Official Bank 0/1456

Certified Information Systems Security Professional (CISSP) (CISSP) - ISC2 Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
1456 Total Questions
1
Question
Which of the following can be used to calculate the loss event probability?
Options
A Total number of possible outcomes divided by frequency of outcomes
B Total number of possible outcomes multiplied by frequency of outcomes
C Number of outcomes multiplied by total number of possible outcomes
D Number of outcomes divided by total number of possible outcomes
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Which of the following is the top barrier for companies to adopt cloud technology?
Options
A Migration period
B Security
C Data integrity
D Cost
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
What is the FIRST step when developing an Information Security Continuous Monitoring (ISCM) program?
Options
A Define an ISCM strategy based on risk tolerance.
B Establish an ISCM technical architecture.
C Establish an ISCM program determining metrics, status monitoring frequencies, and control assessment frequencies.
D Collect the security-related information required for metrics, assessments, and reporting.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Why do certificate Authorities (CA) add value to the security of electronic commerce transactions?
Options
A They provide a secure communication enamel to the transaction parties.
B They maintain the certificate revocation list.
C They maintain the private keys of transition parties.
D They verify the transaction parties' private keys.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A federal agency has hired an auditor to perform penetration testing on a critical system as part of the mandatory, annual Federal Information Security Management Act (FISMA) security assessments. The auditor is new to this system but has extensive experience with all types of penetration testing. The auditor has decided to begin with sniffing network traffic. What type of penetration testing is the auditor conducting?
Options
A Red box testing
B White box testing
C Gray box testing
D Black box testing
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.