Free ISC2 CISSP-ISSMP practice questions

10 free ISC2 CISSP-ISSMP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 218 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following fields of management focuses on establishing and maintaining consistency of a system's or product's performance and its functional and physical attributes with its requirements, design, and operational information throughout its life?

  1. Configuration management
  2. Risk management
  3. Procurement management
  4. Change management
Show answer and explanation

Correct answer: A. Configuration management

Configuration management is the discipline that establishes and maintains consistency of a system's or product's performance, functional attributes, and physical attributes with its requirements, design, and operational information throughout its lifecycle. This involves tracking, documenting, and controlling all changes to the system's configuration items.

Why the other options are wrong

  • B. Risk management focuses on identifying, analyzing, and mitigating risks, not maintaining system consistency.
  • C. Procurement management deals with acquiring goods and services from external sources.
  • D. Change management controls the implementation of changes to systems but does not establish the baseline consistency.

Question 2

Which of the following are the ways of sending secure e-mail messages over the Internet? Each correct answer represents a complete solution.

Choose two.

  1. TLS
  2. PGP
  3. S/MIME
  4. IPSec
Show answer and explanation

Correct answer: B, C

B. PGP C. S/MIME PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose Internet Mail Extensions) are complete end-to-end solutions for securing email messages. Both provide encryption and digital signature capabilities for email. TLS secures the transport channel between mail servers but not the message itself, and IPSec operates at the network layer rather than providing email-specific security.

Why the other options are wrong

  • A. TLS secures the connection between mail servers during transmission but does not provide end-to-end message encryption.
  • D. IPSec is a network-layer security protocol used for VPNs and network communication, not specifically for email security.

Question 3

You work as a Senior Marketing Manger for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote desktop session. You suspected that some malicious attack was performed on the network of the company. You immediately called the incident response team to handle the situation who enquired the Network Administrator to acquire all relevant information regarding the malfunctioning.

The Network Administrator informed the incident response team that he was reviewing the security of the network which caused all these problems. Incident response team announced that this was a controlled event not an incident.

Which of the following steps of an incident handling process was performed by the incident response team?

  1. Containment
  2. Eradication
  3. Preparation
  4. Identification
Show answer and explanation

Correct answer: D. Identification

The Identification phase is where the incident response team determines whether an event is actually a security incident or a controlled, legitimate activity. In this scenario, the incident response team identified that the Network Administrator's security review was a controlled event, not a malicious incident. This classification decision is the core function of the Identification step.

Why the other options are wrong

  • A. Containment involves stopping the attack and limiting its impact, which was not performed here.
  • B. Eradication involves removing malware or unauthorized access, which was not needed since this was a controlled event.
  • C. Preparation involves establishing tools, processes, and readiness before an incident occurs.

Question 4

Which of the following is the process performed between organizations that have unique hardware or software that cannot be maintained at a hot or warm site?

  1. Cold sites arrangement
  2. Business impact analysis
  3. Duplicate processing facilities
  4. Reciprocal agreements
Show answer and explanation

Correct answer: D. Reciprocal agreements

Reciprocal agreements are mutual arrangements between two or more organizations to support each other's disaster recovery by providing backup processing facilities. These agreements are particularly valuable for organizations with unique hardware or software that cannot be replicated at standard hot or warm sites, as they leverage partner resources instead.

Why the other options are wrong

  • A. Cold sites arrangement refers to facilities that are prepared but not actively maintained with current data or running systems.
  • B. Business impact analysis is an assessment process, not a processing facility arrangement.
  • C. Duplicate processing facilities involve maintaining redundant infrastructure within a single organization, not between organizations.

Question 5

Which of the following involves changing data prior to or during input to a computer in an effort to commit fraud?

  1. Data diddling
  2. Wiretapping
  3. Eavesdropping
  4. Spoofing
Show answer and explanation

Correct answer: A. Data diddling

Data diddling is the fraudulent practice of changing or altering data before it enters or during its input into a computer system. This is a common form of computer fraud where perpetrators modify information to commit financial or operational fraud.

Why the other options are wrong

  • B. Wiretapping involves intercepting electronic communications over networks or telephone lines.
  • C. Eavesdropping is the unauthorized listening to or monitoring of private conversations or communications.
  • D. Spoofing involves impersonating another entity by falsifying identity information in network packets or communications.

