Browse all practice questions for the CISSP Domain 1 – Security and Risk Management Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 1 – Security and Risk Management Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is meant by the term "Total Risk" in risk analysis?
  • What aspect of availability ensures a resource is easy to use and understand?
  • What is the meaning of Compensating controls in risk management?
  • What does ISO 27002 primarily provide guidance on?
  • What does likelihood determination assess in risk management?
  • Which type of Authentication involves something you know?
  • What is commonly implemented as a technical measure to combat phishing attacks?
  • What is the legal requirement of the Security Breach Notification Law?
  • What does PCI-DSS stand for and relate to?
  • Which attack vector is characterized by targeting specific individuals with personalized messages?
  • What type of evidence supports facts but may not stand alone as proof?
  • What is the main focus of the ISO 27000 series?
  • What is a common method to ensure data confidentiality while in transport?
  • What characterizes the EU Data Protection Directive?
  • To which areas does Defense in Depth apply?
  • What inherently makes hearsay generally inadmissible in court?
  • What is one of the criteria for a patent to be granted?
  • Which of the following is NOT a mandate under HIPAA?
  • Who is most likely to be responsible for ensuring accountability in an organization?
  • What does authorization determine in an access control model?
  • Which statement best describes the nature of US privacy regulation?
  • In legal terms, gray areas in the law are determined by what?
  • In the context of Authentication, what does Type V represent?
  • According to the (ISC)2 Code of Ethics, which of the following is a primary focus?
  • Which type of Authentication utilizes geolocation as a factor?
  • Which of the following is considered direct evidence?
  • What do administrative (directive) controls encompass?
  • What are the three elements included in the CIA triad?
  • What does PCI-DSS stand for, and what is its primary purpose?
  • What is the primary focus of the Wassenaar Arrangement?
  • Which element of the IAAA framework involves ensuring user identity is established?
  • Too much availability can negatively influence which of the following?
  • What is typically included in agreements with third parties to ensure security compliance?
  • Circumstantial evidence is best defined as which of the following?
  • What is the primary characteristic of entrapment in a legal context?
  • Which type of phishing attack is specifically targeted at senior leadership within an organization?
  • Which of the following is a method for establishing non-repudiation?
  • What framework is recommended for risk management according to the NIST guidelines?
  • Which of the following is NOT a type of risk response strategy?
  • What does Integrity refer to in the context of security?
  • Which of the following methods is critical to maintaining the integrity of evidence?
  • Which principle is emphasized in the (ISC)2 code regarding professional behavior?
  • Which term refers to the expected cost if a risk occurs once?
  • What is forensic imaging primarily concerned with?
  • According to IAB's Ethics and the Internet, which action is prohibited?
  • How many laws are covered in the CISSP exam according to the standard curriculum?
  • Which ISO standard directs how to protect Personal Health Information (PHI)?
  • What is the primary role of a vulnerability in risk management?
  • Which ISO standard focuses on how to measure success of an ISMS?
  • What does due care refer to in the context of IT security?
  • Which of the following is one of the Ten Commandments from the Computer Ethics Institute?
  • What is the impact of excessive confidentiality on data management?
  • What is the focus of management in the context of governance?
  • Which type of Authentication does NOT rely on physical attributes?
  • Which concept ensures that an action cannot be denied after it has been performed?
  • How can cybersquatting be legally defined?
  • What is auditing in the context of information security?
  • What type of access control detects an attack during or after it has occurred?
  • Which law is most commonly used to prosecute computer crimes?
  • What is the primary goal of confidentiality in security practices?
  • What does "CIA" stand for in security terminology?
  • How long does copyright protection last for an individual creator?
  • Which category do hardware and software components fall under in security controls?
  • Which of the following would be included in result documentation?
  • What is an example of what security policies might cover?
  • What does the principle of availability ensure?
  • Malicious attacks and component failures are threats to which principle?
  • What is the primary focus of the FRAP methodology?
  • Which of the following defines a threat in security terms?
  • What is the maximum duration that registered trademarks can remain valid?
  • How are standards characterized in a security context?
  • What is the primary intent of typosquatting?
  • Before utilizing honeypots, what is a crucial step that should be taken?
  • Which step is NOT part of the 9-step process for Risk Management Framework?
  • What defines collaborative evidence in legal terms?
  • In Criminal Law, what is required to prove a case?
  • Which element in the IAAA framework corresponds to tracking accountability?
  • How do technical controls primarily help in an organization?
  • Which type of email attack is characterized by its targeted approach, often at specific individuals?
  • What is the primary focus of qualitative risk analysis?
  • Who are referred to as Script Kiddies?
  • What is the definition of Identification in the context of security?
  • What area does SOX of 2002 regulate?
  • What is the primary purpose of a botnet controlled by a bot-herder?
  • What strategy can mitigate the likelihood of falling victim to targeted phishing attacks?
  • What are procedures primarily characterized as?
  • Which term describes computers infected with malware that are controlled remotely by a botnet?
  • What does control analysis primarily assess?
  • Which of the following describes the attributes of a typical bot controlled by a botnet?
  • What is a botnet?
  • Which of the following is a characteristic of mandatory procedures?
  • Which ISO standard focuses on the establishment, implementation, control, and improvement of an Information Security Management System (ISMS)?
  • Which risk response strategy involves applying efforts to reduce the risk?
  • What is the primary characteristic of negligence in legal terms?
  • What does the concept of confidentiality in security aim to protect?
  • What defines a BlackHat hacker?
  • What is a primary goal of implementing Defense in Depth within an organization?
  • What is a key focus of Administrative Law?
  • What is the role of chain of custody in legal evidence?
