wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CISSP Domain 7

Total questions: 20

Worksheet time: 2hrs 40mins

Name
Class
Date
1.

An organization is found lacking the ability to properly establish performance indicators for its Web hosting solution during an audit. What would be the MOST probable cause?

a)

Absence of a Business Intelligence (BI) solution

b)

Inadequate cost modeling

c)

Improper deployment of the Service-Oriented Architecture (SOA)

d)

Insufficient Service Level Agreement (SLA)

2.

What is the PRIMARY reason for implementing change management?

a)

Certify and approve releases to the environment

b)

Provide version rollbacks for system changes

c)

Ensure that all applications are approved

d)

Ensure accountability for changes to the environment

3.

Which of the following is a PRIMARY advantage of using a third-party identity service?

a)

Consolidation of multiple providers

b)

Directory synchronization

c)

Web based logon

d)

Automated account management

4.

With what frequency should monitoring of a control occur when implementing Information Security Continuous Monitoring (ISCM) solutions?

a)

Continuously without exception for all security controls

b)

Before and after each change of the control

c)

At a rate concurrent with the volatility of the security control

d)

Only during system implementation and decommissioning

5.

A Business Continuity Plan/Disaster Recovery Plan (BCP/DRP) will provide which of the following?

a)

Guaranteed recovery of all business functions

b)

Minimization of the need decision making during a crisis

c)

Insurance against litigation following a disaster

d)

Protection from loss of organization resources

6.

Which of the following is the FIRST step in the incident response process?

a)

Determine the cause of the incident

b)

Disconnect the system involved from the network

c)

Isolate and contain the system involved

d)

Investigate all symptoms to confirm the incident

7.

A continuous information security monitoring program can BEST reduce risk through which of the following?

a)

Collecting security events and correlating them to identify anomalies

b)

Facilitating system-wide visibility into the activities of critical user accounts

c)

Encompassing people, process, and technology

d)

Logging both scheduled and unscheduled system changes

8.

which of the following is MOST important to minimize potential impact when implementing a new vulnerability scanning tool in a production environment?

a)

Negotiate schedule with the Information Technology (IT) operation’s team

b)

Log vulnerability summary reports to a secured server

c)

Enable scanning during off-peak hours

d)

Establish access for Information Technology (IT) management

9.

A Security Operations Center (SOC) receives an incident response notification on a server with an active intruder who has planted a backdoor. Initial notifications are sent and communications are established.

What MUST be considered or evaluated before performing the next step?

a)

Notifying law enforcement is crucial before hashing the contents of the server hard drive

b)

Identifying who executed the incident is more important than how the incident happened

c)

Removing the server from the network may prevent catching the intruder

d)

Copying the contents of the hard drive to another storage device may damage the evidence

10.

Operations Security seeks to PRIMARILY protect against which of the following?

a)

Risk Control

b)

Facility Disaster

c)

Compromisation

d)

Asset Threats

11.

Which of the following is a violation of the least privilege principle?

a)

A user has access to only the files needed to perform their specific job functions

b)

An administrator has unrestricted access to critical systems as well as non-essential systems

c)

A temporary contractor is requesting access that expires when their contract ends

d)

A software application is given permissions to only the resources it requires to run

12.
Which of the following is NOT a primary function of incident response?
a)
Detection
b)
Recovery
c)

Forensic

d)
Identification
13.
Which of these security measures is most effective in preventing unauthorized physical access to a data center?
a)

Alarm System

b)
Biometric authentication
c)
Virtual private network (VPN)
d)

CCTV

14.
Which type of backup only saves data that has changed since the last full backup?
a)
Full backup
b)
Differential backup
c)
Incremental backup
d)
Snapshot backup
15.

Which of the following actions is typically performed by a SIEM system to improve threat detection?

a)

Analyzing unauthorized IP addresses from accessing the network

b)

Correlating events from various sources to identify suspicious patterns

c)

Analyzing events to match risk register

d)

Correlating risk knowledge to various events to help security goal

16.

What type security control if organization decide to build Forensic team

a)

Administrative Preventive

b)

Technical Detective

c)

Physical Correction

d)

Administrative Deterrent

17.
A critical server goes down, and immediate action is needed. Which of the following procedures should be followed to restore the server quickly?
a)
Incident Response Plan
b)
Disaster Recovery Plan
c)
Business Continuity Plan
d)
Risk Assessment Plan
18.
Which of the following is a valid reason for conducting regular log analysis in a security operations environment?
a)
To improve system performance
b)
To detect unauthorized or suspicious activities
c)
To identify software version upgrades
d)
To reduce the amount of storage used by logs
19.
Which of the following describes the primary purpose of a forensic investigation in security operations?
a)
To recover data from a compromised system for immediate operational use
b)
To identify, preserve, analyze, and document digital evidence for legal proceedings
c)
To assess vulnerabilities in software and provide updates
d)
To monitor ongoing threats and alert the security team in real time
20.

Which of the following scenarios best demonstrates the principle of segregation of duties?

a)

One employee is responsible for both approving and processing expense reimbursements

b)

The network administrator is responsible for managing and and security manager auditing firewall configurations.

c)

A software developer can write code, but a different employee must review and approve the code before deployment.s

d)

The security team monitors physical and digital access controls within the organization but vendors execute the operation