CISSP Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 CISSP flashcards as text
Which disaster recovery strategy involves maintaining a fully equipped and operational duplicate facility?
Answer: Hot site
A hot site is a fully operational duplicate data center that can take over immediately with near-zero recovery time.
What does the 'separation of duties' control primarily prevent?
Answer: Single individuals from completing high-risk transactions alone
Separation of duties divides critical tasks among multiple people to prevent any single individual from committing fraud or error undetected.
A developer implements input validation only on the client side. What is the MAIN security risk?
Answer: Attackers can bypass client-side controls and send malicious input directly
Client-side validation can be bypassed by intercepting and modifying requests, so server-side validation is essential for security.
Which of the following BEST describes a 'rainbow table' attack?
Answer: Using precomputed hash values to reverse password hashes
A rainbow table attack uses precomputed tables of hash values to quickly look up the plaintext corresponding to a stolen password hash.
Under GDPR, what is the maximum timeframe to notify supervisory authorities of a personal data breach?
Answer: 72 hours
GDPR Article 33 requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach.
Which security architecture framework divides networks into security zones based on trust levels?
Answer: Defense in depth with DMZ segmentation
Defense in depth with DMZ segmentation places untrusted, semi-trusted, and trusted networks in separate zones with controls between each layer.
What is 'salting' in the context of password storage?
Answer: Adding a unique random value to each password before hashing
Salting adds a unique random value to each password before hashing, preventing rainbow table attacks and ensuring identical passwords produce different hashes.