Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the ISC certification ISSAP Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the ISC ISSAP exam. To support your certification journey, we have made a selection of our premium 2026 ISC certification practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

You are the Security Consultant and have been contacted by a client regarding their encryption and hashing algorithms. Their in-house network administrator tells you that their current hashing algorithm is an older one with known weaknesses and is not collision resistant.Which algorithm are they most likely using for hashing?

Options:

A.

PKI

B.

SHA

C.

Kerberos

D.

MD5

Buy Now
Questions 5

Which of the following describes the acceptable amount of data loss measured in time?

Options:

A.

Recovery Consistency Objective (RCO)

B.

Recovery Time Objective (RTO)

C.

Recovery Point Objective (RPO)

D.

Recovery Time Actual (RTA)

Buy Now
Questions 6

Which of the following authentication methods is based on physical appearance of a user?

Options:

A.

Key fob

B.

Biometrics

C.

ID/password combination

D.

Smart card

Buy Now
Questions 7

Mark works as a Network Administrator for NetTech Inc. He wants to connect the company ' s headquarter and its regional offices using a WAN technology. For this, he uses packet-switched connection. Which of the following WAN technologies will Mark use to connect the offices? Each correct answer represents a complete solution. Choose two.

Options:

A.

ISDN

B.

X.25

C.

Frame Relay

D.

Leased line

Buy Now
Questions 8

Which of the following is responsible for maintaining certificates in a public key infrastructure (PKI)?

Options:

A.

Domain Controller

B.

Certificate User

C.

Certification Authority

D.

Internet Authentication Server

Buy Now
Questions 9

Which of the following methods of encryption uses a single key to encrypt and decrypt data?

Options:

A.

Asymmetric

B.

Symmetric

C.

S/MIME

D.

PGP

Buy Now
Questions 10

You are implementing some security services in an organization, such as smart cards, biometrics, access control lists, firewalls, intrusion detection systems, and clipping levels. Which of the following categories of implementation of the access control includes all these security services?

Options:

A.

Administrative access control

B.

Logical access control

C.

Physical access control

D.

Preventive access control

Buy Now
Questions 11

Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an enterprise?

Options:

A.

Eradication phase

B.

Recovery phase

C.

Containment phase

D.

Preparation phase

E.

Identification phase

Buy Now
Questions 12

Which of the following SDLC phases consists of the given security controls: Misuse Case Modeling Security Design and Architecture Review Threat and Risk Modeling Security Requirements and Test Cases Generation

Options:

A.

Design

B.

Maintenance

C.

Deployment

D.

Requirements Gathering

Buy Now
Questions 13

Which of the following protocols provides certificate-based authentication for virtual private networks (VPNs)?

Options:

A.

PPTP

B.

SMTP

C.

HTTPS

D.

L2TP

Buy Now
Questions 14

You work as a remote support technician. A user named Rick calls you for support. Rick wants to connect his LAN connection to the Internet. Which of the following devices will you suggest that he use?

Options:

A.

Hub

B.

Repeater

C.

Bridge

D.

Switch

E.

Router

Buy Now
Questions 15

Which of the following attacks allows the bypassing of access control lists on servers or routers, and helps an attacker to hide? Each correct answer represents a complete solution. Choose two.

Options:

A.

DNS cache poisoning

B.

MAC spoofing

C.

IP spoofing attack

D.

DDoS attack

Buy Now
Questions 16

Which of the following statements about Discretionary Access Control List (DACL) is true?

Options:

A.

It specifies whether an audit activity should be performed when an object attempts to access a resource.

B.

It is a unique number that identifies a user, group, and computer account.

C.

It is a list containing user accounts, groups, and computers that are allowed (or denied) access to the object.

D.

It is a rule list containing access control entries.

Buy Now
Questions 17

Which of the following statements are true about Public-key cryptography? Each correct answer represents a complete solution. Choose two.

Options:

A.

Data encrypted with the secret key can only be decrypted by another secret key.

B.

The secret key can encrypt a message, and anyone with the public key can decrypt it.

C.

The distinguishing technique used in public key-private key cryptography is the use of symmetric key algorithms.

D.

Data encrypted by the public key can only be decrypted by the secret key.

Buy Now
Questions 18

Which of the following security architectures defines how to integrate widely disparate applications for a world that is Web-based and uses multiple implementation platforms?

Options:

A.

Sherwood Applied Business Security Architecture

B.

Service-oriented modeling and architecture

C.

Enterprise architecture

D.

Service-oriented architecture

Buy Now
Questions 19

You work as a Network Administrator for McRoberts Inc. You are expanding your company ' s network. After you have implemented the network, you test the connectivity to a remote host by using the PING command. You get the ICMP echo reply message from the remote host. Which of the following layers of the OSI model are tested through this process? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Layer 3

B.

Layer 2

C.

Layer 4

D.

Layer 1

Buy Now
Questions 20

Which of the following protocols provides the highest level of VPN security with a VPN connection that uses the L2TP protocol?

Options:

A.

IPSec

B.

PPPoE

C.

PPP

D.

TFTP

Buy Now
Questions 21

Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?

Options:

A.

Safeguard

B.

Annualized Rate of Occurrence (ARO)

C.

Single Loss Expectancy (SLE)

D.

Exposure Factor (EF)

Buy Now
Questions 22

You work as a Security Manager for Tech Perfect Inc. A number of people are involved with you in the DRP efforts. You have maintained several different types of plan documents, intended for different audiences. Which of the following documents will be useful for you as well as public relations personnel who require a non-technical perspective on the entire organization ' s disaster recovery efforts?

Options:

A.

Technical guide

B.

Executive summary

C.

Checklist

D.

Department-specific plan

Buy Now
Questions 23

Which of the following statements about Network Address Translation (NAT) are true? Each correct answer represents a complete solution. Choose three.

Options:

A.

It hides the internal IP addressing scheme.

B.

It protects network from the password guessing attacks.

C.

It is used to connect private networks to the public Internet.

D.

It shares public Internet addresses with a large number of internal network clients.

Buy Now
Questions 24

Which of the following are natural environmental threats that an organization faces? Each correct answer represents a complete solution. Choose two.

Options:

A.

Strikes

B.

Floods

C.

Accidents

D.

Storms

Buy Now
Questions 25

You work as a Network Administrator for Net Perfect Inc. The company has a Linux-based network. You need to configure a firewall for the company. The firewall should be able to keep track of the state of network connections traveling across the network. Which of the following types of firewalls will you configure to accomplish the task?

Options:

A.

Stateful firewall

B.

Host-based application firewall

C.

A network-based application layer firewall

D.

An application firewall

Buy Now
Questions 26

You work as an administrator for Techraft Inc. Employees of your company create ' products ' , which are supposed to be given different levels of access. You need to configure a security policy in such a way that an employee (producer of the product) grants accessing privileges (such as read, write, or alter) for his product. Which of the following access control models will you use to accomplish this task?

Options:

A.

Discretionary access control (DAC)

B.

Role-based access control (RBAC)

C.

Mandatory access control (MAC)

D.

Access control list (ACL)

Buy Now
Questions 27

Which of the following encryption algorithms are based on block ciphers?

Options:

A.

RC4

B.

Twofish

C.

Rijndael

D.

RC5

Buy Now
Questions 28

Which of the following user authentications are supported by the SSH-1 protocol but not by the SSH-2 protocol? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

TIS authentication

B.

Rhosts (rsh-style) authentication

C.

Kerberos authentication

D.

Password-based authentication

Buy Now
Questions 29

You are responsible for security at a building that has a lot of traffic. There are even a significant number of non-employees coming in and out of the building. You are concerned about being able to find out who is in the building at a particular time. What is the simplest way to accomplish this?

Options:

A.

Implement a sign in sheet at the main entrance and route all traffic through there.

B.

Have all people entering the building use smart cards for access.

C.

Implement biometric access.

D.

Implement cameras at all entrances.

Buy Now
Questions 30

You work as a Network Administrator for McNeil Inc. The company has a TCP/IP-based network. Performance of the network is slow because of heavy traffic. A hub is used as a central connecting device in the network. Which of the following devices can be used in place of a hub to control the network traffic efficiently?

Options:

A.

Repeater

B.

Bridge

C.

Switch

D.

Router

Buy Now
Questions 31

Which of the following are used to suppress electrical and computer fires? Each correct answer represents a complete solution. Choose two.

Options:

A.

Halon

B.

Water

C.

CO2

D.

Soda acid

Buy Now
Questions 32

Which of the following security protocols provides confidentiality, integrity, and authentication of network traffic with end-to-end and intermediate-hop security?

Options:

A.

IPSec

B.

SET

C.

SWIPE

D.

SKIP

Buy Now
Questions 33

Adam works as a Network Administrator. He discovers that the wireless AP transmits 128 bytes of plaintext, and the station responds by encrypting the plaintext. It then transmits the resulting ciphertext using the same key and cipher that are used by WEP to encrypt subsequent network traffic. Which of the following types of authentication mechanism is used here?

Options:

A.

Pre-shared key authentication

B.

Open system authentication

C.

Shared key authentication

D.

Single key authentication

Buy Now
Questions 34

You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that this process is providing a way to spammers to perform different types of e-mail attacks. Which of the following phases of the Incident handling process will now be involved in resolving this process and find a solution? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

Identification

B.

Eradication

C.

Recovery

D.

Contamination

E.

Preparation

Buy Now
Questions 35

Which of the following are used to suppress gasoline and oil fires? Each correct answer represents a complete solution. Choose three.

Options:

A.

Water

B.

CO2

C.

Halon

D.

Soda acid

Buy Now
Questions 36

Which of the following is a form of gate that allows one person to pass at a time?

Options:

A.

Biometric

B.

Man-trap

C.

Turnstile

D.

Fence

Buy Now
Questions 37

The ATM of a bank is robbed by breaking the ATM machine. Which of the following physical security devices can now be used for verification and historical analysis of the ATM robbery?

Options:

A.

Key card

B.

Biometric devices

C.

Intrusion detection systems

D.

CCTV Cameras

Buy Now
Questions 38

Which of the following are the examples of technical controls? Each correct answer represents a complete solution. Choose three.

Options:

A.

Auditing

B.

Network acchitecture

C.

System access

D.

Data backups

Buy Now
Questions 39

Which of the following firewalls inspects the actual contents of packets?

Options:

A.

Packet filtering firewall

B.

Stateful inspection firewall

C.

Application-level firewall

D.

Circuit-level firewall

Buy Now
Questions 40

Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?

Options:

A.

Network-based

B.

Anomaly-based

C.

File-based

D.

Signature-based

Buy Now
Questions 41

Which of the following protocols is an alternative to certificate revocation lists (CRL) and allows the authenticity of a certificate to be immediately verified?

Options:

A.

RSTP

B.

SKIP

C.

OCSP

D.

HTTP

Buy Now
Questions 42

Sam is creating an e-commerce site. He wants a simple security solution that does not require each customer to have an individual key. Which of the following encryption methods will he use?

Options:

A.

Asymmetric encryption

B.

Symmetric encryption

C.

S/MIME

D.

PGP

Buy Now
Questions 43

Which of the following does PEAP use to authenticate the user inside an encrypted tunnel? Each correct answer represents a complete solution. Choose two.

Options:

A.

GTC

B.

MS-CHAP v2

C.

AES

D.

RC4

Buy Now
Questions 44

Which of the following statements about incremental backup are true? Each correct answer represents a complete solution. Choose two.

