CISSP Asset Security 5 — Questions and Answers
Question 1: Which framework provides a standardized vocabulary for describing hardware and software asset information to support vulnerability management?
- COBIT
- Common Platform Enumeration (CPE) (Correct answer)
- ISO 27001
- NIST RMF
Correct answer: Common Platform Enumeration (CPE)
Common Platform Enumeration (CPE) is a structured naming scheme for IT systems, software, and packages that enables consistent identification of assets in vulnerability databases like NVD.
Question 2: An employee transfers to a new role with different access requirements. Which process ensures their old access rights are removed?
- Access recertification
- Privilege creep prevention via access reviews (Correct answer)
- Separation of duties enforcement
- Mandatory vacation policy
Correct answer: Privilege creep prevention via access reviews
Regular access reviews and timely revocation of previous role permissions prevent privilege creep, where users accumulate access rights beyond what their current role requires.
Question 3: Which type of data classification is MOST common in private sector organizations?
- Top Secret / Secret / Confidential / Unclassified
- Public / Internal / Confidential / Restricted (Correct answer)
- Class 1 / Class 2 / Class 3 / Class 4
- Personal / Non-Personal / Sensitive / Open
Correct answer: Public / Internal / Confidential / Restricted
Private sector organizations typically use a four-tier model of Public, Internal Use Only, Confidential, and Restricted (or similarly named tiers) as opposed to the government's classification scheme.
Question 4: What is the FIRST step an organization should take when establishing a data classification program?
- Deploy a DLP solution to monitor data flows
- Identify and inventory all data assets owned by the organization (Correct answer)
- Train employees on handling classified data
- Define the classification levels and labeling standards
Correct answer: Identify and inventory all data assets owned by the organization
Before data can be classified or protected, organizations must first identify and inventory all data assets to understand what they have, where it is, and who is responsible for it.
Question 5: Which secure disposal method is REQUIRED for solid-state drives (SSDs) when the data contains classified information?
- Single-pass overwrite using zeros
- Degaussing
- ATA Secure Erase command
- Physical destruction or verified cryptographic erasure (Correct answer)
Correct answer: Physical destruction or verified cryptographic erasure
SSDs are not effectively sanitized by degaussing (no magnetic media) or overwriting (wear leveling may leave residual data); physical destruction or cryptographic erasure are the only reliable methods for classified data.
Question 6: A company acquires another firm and inherits its data assets. Which responsibility does the acquiring company immediately assume regarding the inherited customer data?
- The original privacy notices remain valid indefinitely
- The acquirer becomes the data controller with all associated privacy obligations (Correct answer)
- Inherited data is exempt from current privacy regulations for two years
- The acquired company's DPO retains full authority over the data
Correct answer: The acquirer becomes the data controller with all associated privacy obligations
Upon acquisition, the inheriting organization becomes the data controller and assumes full legal responsibility for protecting inherited personal data in compliance with applicable privacy regulations.
Question 7: Which concept refers to protecting information by ensuring it is only accessible to those with the verified need and authorization to see it?
- Confidentiality (Correct answer)
- Integrity
- Availability
- Non-repudiation
Correct answer: Confidentiality
Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes, which is the primary goal of data classification and access control.
Which framework provides a standardized vocabulary for describing hardware and software asset information to support vulnerability management?