Skip to content

CISSP Certification Guide / Chapter 33

Full Practice Exam I: Questions 1–63

The first sitting of the book's complete 125-question practice exam: 63 original questions at the current blueprint weights across all eight domains, run as one timed session, with per-domain scoring, a full answer key, and a rationale for every question.

How to run this exam

This chapter is the first sitting of the full practice exam: 63 questions at the current blueprint weights, with the second sitting, questions 64 through 125, in Chapter 34. The domains appear in the proportions the public outline assigns. Domain 1 carries 10 questions, Domain 2 carries 6, Domains 3 through 7 carry 8 each, and Domain 8 carries 7. The real exam interleaves domains and never tells you which domain an item tests, so the section headings here are a scoring convenience, not a simulation of the interface. Take the run the way Chapter 32 prescribes: read the question line first, name the shape and the qualifier, kill what you can kill, choose among survivors with the decision hierarchy, confirm, and move.

Set the clock for ninety minutes before you read the first stem. That is the real exam’s working pace: 125 items in 180 minutes is about 1.4 minutes per item, so 63 items at that pace is roughly 91 minutes, and ninety is a fair round number to hold. Apply the two-minute cap per item from Chapter 32. Answer every question, including the ones that force a guess. No skipping, no review, no returning, no notes, no phone, no comfort stop in the middle. The adaptive engine from Chapter 2 offers none of those things, and the practice that transfers is the practice that reproduces the constraint.

When the clock stops, keep the key closed. Score the run honestly, first the total and then the per-domain count using the section headings. Then apply the thresholds from Chapter 1: below 60 percent in a domain sends that domain through the re-read, redo, retest loop; 60 to 80 percent earns targeted rationale review; above 80 percent gets one weekly pass. The per-domain number is the instrument that says where the remaining study hours go, and the specific questions you missed say which ideas to rebuild first.

If one ninety-minute sitting is impossible, split the exam at a domain boundary and write the split on the score sheet. The scoring stays honest; the fatigue simulation does not, and you should know that the last-hour discipline from Chapter 32 is exactly what the split run does not train.

Domain 1: Security and Risk Management (Questions 1–10)

  1. A database is valued at $2,000,000. A risk analysis estimates that a major breach would destroy 25 percent of the database’s value, and that such a breach is expected to occur once every four years. What is the annualized loss expectancy (ALE)?

    A. $500,000 B. $1,250,000 C. $2,000,000 D. $125,000

  2. A company calculates that the controls needed to prevent a specific threat would cost more than the probable financial loss from that threat over the same period, and the threat carries no legal or reputational obligation the company must satisfy. Per ISO 31000:2018, which risk treatment is BEST aligned with the framework?

    A. Mitigate the risk anyway, because every risk must be reduced B. Transfer the risk by purchasing insurance C. Accept the risk, with the decision documented by the accountable owner D. Avoid the risk by eliminating the activity

  3. An organization wants its information security objectives to align with its business requirements. Per ISO/IEC 27001:2022, who carries the primary accountability for leadership and commitment to the information security management system?

    A. The chief information security officer alone B. Top management C. The external certification auditor D. The security operations center manager

  4. A European retailer discovers that an attacker exfiltrated customer personal data from its payment systems. Under the GDPR (Regulation (EU) 2016/679), what is the general breach notification obligation?

    A. Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach B. Notify the supervisory authority within 30 calendar days C. Notify data subjects before the supervisory authority in every case D. Notify no one unless the exfiltrated data was encrypted

  5. During a risk review, someone must decide whether to accept a residual risk in a legacy application. Per ISO 31000:2018, who should own that decision?

    A. The IT administrator who maintains the application B. The vendor of the application C. The insurance broker who priced the risk D. The person accountable for the risk, typically the owner of the asset or business process

  6. A logistics company’s order system can tolerate losing up to 4 hours of transactions and must be fully operational within 24 hours of a disruption. Which pair of objectives should the company specify?

    A. RPO of 24 hours, RTO of 4 hours B. RTO of 4 hours, RPO of 24 hours C. RPO of 4 hours, RTO of 24 hours D. MTD of 4 hours, RPO of 24 hours

  7. A security team wants to enforce that every password reset checks the new secret against a list of known compromised values. At which level of the policy hierarchy does this operational detail belong?

    A. The standard or procedure that specifies how the policy’s requirements are met B. The security policy, because compliance is mandatory C. The executive board’s mission statement D. The vendor’s default configuration guide

  8. A CISSP holder learns that a contractor in the holder’s industry has repeatedly misrepresented employees’ certifications in bids. Per the ISC2 Code of Ethics, which action best honors the holder’s obligations?

    A. Bring the matter to the attention of the appropriate authorities or stakeholders who can act on it, in line with the canon to act honorably and to disclose situations that could violate the Code, the law, or the organization’s policies B. Post the contractor’s records on a public forum so customers can see them C. Do nothing, because the matter is outside the holder’s employer D. Confront the contractor’s chief executive personally and demand a retraction

  9. An organization hires a contractor for six months to handle customer support data. Which set of controls BEST aligns with personnel security practice?

    A. A verbal confidentiality promise and access to every customer record B. Monitoring the contractor’s personal devices only C. Background screening proportional to the role, a signed confidentiality agreement, need-to-know access, and deprovisioning at the end of the contract D. Permanent administrator rights so the contractor can work unsupervised

  10. A merchant isolates its cardholder data environment (CDE) behind a firewall. Per PCI DSS v4.0, which statement is correct?

    A. Segmentation removes the CDE from the scope of the assessment entirely B. Segmentation can reduce the scope, but systems that store, process, or transmit cardholder data, or that can affect the security of the CDE, remain in scope and must still meet the requirements C. Only the payment gateway is in scope for the assessment D. Buying a compliant firewall satisfies the requirement set

Domain 2: Asset Security (Questions 11–16)

  1. In a data governance framework, a vice president of marketing is accountable for the accuracy, classification, and use of the customer profile data her division produces. Which role does she hold?

    A. Data custodian B. System administrator C. Business owner of the data D. Data processor under a contract

  2. A company labels its payroll database “restricted” and its public website “public”. Which statement about classification is correct?

    A. Classification reflects the value and sensitivity of the data and drives the minimum set of controls applied to it, and labels can change as value changes B. The label determines which firewall model to buy C. Public data needs no integrity protection because it is public D. Classification is a one-time event that never needs review

  3. An organization is decommissioning magnetic hard drives that held confidential customer data. Per NIST SP 800-88 Rev 1, which statement is correct?

    A. Deleting the files empties the data from the drive permanently B. Degaussing works on all media types, including optical disks C. A licensed recycler’s pickup form is sufficient proof of sanitization D. The recognized sanitization options are clear, purge, and destroy, and the right choice depends on the media and the confidentiality of the data

  4. A clinic keeps patient records 10 years per state law, its insurer requires incident reports retained 7 years, and its own operations policy says 12 years. Which retention schedule is correct?

    A. The longest applicable period, 12 years per operations policy, provided it covers the legal and contractual minimums; retention schedules consolidate the applicable legal, regulatory, contractual, and operational drivers B. The shortest period, because storage costs money C. 7 years, because that is what the insurer requires D. Retention is decided ad hoc as records age

  5. Per NIST SP 800-122, which item is personally identifiable information (PII)?

    A. The serial number of a company-owned server B. A person’s name paired with their Social Security number C. The IP address of a public web server D. The floor plan of an office building

  6. An analyst must work with confidential customer data on a laptop while traveling. Which combination BEST protects the data in use?

    A. Encryption of the marketing brochures on the laptop B. Keeping the laptop powered on so the data stays in memory C. A privacy screen, a lock screen that engages on session inactivity, and access through a controlled application or virtual desktop rather than unrestricted local copies D. Printing the data and carrying it in a folder

Domain 3: Security Architecture and Engineering (Questions 17–24)

  1. In a Bell-LaPadula multilevel system, a subject with secret clearance reads a document labeled top secret. Which rule is violated?

    A. The *-property, which prohibits writing up B. The simple security property, which prohibits reading up C. The Biba read-down rule D. The Clark-Wilson well-formed transaction rule

  2. Which statement correctly describes the Biba integrity model?

    A. It prohibits reading up and writing down, mirroring Bell-LaPadula for integrity B. It focuses on separation of duties in commercial transactions C. It prohibits reading down and writing up, so high-integrity subjects do not process low-integrity data D. It requires dual control for every access

  3. A security kernel must enforce the reference monitor concept. Which three properties must it satisfy?

    A. Least privilege, need to know, and dual control B. Confidentiality, integrity, and availability as measurable metrics C. Authentication, authorization, and non-repudiation as features D. Complete mediation, tamperproofness (isolation), and verifiability

  4. A product is evaluated under the Common Criteria per ISO/IEC 15408. Which statement is correct?

    A. Evaluation Assurance Levels EAL1 through EAL7 describe increasing assurance that the security functions are correctly implemented and tested; they do not certify specific features or freedom from all flaws B. An Evaluation Assurance Level of EAL7 guarantees the product has no vulnerabilities C. The vendor may assign its own evaluation assurance level D. Common Criteria certification replaces penetration testing permanently

  5. Per FIPS 197, which statement about AES is correct?

    A. AES is a stream cipher with a fixed 64-bit key B. AES is an asymmetric algorithm used for key exchange C. AES encrypts data but cannot decrypt it D. AES is a symmetric block cipher with a 128-bit block size and key sizes of 128, 192, and 256 bits

  6. Per FIPS 180-4, which property makes SHA-256 useful for verifying file integrity?

    A. The digest can be decrypted with the sender’s private key B. The digest is the same length as the input C. Any change to the input produces, with overwhelming probability, a different digest, and the function is one-way D. Two different messages with the same digest are easy to find

  7. In a digital signature scheme, which key operation produces and verifies a signature?

    A. Sign with the recipient’s public key; verify with the recipient’s private key B. Sign with the sender’s private key; verify with the sender’s public key C. Sign with a shared symmetric key; verify with the same key D. Sign with the sender’s public key; verify with the sender’s private key

  8. Per NIST SP 800-207, which statement best describes the core assumption of a Zero Trust architecture?

    A. Users inside the corporate perimeter are always trusted B. Network location alone is not a basis for trust, and access decisions evaluate identity, device posture, and other attributes for every request C. Zero Trust requires moving every workload to the cloud D. Zero Trust replaces authentication with encryption

Domain 4: Communication and Network Security (Questions 25–32)

  1. A network analyst explains where TLS 1.3 (RFC 8446) sits in the protocol stack. Which statement is correct?

    A. TLS operates at the network layer, encrypting IP packets B. TLS operates at the physical layer C. TLS operates between the application and transport layers, functionally mapped to the presentation layer of the OSI model D. TLS replaces IPsec at the network layer

  2. A company separates its payment systems from employee workstations so direct traffic between the zones is blocked except through managed gateways. Which concept does this implement?

    A. Load balancing across the zones B. Network segmentation and isolation to limit lateral movement C. DNS caching between the zones D. Bandwidth throttling on the gateways

  3. In IPsec per RFC 4301, which statement correctly distinguishes AH and ESP?

    A. AH provides confidentiality; ESP provides integrity only B. Both provide confidentiality by default C. AH provides integrity and origin authentication without confidentiality, while ESP provides confidentiality plus integrity protection D. ESP is used only for IPv6 traffic

  4. An organization upgrades its wireless network to WPA3. Which security property is the main gain?

    A. The network no longer encrypts traffic, improving performance B. The network reverts to WEP for compatibility with older devices C. The passphrase is broadcast in cleartext to simplify onboarding D. Simultaneous Authentication of Equals (SAE) replaces the pre-shared key handshake that allowed offline dictionary attacks, and management frame protection is enforced

  5. A remote employee needs secure access to corporate resources over an untrusted network. Which solution provides an authenticated, encrypted tunnel?

    A. Telnet to the corporate gateway B. Port forwarding on the employee’s home router C. A remote-access VPN using IPsec or TLS, with the endpoint authenticated before the tunnel carries traffic D. A shared drive mapped over the internet without encryption

  6. A security team wants to stop attackers from forging DNS responses so users are redirected to a fake site. Per RFC 4033, which mechanism provides this protection?

    A. Encrypting all DNS queries with TLS B. DNSSEC, which signs DNS records so validating resolvers can confirm origin and integrity C. Caching DNS responses for longer D. Blocking port 53

  7. A company deploys port-level network access control: the switch keeps the port blocked until the device authenticates with a central server. Which technology stack matches this design?

    A. MAC flooding to open the port B. ARP poisoning of the gateway C. IEEE 802.1X with EAP, with the switch as authenticator and a RADIUS server (per RFC 2865) as the authentication decision point D. DHCP starvation on the segment

  8. An e-commerce site is under a volumetric DDoS attack that saturates its internet link. Which mitigation is MOST effective at keeping the site reachable?

    A. A firewall rule that drops the packets after the link is saturated B. Lowering the DNS TTL so records refresh faster C. A DDoS mitigation service or scrubbing center that absorbs and filters the traffic upstream before it reaches the site’s own connection D. Disabling the web server to end the attack

Domain 5: Identity and Access Management (Questions 33–40)

  1. Which authentication combination uses two different categories of evidence?

    A. A password and a security question B. A smart card and a PIN C. Two different passwords D. A fingerprint and a voiceprint

  2. Per NIST SP 800-63B, which set of practices best supports memorized secret security?

    A. Screening new secrets against lists of known compromised values, allowing long secrets, and rate-limiting authentication attempts B. Forced rotation every 60 days with strict composition rules C. Storing secrets in plaintext so users can be reminded of them D. Fixing secret length at exactly 8 characters

  3. A biometric system’s acceptance threshold is lowered so more samples are accepted. Which effect follows?

    A. The false accept rate falls and the false reject rate rises B. Both rates rise C. Both rates fall D. The false accept rate rises and the false reject rate falls

  4. A data platform evaluates access with a policy that reads: allow read when subject.department equals finance and object.classification equals internal and time is within business hours. Which access control model does this implement?

    A. Discretionary access control B. Attribute-based access control, per the policy-based model described in NIST SP 800-162 C. Mandatory access control with security labels D. Rule-based access control only

  5. Per RFC 4120, in Kerberos, what does a client receive from the Authentication Service and later present to the Ticket-Granting Service?

    A. A ticket-granting ticket B. A client certificate signed by a public certification authority C. A one-time code from a hardware token D. A biometric template captured at login

  6. Partner company employees need to access your SaaS application using their own corporate identity, without your creating a local account per person. Which approach fits best?

    A. Federated identity: the partner’s identity provider asserts the user’s identity to your application using a standard such as SAML 2.0 or OpenID Connect B. Creating a local account for each partner employee with a shared password C. Trusting whatever email address the user types at login D. Using each employee’s MAC address as their identity

  7. An employee transfers from sales to engineering. Which access lifecycle activity is required?

    A. Nothing, until the next audit B. Only removing the old accounts C. Creating a new account with the same password as the old one D. Reviewing and adjusting access to match the new role: revoking sales-only rights no longer needed and provisioning the rights the new role requires

  8. A database administrator needs privileged access to a production database for a one-hour maintenance window. Which privileged access management practice fits best?

    A. Permanent membership in the database administrators group B. Just-in-time elevation for the window with automatic expiry, plus session recording so the activity is attributable C. Sharing the database root password by email D. Granting the administrator access to every employee account

Domain 6: Security Assessment and Testing (Questions 41–48)

  1. Per PCI DSS v4.0, which schedule describes the vulnerability scanning and penetration testing requirements?

    A. One penetration test replaces all vulnerability scanning B. Internal and external vulnerability scans on a defined periodic schedule, with external scans quarterly, plus annual penetration testing and testing after significant changes C. Scanning once at deployment is sufficient D. PCI DSS requires no testing of in-scope systems

  2. Before a penetration test, the tester and the organization agree on the systems in scope, the techniques allowed, and the times testing may occur. What is this agreement called?

    A. Certificate of destruction B. Chain of custody C. Rules of engagement D. Service-level objective

  3. A developer wants to find injection flaws in source code before the application is built. Which technique fits best?

    A. A penetration test against the production environment B. Fuzzing the compiled binary with random input C. A port scan of the build server D. Static application security testing (SAST), which analyzes source code without executing it

  4. A QA engineer feeds malformed, unexpected inputs to an input parser and observes the results. Which technique is this?

    A. Baseline scanning B. Fuzzing C. Code review D. Social engineering

  5. Per NIST SP 800-92, which practice best preserves the usefulness and integrity of audit logs?

    A. Local logs with no access control on each host B. Deleting logs after 24 hours C. Allowing users to delete their own log entries D. Centralized collection with protected, append-only or write-once storage, synchronized clocks, and regular review for anomalies

  6. Per NIST SP 800-137, what is the purpose of information security continuous monitoring?

    A. Maintaining ongoing awareness of the security posture, including changes, vulnerabilities, and threats, so the organization can respond in a timely way B. Replacing all periodic audits permanently C. Producing daily reports that are never read D. Restricting all internet access from the corporate network

  7. A SOC reports the average time between a security event occurring and the team detecting it. Which metric is this?

    A. Mean time to repair (MTTR) B. Mean time to detect (MTTD) C. Recovery time objective (RTO) D. Annualized rate of occurrence (ARO)

  8. An application in staging is exercised over HTTP with crafted requests designed to trigger common flaws. Which technique is this?

    A. Static source analysis B. Threat modeling at design time C. Dynamic application security testing (DAST) D. Perimeter scanning of the staging network

Domain 7: Security Operations (Questions 49–56)

  1. Per NIST SP 800-61 Rev 2, which sequence describes the incident response lifecycle?

    A. Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity B. Detection; Notification; Remediation; Close C. Prevention; Purchase; Install; Report D. Preparation happens only after an incident occurs

  2. During an investigation, the analyst captures memory contents before imaging disks. Which principle does this follow?

    A. The chain of custody rule, which requires memory first B. Disk imaging is optional and may be skipped C. The order of volatility: capture the most volatile data first (per RFC 3227) D. Memory is erased after the disk is imaged

  3. Which practice is essential to preserving the admissibility of forensic evidence?

    A. Documenting every transfer of custody with identity, date, and purpose, and protecting the evidence from alteration B. Storing evidence on a shared drive where anyone can edit it C. Copying files with the operating system’s file manager D. Discussing the case on public forums

  4. An attacker encrypts an organization’s files with ransomware. Which control is MOST effective at limiting the damage?

    A. Paying the ransom quickly B. Offline or immutable backups with tested restoration, plus segmentation and least-privilege access that limit how far an infection spreads C. Disabling endpoint protection so the encryption is not detected D. Granting all users administrator rights

  5. A backup strategy must survive the destruction of the primary site. Which combination best addresses this requirement?

    A. Backups stored in the same rack as the servers B. A second copy at an offsite location, restoration tested on a schedule, and a recovery point objective that bounds the acceptable data loss C. A single copy on the same disk as the source data D. Manual backups made by each employee

  6. Which physical control is designed to prevent tailgating at a secured entrance?

    A. A backup generator B. A fire suppression system C. Cable locks on workstations D. A mantrap with interlocking doors

  7. A team plans to change a production firewall rule on Friday afternoon. Which is the BEST approach per change management?

    A. Submit the change for approval, test it in a non-production environment, schedule it with a backout plan, and document the outcome B. Apply the rule directly because the change is small C. Make the change during the busiest traffic hours so it is tested under load D. Skip change management because the window is short

  8. Which statement correctly characterizes disaster recovery site options?

    A. A cold site can resume operations within minutes B. All site types resume operations at the same speed C. Disaster recovery sites exist only for storing backups D. A hot site is fully equipped to resume operations quickly, a warm site has partial readiness, and a cold site provides space and infrastructure requiring longer setup

Domain 8: Software Development Security (Questions 57–63)

  1. In which phase of the SDLC is a security requirements defect most expensive to correct?

    A. At requirements or design time B. In production, after release C. During coding D. The cost is identical in every phase

  2. A web application concatenates user input directly into SQL statements, and an attacker submits ’ OR ‘1’=‘1. Per the OWASP Top 10, which defense is MOST effective?

    A. More verbose error messages B. Parameterized queries or prepared statements C. Disabling the audit log D. A longer session timeout

  3. Which statement correctly distinguishes stored cross-site scripting (XSS) from cross-site request forgery (CSRF)?

    A. XSS delivers attacker-controlled script that executes in the victim’s browser; CSRF tricks the victim’s browser into sending an authenticated request the victim did not intend B. XSS is a network-layer flaw and CSRF is an application-layer flaw C. Both attacks require the attacker to compromise the server first D. CSRF injects script and XSS forges requests

  4. A developer renders user-supplied comments on a web page. Which control BEST prevents script injection at render time?

    A. Removing the comments feature entirely B. Increasing the page timeout C. Encrypting the session cookie D. Context-appropriate output encoding or escaping of the user input when it is displayed

  5. A team wants to catch vulnerabilities as early as possible in the CI/CD pipeline. Which practice best supports shift-left security?

    A. Testing security only at the annual audit B. Relying on the production firewall C. Running static analysis in the build stage, scanning dependencies, and gating the pipeline so vulnerable builds do not proceed D. Removing code review to speed up releases

  6. A team wants a machine-readable inventory of the open-source components in its application so it can identify known vulnerable components. Which artifact provides this?

    A. A software bill of materials (SBOM), commonly expressed in formats such as SPDX or CycloneDX B. A network diagram C. A certificate inventory D. A firewall rule set

  7. An application depends on a library with a publicly disclosed critical vulnerability (a CVE). Which is the BEST response?

    A. Ignore the finding because the library is open source B. Suppress the vulnerability report C. Rewrite the entire application immediately D. Update to a patched version if one exists; if patching is not immediately feasible, apply compensating controls, track the finding for remediation, and reassess on a schedule

Score your run before you open the key

The answer key and the rationales are below. Do not open them until you have finished the ninety-minute run and written your totals. Score two ways. First the total: count correct answers and convert to a percentage. Then the per-domain count: use the section headings, and convert each domain’s raw score against its own question count, which is 10 for Domain 1, 6 for Domain 2, 8 for Domains 3 through 7, and 7 for Domain 8. Apply the thresholds from Chapter 1: below 60 percent in a domain means the re-read, redo, retest loop for that domain; 60 to 80 percent means targeted rationale review; above 80 percent means one weekly pass. Record both the total and the per-domain numbers on your score sheet, because Chapter 35’s readiness review is built from them.

Answer key

Question Answer Question Answer Question Answer
1 D 2 C 3 B
4 A 5 D 6 C
7 A 8 A 9 C
10 B 11 C 12 A
13 D 14 A 15 B
16 C 17 B 18 C
19 D 20 A 21 D
22 C 23 B 24 B
25 C 26 B 27 C
28 D 29 C 30 B
31 C 32 C 33 B
34 A 35 D 36 B
37 A 38 A 39 D
40 B 41 B 42 C
43 D 44 B 45 D
46 A 47 B 48 C
49 A 50 C 51 A
52 B 53 B 54 D
55 A 56 D 57 B
58 B 59 A 60 D
61 C 62 A 63 D

Rationales

  1. D. The single-loss expectancy (SLE) is the asset value times the exposure factor: $2,000,000 × 0.25 equals $500,000. The annualized rate of occurrence (ARO) is one breach every four years, 0.25 per year. The annualized loss expectancy (ALE) is SLE times ARO: $500,000 × 0.25 equals $125,000. The $500,000 figure is the SLE and the other options are the asset value and a distractor; only the ALE folds the annual frequency into the loss.

  2. C. ISO 31000:2018 treats risk treatment as a decision among options that include retaining the risk, and the framework’s principle is proportionality: treatment should be proportionate to the risk and the context. Where the controls cost more than the probable loss and no obligation compels mitigation, documented acceptance by the accountable owner is the framework-aligned response. Mitigation regardless of economics contradicts the cost logic, insurance is a transfer option the scenario gives no basis for, and avoidance eliminates an activity the business may need.

  3. B. ISO/IEC 27001:2022 clause 5.1 assigns leadership and commitment for the information security management system to top management: setting the objectives, ensuring alignment with the strategic direction, and providing the resources. The chief information security officer and the SOC manager execute and operate the program, and the certification auditor evaluates it; the standard’s accountability sits with top management.

  4. A. GDPR Article 33 requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. The 30-day figure is not the breach rule, data subjects are notified when the breach is likely to result in high risk to them (Article 34), not always before the authority, and encryption is a mitigating factor in the risk assessment, not a license to stay silent.

  5. D. ISO 31000:2018 assigns risk accountability to the risk owner, the person accountable for managing the risk, typically the owner of the asset or the business process. The administrator maintains the system, the vendor supplies it, and the broker prices transfer; none of them can accept residual risk on the business’s behalf. Acceptance is a documented decision made at the accountable level.

  6. C. The recovery point objective (RPO) bounds acceptable data loss: the system can tolerate losing 4 hours of transactions, so the RPO is 4 hours. The recovery time objective (RTO) bounds the time to restore service: the system must be operational within 24 hours, so the RTO is 24 hours. Options A and B swap the definitions, and maximum tolerable downtime (MTD) is a related but different figure, the total interruption the business can survive.

  7. A. The policy hierarchy puts statements of intent in the policy and the operational method in standards and procedures. Checking new secrets against breach lists is a how, a concrete mechanism that implements the policy’s requirement for secure credential handling, so it belongs in the standard or procedure. The policy states the requirement; the mission statement is not a control document; and a vendor’s default guide is not the organization’s normative hierarchy.

  8. A. The ISC2 Code of Ethics requires members to act honorably, honestly, justly, responsibly, and legally, and to disclose to the appropriate authorities any situation that could violate the Code, the law, or their organization’s policies. Bringing the misrepresentation to the parties who can act on it is that duty in practice. Public shaming, silence, and a personal confrontation are self-help, inaction, or unauthorized escalation, none of which the canon supports.

  9. C. Personnel security pairs screening with the role’s risk, contractual confidentiality commitments, access scoped to the job, and deprovisioning when the engagement ends. ISO/IEC 27001:2022 Annex A expresses the same pattern: screening of candidates, confidentiality commitments in the terms of engagement, and removal of access rights at the end of employment. A verbal promise, blanket access, or permanent administrator rights fail the proportionality and least-privilege tests.

  10. B. PCI DSS v4.0 defines scope as the cardholder data environment: systems that store, process, or transmit cardholder data, or that can affect the security of the CDE. Segmentation is a scope-reduction technique, not an exemption: isolation must be demonstrated, and the systems that remain in scope are still subject to the requirements. Only-the-gateway and firewall-solves-it both mistake a component for the program.

  11. C. The role accountable for a data asset’s business value, classification, and use is the business owner, sometimes called the data owner. The custodian implements the technical controls under the owner’s direction, the administrator operates the systems, and a processor is a contract-party concept from privacy regulation, not an accountability role within the organization.

  12. A. Classification labels express the value and sensitivity of the data and drive the minimum controls required to protect it, and labels are not permanent: as value, regulation, or business context changes, they are reviewed and revised. The label does not dictate a firewall product, public data still needs integrity protection so it cannot be defaced, and classification is a managed process rather than a one-time event.

  13. D. NIST SP 800-88 Rev 1 defines three categories of sanitization, clear, purge, and destroy, and the appropriate choice depends on the media type and the confidentiality of the data. For magnetic media, overwriting can clear, degaussing can purge (and makes the drive unusable), and destruction is the highest-assurance option. Deleting files does not sanitize, degaussing is ineffective on optical media, and a recycler’s pickup form is paperwork, not sanitization.

  14. A. A retention schedule consolidates the applicable drivers: legal, regulatory, contractual, and operational. The schedule should satisfy the longest applicable requirement that still covers the minimums, so 12 years per operations policy covers the 10-year legal and 7-year contractual minimums. Shortest-wins, insurer-only, and ad hoc retention all ignore the drivers that make retention a legal obligation rather than a storage decision.

  15. B. NIST SP 800-122 defines PII as information that can be used to distinguish or trace an individual’s identity, either alone or combined with other information. A name paired with a Social Security number is the canonical case. A server serial number, a public web server address, and a floor plan identify equipment and space, not a person.

  16. C. Data in use is protected by controls over the session and the environment: privacy screens limit shoulder surfing, lock screens terminate exposure when the analyst steps away, and accessing data through a controlled application or virtual desktop prevents unrestricted local copies from scattering onto the device. Encrypting unrelated brochures, keeping the laptop powered on, or printing the data leaves the sensitive data exposed exactly where the analyst is.

  17. B. Bell-LaPadula enforces confidentiality with two properties: the simple security property prohibits a subject from reading objects at a higher classification (no read up), and the *-property prohibits writing down to lower classifications. Reading a top-secret document with secret clearance violates the simple security property. The *-property governs writing, and the Biba and Clark-Wilson rules are integrity and transaction models, not this violation.

  18. C. Biba is the integrity counterpart of Bell-LaPadula: no read down, so a high-integrity subject never trusts low-integrity data, and no write up, so low-integrity subjects cannot corrupt high-integrity objects. The no-read-up, no-write-down pattern is Bell-LaPadula’s, separation of duties belongs to Clark-Wilson, and dual control is an operational procedure rather than a property of the model.

  19. D. The reference monitor concept requires complete mediation of every access attempt, tamperproofness so the enforcement cannot be bypassed or modified, and verifiability, usually by keeping the mechanism small enough to analyze and test. Least privilege, the CIA triad, and authentication features are security properties and functions; they are not the three requirements of the reference monitor itself.

  20. A. Common Criteria evaluation per ISO/IEC 15408 grades assurance, not features: Evaluation Assurance Levels EAL1 through EAL7 describe increasing rigor in the specification, design, and testing of the security functions. A high EAL does not certify the absence of all vulnerabilities, the vendor cannot assign its own level, and certification does not replace ongoing security testing such as penetration tests.

  21. D. FIPS 197 specifies AES as a symmetric block cipher: a fixed 128-bit block size with key sizes of 128, 192, and 256 bits. Symmetric means the same key encrypts and decrypts. AES is not a stream cipher, it is not asymmetric, and it can decrypt as readily as it encrypts.

  22. C. SHA-256 per FIPS 180-4 is a one-way, collision-resistant hash: any change in the input produces, with overwhelming probability, a different digest, and the function cannot be inverted to recover the input. Integrity verification compares a recomputed digest with a trusted baseline. The digest is a fixed length regardless of input, and finding two messages with the same digest is computationally infeasible, not easy.

  23. B. A digital signature is created with the sender’s private key and verified with the sender’s public key, which ties the signature to the sender while allowing anyone holding the public key to check it. The recipient’s keys play no role in signing, a shared symmetric key cannot provide non-repudiation, and signing with a public key would let anyone forge the sender’s signature.

  24. B. NIST SP 800-207 states the Zero Trust assumption plainly: no implicit trust is granted based on network location, and every access decision considers identity, device posture, and other attributes. The perimeter-is-trusted view is exactly what Zero Trust rejects, cloud migration is one implementation choice rather than a requirement, and encryption is a component of the architecture, not a replacement for authentication.

  25. C. TLS operates between the application layer and the transport layer, which the OSI model maps to the presentation layer: it protects application data before the transport protocol carries it. TLS does not encrypt IP packets, which is IPsec’s job; it is not a physical-layer mechanism; and it does not replace IPsec.

  26. B. Separating zones so that traffic cannot flow directly except through managed gateways is segmentation and isolation, the core mechanism for limiting lateral movement: an attacker who reaches one zone is stopped before reaching the payment systems. Load balancing distributes traffic, DNS caching speeds resolution, and bandwidth throttling limits rate; none of them isolates the zones.

  27. C. In IPsec per RFC 4301, AH (RFC 4302) provides integrity and origin authentication without confidentiality, while ESP (RFC 4303) provides confidentiality plus integrity protection. Neither protocol provides confidentiality by default, and ESP is not limited to IPv6.

  28. D. WPA3 replaces the WPA2 pre-shared key handshake with Simultaneous Authentication of Equals (SAE), a password-authenticated exchange that resists offline dictionary attacks, and WPA3-certified networks enforce management frame protection. The network still encrypts traffic, WEP is obsolete rather than restored, and the passphrase is never broadcast.

  29. C. A remote-access VPN builds an encrypted tunnel over an untrusted network and authenticates the endpoint before traffic flows, whether it is built on IPsec or TLS. Telnet is a cleartext remote shell, port forwarding exposes a service without a tunnel, and an unencrypted mapped drive is the exposure itself.

  30. B. DNSSEC, per RFC 4033, provides origin authentication and data integrity by signing DNS records, so a validating resolver can reject forged or altered responses. DNSSEC does not encrypt queries, and caching or blocking port 53 does not authenticate responses.

  31. C. The stack is IEEE 802.1X port-based network access control: the switch acts as the authenticator and keeps the port blocked until the endpoint, the supplicant, completes an EAP exchange, with a RADIUS server (RFC 2865) making the authentication decision. MAC flooding, ARP poisoning, and DHCP starvation are attacks, not access control stacks.

  32. C. A volumetric attack saturates the link, so the defense must engage upstream: a mitigation service or scrubbing center absorbs and filters the traffic before it reaches the site’s own connection. A firewall at the site can only drop traffic that has already consumed the link, DNS TTL changes do not add bandwidth, and disabling the server makes the outage complete.

  33. B. Multi-factor authentication requires evidence from two different categories. A smart card is something you have and a PIN is something you know. A password plus a security question is two knowledge factors, two passwords are two knowledge factors, and a fingerprint plus a voiceprint are two inherence factors: each pair is multi-step but single-category.

  34. A. NIST SP 800-63B directs verifiers to screen new secrets against lists of known compromised values, to permit long secrets, including passphrases, and to slow guessing with throttling or rate limiting. Forced rotation with composition rules is the pattern the guidance moved away from, and plaintext storage or fixed short lengths contradict the standard outright.

  35. D. Lowering the threshold accepts more samples: more impostor attempts pass, so the false accept rate rises, and fewer genuine users are rejected, so the false reject rate falls. The two rates move in opposite directions as the threshold moves, which is the trade at the heart of biometric tuning.

  36. B. The policy evaluates attributes of the subject, the object, and the environment, which is the definition of attribute-based access control in NIST SP 800-162. Discretionary access control is owner discretion, mandatory access control is labels and clearances with no user override, and rule-based describes a narrower mechanism rather than the general policy model at work here.

  37. A. In Kerberos per RFC 4120, the client presents credentials to the Authentication Service and receives a ticket-granting ticket (TGT) plus a session key, then presents the TGT to the Ticket-Granting Service to request service tickets. Certificates, one-time codes, and biometrics are not part of this exchange.

  38. A. Federated identity lets the partner’s identity provider assert identity to your application through a standard such as SAML 2.0 or OpenID Connect, so partner users authenticate at home and your service trusts the assertion. Local accounts with shared passwords, trusting a typed email address, and using MAC addresses all fail because they do not provide verifiable identity.

  39. D. The joiner-mover-leaver lifecycle treats a role change as a move: access is reviewed and adjusted so the employee keeps what the new role requires, loses what the old role only needed, and gains what the new role adds. Doing nothing until audit, only deleting old accounts, or cloning the old credentials all leave the access state wrong.

  40. B. Just-in-time elevation grants the privileged right for the window and expires it automatically, with session recording so the activity is attributable to the administrator. Permanent group membership is standing privilege, sharing the root password destroys attribution, and granting access to employee accounts is unrelated privilege rather than database access.

  41. B. PCI DSS v4.0 requires vulnerability scans on a defined periodic schedule, with external scans at least quarterly and internal scans at least quarterly, plus penetration testing annually and after significant changes. A single test does not replace the scanning cadence, scanning once at deployment decays immediately as the environment changes, and in-scope systems are precisely where the testing is required.

  42. C. The agreement that fixes scope, techniques, timing, and the boundaries of what the tester may do is the rules of engagement, the document the testers and the organization settle before testing begins. A certificate of destruction covers media, chain of custody covers evidence, and a service-level objective covers performance, not test boundaries.

  43. D. Static application security testing analyzes source code without executing it, which is exactly the right point for finding injection flaws before the build. A production penetration test finds exploitable issues in running systems but much later in the lifecycle; fuzzing exercises a binary at runtime; and a port scan finds services, not code flaws.

  44. B. Fuzzing supplies malformed, unexpected, or random inputs to a program and observes crashes, hangs, and other failures. Baseline scanning compares configurations, code review is human analysis, and social engineering targets people rather than parsers.

  45. D. Log management per NIST SP 800-92 centers on protecting the logs: centralized collection, storage with integrity protections such as append-only or write-once, synchronized clocks so events correlate, and regular review for anomalies. Local unprotected logs, short retention, and self-editable logs each defeat the audit function.

  46. A. NIST SP 800-137 defines information security continuous monitoring as maintaining ongoing awareness of the security posture, including changes, vulnerabilities, and threats, to support timely risk management decisions. It supplements audits rather than replacing them, and reports have value only when the organization acts on them.

  47. B. Mean time to detect (MTTD) is the average time between an event occurring and the team detecting it. MTTR is time to repair, RTO is a recovery objective, and ARO is a risk-math frequency; each measures a different thing.

  48. C. Dynamic application security testing (DAST) exercises a running application over its interfaces, here HTTP, with crafted requests designed to trigger common flaws, and observes the responses. Static analysis reads source without running it, threat modeling happens at design time, and perimeter scanning looks at exposed services rather than application logic.

  49. A. NIST SP 800-61 Rev 2 structures incident response as four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. The other sequences either omit preparation, the phase that makes response possible, or compress the containment-to-recovery work that the standard treats as the core.

  50. C. The order of volatility, per RFC 3227, says to capture the most volatile evidence first: registers, memory, temporary files, then disk. Memory is captured before disk imaging precisely because it is the most volatile. The chain of custody applies to all evidence but does not set this order, disk imaging is essential for disk evidence, and memory is not erased by imaging.

  51. A. Chain of custody is the documented record of every transfer of evidence, with identity, date, and purpose, combined with protecting the evidence from alteration. Shared writable storage, casual file copies, and public discussion each break the chain or expose the evidence, and all three can make the evidence inadmissible.

  52. B. The damage from ransomware is bounded by the ability to restore: offline or immutable backups with tested restoration give the organization the option to refuse payment, while segmentation and least privilege limit how far the encryption spreads. Paying funds the attackers and does not guarantee recovery, and disabling protection or widening privilege makes the infection worse.

  53. B. Surviving the destruction of the primary site requires a second copy at an offsite location, restoration tested on a schedule so the copy is known to work, and a recovery point objective that bounds the data loss the business accepts. Backups beside the servers, on the same disk, or made ad hoc all die with the primary site or the drive.

  54. D. A mantrap, a small passage with interlocking doors, is designed to stop tailgating: only one person can be verified per cycle, and the doors cannot both open to let a follower through. Generators, suppression, and cable locks address power, fire, and theft, not entrance control.

  55. A. Change management requires the change to be reviewed and approved, tested outside production, scheduled with a backout plan, and documented afterward. A direct production edit skips approval and testing exactly when a Friday-afternoon mistake becomes an all-weekend outage; testing under peak load and skipping the process convert a controlled change into an uncontrolled experiment.

  56. D. Hot, warm, and cold sites describe increasing setup time and decreasing readiness: a hot site is fully equipped to resume operations quickly, a warm site has partial infrastructure ready, and a cold site provides space and services that need substantial setup. A cold site is not fast, the sites are not equivalent, and recovery sites host operations, not just backups.

  57. B. The cost of correcting a defect rises as it moves through the lifecycle: a security requirements error caught in production is the most expensive kind to fix, because it can invalidate design, code, and tests. Requirements and design are the cheapest points of correction, which is why threat modeling and secure requirements belong early.

  58. B. Parameterized queries and prepared statements separate the SQL logic from the data, so attacker input like ’ OR ‘1’=‘1 is treated as a literal value rather than executable code, which is the definitive defense against the injection class the OWASP Top 10 calls out. Error messages, audit logs, and session timeouts do not address how the query is built.

  59. A. Stored XSS injects attacker-controlled script that is later rendered and executed in the victim’s browser; CSRF tricks the victim’s browser into sending an authenticated request the victim did not intend, using the victim’s existing session. Neither requires the server to be compromised, XSS is an application-layer flaw, and the two differ in mechanism and defense.

  60. D. Output encoding, or escaping, in the correct context for where the data is rendered is the standard defense against script injection at render time: the user’s input is treated as data, not markup. Removing the feature is a product decision, not a rendering control, and timeouts and cookie encryption address sessions, not injection.

  61. C. Shift-left security moves testing earlier in the delivery pipeline: static analysis in the build stage, dependency scanning before artifacts are produced, and gates that block vulnerable builds from proceeding. Annual audits are too late, the production firewall is a perimeter control that does not inspect code, and removing code review moves in the opposite direction.

  62. A. A software bill of materials (SBOM) is the machine-readable inventory of the components in an application, commonly expressed in formats such as SPDX or CycloneDX, and it is the artifact that lets an organization match its components against known-vulnerability databases. A network diagram, certificate inventory, or firewall rules describe infrastructure, not the component supply chain.

  63. D. When a component has a publicly disclosed critical vulnerability, the best response is to update to a patched version if one exists and, if patching is not immediately feasible, to apply compensating controls, track the finding for remediation, and reassess on a schedule. Ignoring the finding, suppressing the report, and rewriting the application are inaction, concealment, or a disproportionate project; none of them manages the risk.

Reading the numbers

The score sheet, not the test, is the deliverable of this sitting. A total score tells you where you stand against the exam’s pass mentality, but it is the per-domain numbers that tell you what to do next, and that is the difference the readiness review in Chapter 35 is built on: total scoring, triage of weak domains, the final plan, and the steps that come after the exam.

If this sitting exposed a domain below 60 percent, the re-read, redo, retest loop from Chapter 1 is the next thing on the calendar, before you sit the second half. A domain in the 60 to 80 percent band gets targeted rationale review, starting with the questions you missed here and the chapters they came from. A domain above 80 percent gets one weekly pass to hold it warm.

Chapter 34 carries questions 64 through 125, the second half of the full exam, under the same rules and the same pacing. Run it the same way you ran this one: question line first, kill, choose, confirm, move, and score the whole 125 when both sittings are done.