Question 6

Which of the following penetration testing phases involves reconnaissance or data gathering?

  1. Attack phase
  2. Pre-attack phase
  3. Post-attack phase
  4. Out-attack phase
Show answer and explanation

Correct answer: B. Pre-attack phase

The pre-attack phase is the initial phase of penetration testing that involves reconnaissance and data gathering. During this phase, testers collect information about the target system, network, and organization to identify potential vulnerabilities and attack vectors before attempting any actual attacks.

Why the other options are wrong

  • A. The attack phase involves actively exploiting identified vulnerabilities and attempting to gain unauthorized access.
  • C. The post-attack phase occurs after the penetration testing is complete and involves analysis and reporting of findings.
  • D. Out-attack phase is not a recognized phase in the standard penetration testing methodology.

Question 7

Mark works as a security manager for SoftTech Inc. He is involved in the BIA phase to create a document to be used to help understand what impact a disruptive event would have on the business. The impact might be financial or operational.

Which of the following are the objectives related to the above phase in which Mark is involved? Each correct answer represents a part of the solution.

Choose three.

  1. Resource requirements identification
  2. Criticality prioritization
  3. Down-time estimation
  4. Performing vulnerability assessment
Show answer and explanation

Correct answer: A, B, C

A. Resource requirements identification B. Criticality prioritization C. Down-time estimation The Business Impact Analysis (BIA) phase includes three primary objectives: Resource requirements identification determines what resources are needed to maintain critical functions, Criticality prioritization ranks business functions by importance, and Down-time estimation calculates the maximum acceptable outage time for each function. These elements collectively help organizations understand the impact of disruptive events.

Why the other options are wrong

  • D. Performing vulnerability assessment is part of risk assessment and security evaluation, not a core objective of the BIA phase.

Question 8

Which of the following recovery plans includes specific strategies and actions to deal with specific variances to assumptions resulting in a particular security problem, emergency, or state of affairs?

  1. Business continuity plan
  2. Disaster recovery plan
  3. Continuity of Operations Plan
  4. Contingency plan
Show answer and explanation

Correct answer: D. Contingency plan

A Contingency plan is a recovery plan that includes specific strategies and actions designed to address particular variances to assumptions that could result in specific security problems, emergencies, or states of affairs. These plans are tailored to handle anticipated deviations and provide predetermined response procedures.

Why the other options are wrong

  • A. A Business continuity plan focuses on maintaining or quickly resuming business operations during and after disruptions.
  • B. A Disaster recovery plan specifically addresses recovery from major disasters and focuses on restoring IT systems and data.
  • C. A Continuity of Operations Plan (COOP) maintains essential functions during emergencies but is broader than addressing specific variances.

Question 9

Which of the following protocols is used with a tunneling protocol to provide security?

  1. FTP
  2. IPX/SPX
  3. IPSec
  4. EAP
Show answer and explanation

Correct answer: C. IPSec

IPSec is a suite of protocols designed to secure IP communications through encryption and authentication. It is used in conjunction with tunneling protocols to provide end-to-end security for data transmitted over networks. IPSec operates at the network layer and can protect entire IP packets, making it the standard protocol for securing tunneled communications.

Why the other options are wrong

  • A. FTP is a file transfer protocol with no inherent security features and is not used as a security mechanism with tunneling protocols.
  • B. IPX/SPX is a legacy network protocol suite that predates modern security implementations and is not used for tunnel security.
  • D. EAP is an authentication framework used for user authentication, not a protocol that provides security to tunneling protocols themselves.

Question 10

Which of the following subphases are defined in the maintenance phase of the life cycle models?

  1. Change control
  2. Configuration control
  3. Request control
  4. Release control
Show answer and explanation

Correct answer: A, C, D

A. Change control C. Request control D. Release control The maintenance phase of the system life cycle is divided into three subphases: request control, change control, and release control. Request control handles user requests for modifications and prioritizes them, change control evaluates and implements the approved modifications while preserving security, and release control governs the final approval and distribution of the updated code into production. Together these subphases keep operational systems stable, documented, and securely updated.

Why the other options are wrong

  • B. Configuration control belongs to configuration management, which tracks system baselines across the entire life cycle rather than serving as a maintenance phase subphase.

That was 10 of 218.

The full ISC2 CISSP-ISSMP pack has all 218 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack