as electrical charge in flash cells, so a magnetic field leaves the data intact and the drives would leave the facility with recoverable data. Options A, C, and D misstate the mechanism, the practical speed, or the method’s scope.

  24. A. Crypto erase is valid only when the key material is truly gone, and the escrow copies held for remote help desk unlocks survive the local key deletion, so the data remains recoverable. Validated encryption is a precondition, not a disqualifier (option B), crypto erase applies to SSDs as well as hard drives (option C), and properly sanitized laptops can be resold (option D).

  25. D. Cloud data multiplies into object versions, snapshots, automated backups, and replicas, so deleting the current version’s pointer leaves those copies untouched. The failure is an inventory gap, not provider negligence (option C), and public readability (option B) has nothing to do with whether the copies exist.

Reading your Domain 2 score

Score yourself against the bands Chapter 1 set for every domain test in this book:

Score Verdict Action
0–14 (below 60%) The domain’s concepts have not landed. Re-read Chapters 8 through 10, redo all of their practice questions, and retake this test in three to five days.
15–19 (60–80%) The concepts are mostly there. Review only the rationales you missed, redo those questions until you can explain each rationale aloud, and keep Domain 2 in weekly spaced review.
20–25 (above 80%) The domain is in good shape. One weekly review pass. Spend the reclaimed hours on weaker domains.

The single number hides the information you need, so break the misses down by area. Domain 2 is a composite of three very different disciplines, and the triage that matters is the triage at the topic level:

Area Questions If you missed 2 or more
Inventory, ownership, classification, valuation 1–9 Re-read Chapter 8: the shadow IT control family, the owner and custodian line, the sensitivity and criticality axes, FIPS 199, and asset valuation.
Privacy and data protection 10–20 Re-read Chapter 9: privacy versus confidentiality, PII, the GDPR’s roles and articles, the American sectoral laws, and the DPIA.
Retention, handling, and disposal 21–25 Re-read Chapter 10: the retention drivers, the litigation hold, the NIST SP 800-88 categories, and the media-by-media disposal map.

Two habits make the score useful. First, log the result and the area misses on your score sheet, because the full practice exam in Chapter 33 will re-test this domain and you want the comparison. Second, treat a miss pattern as a question about process, not just facts. If the misses cluster on questions where you picked a technically familiar option that did not fit the facts, your problem is stem reading, and the fix is to name the machinery, inventory, role, class, or lifecycle step, before you look at the options. If the misses cluster on questions with named standards, FIPS 199, NIST SP 800-88, Article 9, your problem is source recall, and the fix is to redraw the standard’s structure cold, without the chapter open.

What the score means for your plan

Domain 2 carries 10 percent of the current outline’s weight, the smallest single slice of the eight domains, and that is exactly why candidates under-train it. But the domain’s ideas carry everywhere else: the inventory is the substrate of incident response in Domain 7, classification feeds the access decisions of Domain 5, and privacy shows up again in the breach notification clock when operations meets the GDPR’s 72 hours. A candidate who skips asset security because it is light on weight is skipping the vocabulary every other domain speaks.

Pass this test at the level your score band demands and you have earned the right to move to Part IV with confidence. Fail it, and you have earned something rarer: a precise list of what to re-read. Either way, the score sheet is now the authority on where your Domain 2 hours go. The next chapter opens Domain 3, Security Architecture and Engineering, with the design principles and architecture models that decide how the assets you have just classified get engineered into a defensible system: least privilege, defense in depth, trust boundaries, the reference monitor, and the Zero Trust model.