Options:

A.

It is the fastest method of backing up data.

B.

It is the slowest method for taking a data backup.

C.

It backs up the entire database, including the transaction log.

D.

It backs up only the files changed since the most recent backup and clears the archive bit.

Buy Now
Questions 45

You have decided to implement video surveillance in your company in order to enhance network security. Which of the following locations must have a camera in order to provide the minimum level of security for the network resources? Each correct answer represents a complete solution. Choose two.

Options:

A.

Parking lot

B.

All hallways

C.

Server Rooms

D.

All offices

E.

All entrance doors

Buy Now
Questions 46

Which of the following processes is used to identify relationships between mission critical applications, processes, and operations and all supporting elements?

Options:

A.

Critical path analysis

B.

Functional analysis

C.

Risk analysis

D.

Business impact analysis

Buy Now
Questions 47

In which of the following network topologies does the data travel around a loop in a single direction and pass through each device?

Options:

A.

Ring topology

B.

Tree topology

C.

Star topology

D.

Mesh topology

Buy Now
Questions 48

You work as a Network Administrator for NetTech Inc. You want to have secure communication on the company ' s intranet. You decide to use public key and private key pairs. What will you implement to accomplish this?

Options:

A.

Microsoft Internet Information Server (IIS)

B.

VPN

C.

FTP server

D.

Certificate server

Buy Now
Questions 49

Which of the following terms refers to a mechanism which proves that the sender really sent a particular message?

Options:

A.

Integrity

B.

Confidentiality

C.

Authentication

D.

Non-repudiation

Buy Now
Questions 50

You have been assigned the task of selecting a hash algorithm. The algorithm will be specifically used to ensure the integrity of certain sensitive files. It must use a 128 bit hash value. Which of the following should you use?

Options:

A.

AES

B.

SHA

C.

MD5

D.

DES

Buy Now
Questions 51

Which of the following elements of planning gap measures the gap between the total potential for the market and the actual current usage by all the consumers in the market?

Options:

A.

Project gap

B.

Product gap

C.

Competitive gap

D.

Usage gap

Buy Now
Questions 52

An organization is seeking to implement a hot site and wants to maintain a live database server at the backup site. Which of the following solutions will be the best for the organization?

Options:

A.

Electronic vaulting

B.

Remote journaling

C.

Remote mirroring

D.

Transaction logging

Buy Now
Questions 53

Which of the following protocols is used to compare two values calculated using the Message Digest (MD5) hashing function?

Options:

A.

CHAP

B.

PEAP

C.

EAP

D.

EAP-TLS

Buy Now
Questions 54

Which of the following statements best describes a certification authority?

Options:

A.

A certification authority is a technique to authenticate digital documents by using computer cryptography.

B.

A certification authority is a type of encryption that uses a public key and a private key pair for data encryption.

C.

A certification authority is an entity that issues digital certificates for use by other parties.

D.

A certification authority is a type of encryption that uses a single key to encrypt and decrypt data.

Buy Now
Questions 55

You work as a Project Manager for Tech Perfect Inc. You are creating a document which emphasizes the formal study of what your organization is doing currently and where it will be in the future. Which of the following analysis will help you in accomplishing the task?

Options:

A.

Cost-benefit analysis

B.

Gap analysis

C.

Requirement analysis

D.

Vulnerability analysis

Buy Now
Questions 56

Which of the following electrical events shows a sudden drop of power source that can cause a wide variety of problems on a PC or a network?

Options:

A.

Blackout

B.

Power spike

C.

Power sag

D.

Power surge

Buy Now
Questions 57

Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?

Options:

A.

Authentication

B.

Non-repudiation

C.

Integrity

D.

Confidentiality

Buy Now
Questions 58

You work as a Network Administrator for Blue Bell Inc. The company has a TCP-based network. The company has two offices in different cities. The company wants to connect the two offices by using a public network. You decide to configure a virtual private network (VPN) between the offices. Which of the following protocols is used by VPN for tunneling?

Options:

A.

L2TP

B.

HTTPS

C.

SSL

D.

IPSec

Buy Now
Questions 59

An authentication method uses smart cards as well as usernames and passwords for authentication. Which of the following authentication methods is being referred to?

Options:

A.

Mutual

B.

Anonymous

C.

Multi-factor

D.

Biometrics

Buy Now
Questions 60

Which of the following terms refers to the method that allows or restricts specific types of packets from crossing over the firewall?

Options:

A.

Hacking

B.

Packet filtering

C.

Web caching

D.

Spoofing

Buy Now
Questions 61

Which of the following types of halon is found in portable extinguishers and is stored as a liquid?

Options:

A.

Halon-f

B.

Halon 1301

C.

Halon 11

D.

Halon 1211

Buy Now
Questions 62

You want to connect a twisted pair cable segment to a fiber-optic cable segment. Which of the following networking devices will you use to accomplish the task?

Options:

A.

Hub

B.

Switch

C.

Repeater

D.

Router

Buy Now
Questions 63

SSH is a network protocol that allows data to be exchanged between two networks using a secure channel. Which of the following encryption algorithms can be used by the SSH protocol? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Blowfish

B.

DES

C.

IDEA

D.

RC4

Buy Now
Questions 64

Which of the following is used to authenticate asymmetric keys?

Options:

A.

Digital signature

B.

MAC Address

C.

Demilitarized zone (DMZ)

D.

Password

Buy Now
Questions 65

Which of the following should the administrator ensure during the test of a disaster recovery plan?

Options:

A.

Ensure that the plan works properly

B.

Ensure that all the servers in the organization are shut down.

C.

Ensure that each member of the disaster recovery team is aware of their responsibility.

D.

Ensure that all client computers in the organization are shut down.

Buy Now
Questions 66

Which of the following protocols is designed to efficiently handle high-speed data over wide area networks (WANs)?

Options:

A.

PPP

B.

X.25

C.

Frame relay

D.

SLIP

Buy Now
Questions 67

The simplest form of a firewall is a packet filtering firewall. Typically a router works as a packet-filtering firewall and has the capability to filter on some of the contents of packets. On which of the following layers of the OSI reference model do these routers filter information? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Transport layer

B.

Physical layer

C.

Data Link layer

D.

Network layer

Buy Now
Questions 68

Which of the following are the primary components of a discretionary access control (DAC) model? Each correct answer represents a complete solution. Choose two.

Options:

A.

User ' s group

B.

File and data ownership

C.

Smart card

D.

Access rights and permissions

Buy Now
Questions 69

Which of the following statements about a stream cipher are true? Each correct answer represents a complete solution. Choose three.

Options:

A.

It typically executes at a higher speed than a block cipher.

B.

It divides a message into blocks for processing.

C.

It typically executes at a slower speed than a block cipher.

D.

It divides a message into bits for processing.

E.

It is a symmetric key cipher.

Buy Now
Questions 70

Which of the following protocols provides connectionless integrity and data origin authentication of IP packets?

Options:

A.

ESP

B.

AH

C.

IKE

D.

ISAKMP

Buy Now
Questions 71

Kerberos is a computer network authentication protocol that allows individuals communicating over a non-secure network to prove their identity to one another in a secure manner. Which of the following statements are true about the Kerberos authentication scheme? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Kerberos requires continuous availability of a central server.

B.

Dictionary and brute force attacks on the initial TGS response to a client may reveal the subject ' s passwords.

C.

Kerberos builds on Asymmetric key cryptography and requires a trusted third party.

D.

Kerberos requires the clocks of the involved hosts to be synchronized.

Buy Now
Exam Code: ISSAP
Exam Name: ISSAP Information Systems Security Architecture Professional
Last Update: Sep 11, 2026
Questions: 237

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11