← All CISSP Flashcard Decks

Mixed Deck — All CISSP Topics Flashcards

100 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CISSP Topics flashcards as text
  1. Which access control model is BEST suited for a military environment where data classification levels (Top Secret, Secret, Unclassified) govern information access?

    Answer: Mandatory Access Control (MAC)

    MAC enforces access based on data classification labels and subject clearance levels, making it ideal for environments with strict classification hierarchies.

  2. The possibility of a user's private key becoming lost is a security problem when employing private keys. A practitioner can mitigate this risk by using a key recovery agent that can backup and recover his keys. Because another party has key access, granting a single individual the capacity to recover users' private keys increases the risk of nonrepudiation. Which of the following principles could be used to reduce the risk?

    Answer: Dual control

    Explanation: Dual Control is a security principle that requires multiple parties to be present for a task that might have severe security implications. In this instance, it is likely best to have at least two network administrators present before a private key can be recovered. A subset of dual control is called M of N control. M and N are variables, but this control requires M out of a total of N administrators to be present to recover a key. Segregation of Duties is the concept of having more than one person required to complete a sensitive task. The principle of least privilege (PoLP) refers to an information security concept in which a user is given the minimum levels of access or permissions needed to perform his job functions. The need-to-know principle is that access to secured data must be necessary for the conduct of the users’ job functions.

  3. A legacy application uses MD5 to hash passwords. What is the PRIMARY cryptographic concern?

    Answer: MD5 is cryptographically broken and collision-prone

    MD5 is cryptographically broken, susceptible to collision attacks and extremely fast brute-force cracking, making it unsuitable for password hashing.

  4. An organization wants to test its incident response procedures without disrupting production systems. Which exercise type is MOST appropriate?

    Answer: Tabletop exercise

    A tabletop exercise walks participants through a simulated scenario verbally without activating actual systems or recovery procedures.

  5. What is the PRIMARY security concern with using shared credentials among multiple administrators?

    Answer: Inability to attribute actions to specific individuals for accountability

    Shared credentials eliminate individual accountability, making it impossible to audit which specific person performed administrative actions.

  6. Which skill is most critical for effective security and risk management?

    Answer: Communication and stakeholder engagement

    Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.

  7. What distinguishes a Business Continuity Plan (BCP) from a Disaster Recovery Plan (DRP)?

    Answer: The BCP addresses maintaining business operations during a disruption; the DRP focuses on restoring IT systems afterward

    The BCP is broader, covering how the business continues to operate during a disruption, while the DRP specifically addresses IT and infrastructure restoration.

  8. Which concept ensures that a user is given only the minimum access rights necessary to perform their job function?

    Answer: Least privilege

    Least privilege limits user rights and permissions to only what is required for their specific role, reducing the attack surface and limiting damage from compromised accounts.

  9. Trust and Assurance are two elements that are included in the evaluation scope when evaluating a system using the TCSEC and the more modern Common Criteria. Which of the following best describes assurance and trust?

    Answer: Trust describes the function of the product, while assurance describes the reliability of the process used to create the product.

    In security evaluations like TCSEC and Common Criteria, 'trust' describes the confidence that a system will behave as expected and enforce its security policy, focusing on *what* the product does. 'Assurance,' on the other hand, refers to the degree of confidence that the system meets its security requirements through rigorous development, testing, and evaluation processes, focusing on *how* the product was built and verified. Together, they provide a comprehensive view of a system's security posture.

  10. An organization wants to prevent a single administrator from having both the ability to create accounts and approve their own access requests. Which principle addresses this?

    Answer: Segregation of duties

    Segregation of duties (SoD) divides critical tasks between multiple people to prevent fraud and error by ensuring no single person controls an entire process.

  11. Which class of fire extinguisher is specifically rated for electrical equipment fires?

    Answer: Class C

    Class C extinguishers use non-conductive agents and are designed for fires involving energized electrical equipment.

  12. What is the MAIN security advantage of using a biometric system over a PIN-based access system?

    Answer: Biometric credentials cannot be shared or stolen as easily as PINs

    Biometric credentials are tied to an individual's unique physical traits, making them far harder to share, guess, or steal than PINs.

  13. Which NIST publication provides a framework for conducting security and privacy risk assessments for federal information systems?

    Answer: NIST SP 800-30

    NIST SP 800-30 provides guidance for conducting risk assessments, including preparing for, conducting, communicating, and maintaining risk assessment results.

  14. In CISSP practice, what is the purpose of vulnerability scanning?

    Answer: To identify weaknesses before attackers do

    Vulnerability scanning proactively identifies security weaknesses in systems and applications so they can be remediated before exploitation.

  15. Which type of motion detector uses radar-like signals to detect movement through walls and objects?

    Answer: Microwave detector

    Microwave detectors emit microwave pulses and measure reflections, allowing detection through non-metallic barriers.

  16. Which threat modeling methodology uses an attacker-centric approach organized around four categories: Goals, Observations, Plan, and Actions?

    Answer: PASTA

    PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that aligns attacker motivations with business objectives across seven stages.

  17. What is the value of continuing education in cryptography for CISSP professionals?

    Answer: It keeps professionals current with evolving standards and practices

    Continuing education ensures professionals stay current with the latest developments, standards, and best practices in their field.

  18. Which Evaluation Assurance Level (EAL) in Common Criteria represents 'structurally tested' and is the most common for commercial products seeking formal evaluation?

    Answer: EAL4

    EAL4 (methodically designed, tested, and reviewed) is the highest level typically economically feasible for commercial products.

  19. A qualitative risk assessment differs from a quantitative one in that it:

    Answer: Relies on expert judgment and descriptive categories like High/Medium/Low

    Qualitative risk assessments use subjective ratings and expert judgment rather than precise monetary calculations, making them faster but less precise.

  20. Which authentication method requires the user to prove identity using something they have (token) and something they know (PIN), but NOT a biometric factor?

    Answer: Two-factor authentication

    Two-factor authentication (2FA) combines exactly two distinct authentication factors; a hardware token plus a PIN uses 'something you have' and 'something you know'.