  • What role do C-level executives play in governance?
  • What is the purpose of Annualized Loss Expectancy (ALE)?
  • Which of the following falls under Type II Authentication?
  • Which security measure breaches the condition of integrity through data alteration?
  • What does the ECPA protect against?
  • Which of the following laws specifically addresses consumer privacy in financial institutions?
  • What must be ensured for evidence to be admissible according to the Best Evidence Rule?
  • In the acquisition process, what should organizations ensure about their standards?
  • Which type of Authentication includes physical items like tokens or smart cards?
  • What is typically included in physical controls?
  • Which of the following represents a method of Authentication?
  • What capabilities does the PATRIOT Act of 2001 expand?
  • What is the purpose of ISO 27004?
  • What defines a trade secret?
  • What is the primary purpose of accountability in cybersecurity?
  • Who carries the most liability in an organization regarding security?
  • What should employees be familiar with regarding their organization?
  • Why is evidence integrity a vital consideration in legal proceedings?
  • What does Type III Authentication refer to?
  • What best describes the purpose of contractual rights in third-party agreements?
  • Non-repudiation in cybersecurity primarily utilizes which two concepts?
  • What is the primary focus of Authentication in information security?
  • Which of the following best describes a government attacker's motivations?
  • What does the Fourth Amendment specifically protect citizens from?
  • Which principle is viewed as the primary goal of a security infrastructure?
  • Which statement is true regarding the Security Breach Notification Law in most states?
  • When splitting or divesting from a company, what is essential to maintain concerning data?
  • What can result from gross negligence under SOX?
  • What type of attacker is primarily government or state-sponsored, using the internet as a tool against certain systems?
  • What proof standard is typically required in Administrative Law?
  • Layered defense primarily improves which three aspects of information security?
  • In terms of email attacks, what does 'training and awareness' refer to?
  • Continuous improvement in an organization’s security governance is aimed at achieving what?
  • In terms of objects and subjects in security, what does a subject refer to?
  • In relation to federal rules regarding evidence, what does Rule 803 allow for?
  • Which of the following is an example of Identification?
  • When integrating new technology, what should standards reflect?
  • Which of the following best describes the intent of the Ten Commandments from the Computer Ethics Institute?
  • How does enticement differ from entrapment?
  • What element does the layered defense strategy aim to enhance in a security framework?
  • What does ITIL stand for in the context of information technology?
  • How does a government attacker typically operate?
  • What does accountability in a security context often involve?
  • What term describes a true reflection of reality?
  • Which of the following best describes the EU's approach to privacy?
  • Which of the following describes the assurance that the widest range of subjects can interact with a resource?
  • What describes a GreyHat hacker?
  • What type of evidence is described as tangible and physical?
  • What does vulnerability identification involve?
  • Which category of access control is designed to prevent an attack from happening?
  • What type of risk response involves shifting the risk management responsibility to a third party?
  • What does the Risk Formula state?
  • What type of phishing attack involves using voice communication platforms?
  • What is a primary function of physical controls?
  • What is the primary goal of the COSO framework for an IT organization?
  • What is the principle of Defense in Depth in security management?
  • In terms of data privacy, what does 'due diligence' refer to?
  • What type of compliance is associated with Private Regulations?
  • What approach does ISO 27005 provide for risk management?
  • What type of agreement is commonly associated with third-party interactions regarding security?
  • Which of the following describes an exception to copyright laws?
  • What could a Type I Authentication method include?
  • What constitutes a common attack related to patents?
  • Which principle is NOT part of security governance principles?
  • Which principle is characterized by being responsible for actions and outcomes?
  • What does the OECD Privacy Guideline primarily address?
  • What is included in the ISC2 Code of Ethics Canons?
  • What risk response strategy involves knowing the risk exists and accepting the implications?
  • Which type of hacker is typically known as an ethical hacker?
  • What is patent infringement typically characterized by?
  • What does the ISO 27000 series emphasize regarding the management of information security?
  • What do the principles of Availability in security depend on?
  • Which governance principle emphasizes accessing only necessary information?
  • What is the formal definition of Authorization?
  • Which principle relates to being correct and accurate in data representation?
  • Which concept poses a significant risk associated with honeypots?
  • Which aspect does NOT contribute to establishing a chain of custody?
  • What does maintaining Integrity ensure in a data environment?
  • What is the purpose of baselines or benchmarks in an organization?
  • What kind of risk management approach does OCTAVE represent?
  • What is a key component of HIPAA in relation to data protection?
  • What is Residual Risk defined as?
  • Integrity in data security is dependent on which other principle?
  • What defines guidelines in the context of organizational policies?
  • What are the three main rules outlined by HIPAA regarding PHI?
  • The implementation of which standard is essential for an organization to achieve compliance with information security best practices?
  • What is a key legal limitation associated with trade secrets?
  • Which access control type aims to reduce the severity of an attack after it occurs?
  • Which action is typically taken to mitigate insider threats?
  • Which term refers to unauthorized individuals attempting to access systems?
  • Which of the following has a heavy impact on individual liability in security matters?
  • COBIT is designed to align IT goals with what?
  • What is a key function of the Authorization process?
  • In the context of IT, what is considered secondary evidence?
  • What does due diligence pertain to in IT security?
  • What aspect does the prudent person rule emphasize in due care?
  • What does the GLBA focus on protecting?
  • Which type of law is enacted by government agencies?
  • What characterizes an insider threat?
  • What is the main consequence of Civil Law or Tort Law?
  • What is a Hacktivist known for?
  • What is the nature of security policies within an organization?
  • What is one effective method for preventing social engineering email attacks?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy