Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the ISC CISSP Concentrations ISSMP Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the ISC ISSMP exam. To support your certification journey, we have made a selection of our premium 2026 CISSP Concentrations practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

Which of the following processes is used by remote users to make a secure connection to internal resources after establishing an Internet connection?

Options:

A.

Packet filtering

B.

Tunneling

C.

Packet sniffing

D.

Spoofing

Buy Now
Questions 5

In which of the following alternative processing sites is the backup facility maintained in a constant order, with a full complement of servers, workstations, and communication links ready to assume the primary operations responsibility?

Options:

A.

Mobile Site

B.

Cold Site

C.

Warm Site

D.

Hot Site

Buy Now
Questions 6

Against which of the following does SSH provide protection? Each correct answer represents a complete solution. Choose two.

Options:

A.

IP spoofing

B.

Broadcast storm

C.

Password sniffing

D.

DoS attack

Buy Now
Questions 7

Which of the following BCP teams handles financial arrangement, public relations, and media inquiries in the time of disaster recovery?

Options:

A.

Software team

B.

Off-site storage team

C.

Applications team

D.

Emergency-management team

Buy Now
Questions 8

You are advising a school district on disaster recovery plans. In case a disaster affects the main IT centers for the district they will need to be able to work from an alternate location. However, budget is an issue. Which of the following is most appropriate for this client?

Options:

A.

Cold site

B.

Off site

C.

Hot site

D.

Warm site

Buy Now
Questions 9

Configuration Management (CM) is an Information Technology Infrastructure Library (ITIL) IT Service Management (ITSM) process. Configuration Management is used for which of the following? 1.To account for all IT assets 2.To provide precise information support to other ITIL disciplines 3.To provide a solid base only for Incident and Problem Management 4.To verify configuration records and correct any exceptions

Options:

A.

1, 3, and 4 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

2, 3, and 4 only

Buy Now
Questions 10

Which of the following refers to the ability to ensure that the data is not modified or tampered with?

Options:

A.

Availability

B.

Non-repudiation

C.

Integrity

D.

Confidentiality

Buy Now
Questions 11

Which of the following is a process that identifies critical information to determine if friendly actions can be observed by adversary intelligence systems?

Options:

A.

IDS

B.

OPSEC

C.

HIDS

D.

NIDS

Buy Now
Questions 12

Which of the following recovery plans includes specific strategies and actions to deal with specific variances to assumptions resulting in a particular security problem, emergency, or state of affairs?

Options:

A.

Business continuity plan

B.

Disaster recovery plan

C.

Continuity of Operations Plan

D.

Contingency plan

Buy Now
Questions 13

Which of the following security models deal only with integrity? Each correct answer represents a complete solution. Choose two.

Options:

A.

Biba-Wilson

B.

Clark-Wilson

C.

Bell-LaPadula

D.

Biba

Buy Now
Questions 14

Which of the following access control models uses a predefined set of access privileges for an object of a system?

Options:

A.

Role-Based Access Control

B.

Mandatory Access Control

C.

Policy Access Control

D.

Discretionary Access Control

Buy Now
Questions 15

Which of the following characteristics are described by the DIAP Information Readiness Assessment function? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It performs vulnerability/threat analysis assessment.

B.

It identifies and generates IA requirements.

C.

It provides data needed to accurately assess IA readiness.

D.

It provides for entry and storage of individual system data.

Buy Now
Questions 16

Which of the following are the goals of risk management? Each correct answer represents a complete solution. Choose three.

Options:

A.

Assessing the impact of potential threats

B.

Identifying the accused

C.

Finding an economic balance between the impact of the risk and the cost of the countermeasure

D.

Identifying the risk

Buy Now
Questions 17

Fill in the blank with an appropriate phrase.________ An is an intensive application of the OPSEC process to an existing operation or activity by a multidiscipline team of experts.

Options:

A.

OPSEC assessment

Buy Now
Questions 18

Which of the following rated systems of the Orange book has mandatory protection of the TCB?

Options:

A.

B-rated

B.

C-rated

C.

D-rated

D.

A-rated

Buy Now
Questions 19

Which of the following laws is the first to implement penalties for the creator of viruses, worms, and other types of malicious code that causes harm to the computer systems?

Options:

A.

Gramm-Leach-Bliley Act

B.

Computer Fraud and Abuse Act

C.

Computer Security Act

D.

Digital Millennium Copyright Act

Buy Now
Questions 20

Which of the following options is an approach to restricting system access to authorized users?

Options:

A.

DAC

B.

MIC

C.

RBAC

D.

MAC

Buy Now
Questions 21

Which of the following are examples of administrative controls that involve all levels of employees within an organization and determine which users have access to what resources and information? Each correct answer represents a complete solution. Choose three.

Options:

A.

Employee registration and accounting

B.

Disaster preparedness and recovery plans

C.

Network authentication

D.

Training and awareness

E.

Encryption

Buy Now
Questions 22

Your project team has identified a project risk that must be responded to. The risk has been recorded in the risk register and the project team has been discussing potential risk responses for the risk event. The event is not likely to happen for several months but the probability of the event is high. Which one of the following is a valid response to the identified risk event?

Options:

A.

Earned value management

B.

Risk audit

C.

Technical performance measurement

D.

Corrective action

Buy Now
Questions 23

You work as a Web Administrator for Perfect World Inc. The company is planning to host an E-commerce Web site. You are required to design a security plan for it. Client computers with different operating systems will access the Web server. How will you configure the Web server so that it is secure and only authenticated users are able to access it? Each correct answer represents a part of the solution. Choose two.

Options:

A.

Use encrypted authentication.

B.

Use the SSL protocol.

C.

Use the EAP protocol.

D.

Use Basic authentication.

Buy Now
Questions 24

Which of the following statements are true about security risks? Each correct answer represents a complete solution. Choose three.

Options:

A.

They can be analyzed and measured by the risk analysis process.

B.

They can be removed completely by taking proper actions.

C.

They can be mitigated by reviewing and taking responsible actions based on possible risks.

D.

They are considered an indicator of threats coupled with vulnerability.

Buy Now
Questions 25

Which of the following BCP teams provides clerical support to the other teams and serves as a message center for the user-recovery site?

Options:

A.

Security team

B.

Data preparation and records team

C.

Administrative support team

D.

Emergency operations team

Buy Now
Questions 26

Which of the following U.S. Federal laws addresses computer crime activities in communication lines, stations, or systems?

Options:

A.

18 U.S.C. 1362

B.

18 U.S.C. 1030

C.

18 U.S.C. 1029

D.

18 U.S.C. 2701

E.

18 U.S.C. 2510

Buy Now
Questions 27

Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not?

Options:

A.

Data custodian

B.

Auditor

C.

User

D.

Data owner

Buy Now
Questions 28

You are the project manager of the HJK Project for your organization. You and the project team have created risk responses for many of the risk events in the project. Where should you document the proposed responses and the current status of all identified risks?

Options:

A.

Risk management plan

B.

Lessons learned documentation

C.

Risk register

D.

Stakeholder management strategy

Buy Now
Questions 29

Mark works as a security manager for SoftTech Inc. He is performing a security awareness program. To be successful in performing the awareness program, he should take into account the needs and current levels of training and understanding of the employees and audience. There are five key ways, which Mark should keep in mind while performing this activity. Current level of computer usage What the audience really wants to learn How receptive the audience is to the security program How to gain acceptance Who might be a possible ally Which of the following activities is performed in this security awareness process?

Options:

A.

Separation of duties

B.

Stunned owl syndrome

C.

Audience participation

D.

Audience segmentation

Buy Now
Questions 30

Which of the following rate systems of the Orange book has no security controls?

Options:

A.

D-rated

B.

C-rated

C.

E-rated

D.

A-rated

Buy Now
Questions 31

Which of the following statements about Due Care policy is true?

Options:

A.

It is a method used to authenticate users on a network.

B.

It is a method for securing database servers.

C.

It identifies the level of confidentiality of information.

D.

It provides information about new viruses.

Buy Now
Questions 32

Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee's computer while he is typing in his password at any access point such as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?

Options:

A.

Availability

B.

Confidentiality

C.

Integrity

D.

Authenticity

Buy Now
Questions 33

How can you calculate the Annualized Loss Expectancy (ALE) that may occur due to a threat?

Options:

A.

Single Loss Expectancy (SLE)/ Exposure Factor (EF)

B.

Asset Value X Exposure Factor (EF)

C.

Exposure Factor (EF)/Single Loss Expectancy (SLE)

D.

Single Loss Expectancy (SLE) X Annualized Rate of Occurrence (ARO)

Buy Now
Questions 34

Which of the following Acts enacted in United States allows the FBI to issue National Security Letters (NSLs) to Internet service providers (ISPs) ordering them to disclose records about their customers?

Options:

A.

Electronic Communications Privacy Act of 1986

B.

Wiretap Act

C.

Computer Fraud and Abuse Act

D.

Economic Espionage Act of 1996

Buy Now
Questions 35

Which of the following governance bodies provides management, operational and technical controls to satisfy security requirements?

Options:

A.

Senior Management

B.

Business Unit Manager

C.

Information Security Steering Committee

D.

Chief Information Security Officer

Buy Now
Questions 36

Della works as a security manager for SoftTech Inc. She is training some of the newly recruited personnel in the field of security management. She is giving a tutorial on DRP. She explains that the major goal of a disaster recovery plan is to provide an organized way to make decisions if a disruptive event occurs and asks for the other objectives of the DRP. If you are among some of the newly recruited personnel in SoftTech Inc, what will be your answer for her question? Each correct answer represents a part of the solution. Choose three.

Options:

A.

Protect an organization from major computer services failure.

B.

Minimize the risk to the organization from delays in providing services.

C.

Guarantee the reliability of standby systems through testing and simulation.

D.

Maximize the decision-making required by personnel during a disaster.

Buy Now
Questions 37

Mark is the project manager of the NHQ project in Spartech Inc. The project has an asset valued at $195,000 and is subjected to an exposure factor of 35 percent. What will be the Single Loss Expectancy of the project?

Options:

A.

$92,600

B.

$67,250

C.

$68,250

D.

$72,650

Buy Now
Questions 38

Which of the following access control models are used in the commercial sector? Each correct answer represents a complete solution. Choose two.

Options:

A.

Clark-Biba model

B.

Clark-Wilson model

C.

Bell-LaPadula model

D.

Biba model

Buy Now
Questions 39

Which of the following are the ways of sending secure e-mail messages over the Internet? Each correct answer represents a complete solution. Choose two.

Options:

A.

TLS

B.

PGP

C.

S/MIME

D.

IPSec

Buy Now
Questions 40

Your project has several risks that may cause serious financial impact should they happen. You have studied the risk events and made some potential risk responses for the risk events but management wants you to do more. They'd like for you to create some type of a chart that identified the risk probability and impact with a financial amount for each risk event. What is the likely outcome of creating this type of chart?

Options:

A.

Quantitative analysis

B.

Contingency reserve

C.

Risk response

D.

Risk response plan

Buy Now
Questions 41

Which of the following involves changing data prior to or during input to a computer in an effort to commit fraud?

Options:

A.

Data diddling

B.

Wiretapping

C.

Eavesdropping

D.

Spoofing

Buy Now
Questions 42

Which of the following elements of BCP process includes the areas of plan implementation, plan testing, and ongoing plan maintenance, and also involves defining and documenting the continuity strategy?

Options:

A.

Business continuity plan development

B.

Business impact assessment

C.

Scope and plan initiation

D.

Plan approval and implementation

Buy Now
Questions 43

You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extension of your enterprise. The networking, to be done in the new extension, requires different types of cables and an appropriate policy that will be decided by you. Which of the following stages in the Incident handling process involves your decision making?

Options:

A.

Preparation

B.

Eradication

C.

Identification

D.

Containment

Buy Now
Questions 44

Which of the following statements is true about auditing?

Options:

A.

It is used to protect the network against virus attacks.

B.

It is used to track user accounts for file and object access, logon attempts, etc.

C.

It is used to secure the network or the computers on the network.

D.

It is used to prevent unauthorized access to network resources.

Buy Now
Questions 45

Which of the following statements about system hardening are true? Each correct answer represents a complete solution. Choose two.

Options:

A.

It can be achieved by installing service packs and security updates on a regular basis.

B.

It is used for securing the computer hardware.

C.

It can be achieved by locking the computer room.

D.

It is used for securing an operating system.

Buy Now
Questions 46

Ned is the program manager for his organization and he's considering some new materials for his program. He and his team have never worked with these materials before and he wants to ask the vendor for some additional information, a demon, and even some samples. What type of a document should Ned send to the vendor?

Options:

A.

IFB

B.

RFQ

C.

RFP

D.

RFI

Buy Now
Questions 47

Which of the following are examples of physical controls used to prevent unauthorized access to sensitive materials?

Options:

A.

Thermal alarm systems

B.

Closed circuit cameras

C.

Encryption

D.

Security Guards

Buy Now
Questions 48

Which of the following authentication protocols provides support for a wide range of authentication methods, such as smart cards and certificates?

Options:

A.

PAP

B.

EAP

C.

MS-CHAP v2

D.

CHAP

Buy Now
Questions 49

Which of the following anti-child pornography organizations helps local communities to create programs and develop strategies to investigate child exploitation?

Options:

A.

Internet Crimes Against Children (ICAC)

B.

Project Safe Childhood (PSC)

C.

Anti-Child Porn.org

D.

Innocent Images National Imitative (IINI)

Buy Now
Questions 50

Which of the following liabilities is a third-party liability in which an individual may be responsible for an action by another party?

Options:

A.

Relational liability

B.

Engaged liability

C.

Contributory liability

D.

Vicarious liability

Buy Now
Questions 51

Which of the following is a documentation of guidelines that computer forensics experts use to handle evidences?

Options:

A.

Evidence access policy

B.

Incident response policy

C.

Chain of custody

D.

Chain of evidence

Buy Now
Questions 52

Which of the following signatures watches for the connection attempts to well-known, frequently attacked ports?

Options:

A.

Port signatures

B.

Digital signatures

C.

Header condition signatures

D.

String signatures

Buy Now
Questions 53

Change Management is used to ensure that standardized methods and procedures are used for efficient handling of all changes. Who decides the category of a change?

Options:

A.

The Problem Manager

B.

The Process Manager

C.

The Change Manager

D.

The Service Desk

E.

The Change Advisory Board

Buy Now
Questions 54

You are the project manager for TTX project. You have to procure some electronics gadgets for the project. A relative of yours is in the retail business of those gadgets. He approaches you for your favor to get the order. This is the situation of ____.

Options:

A.

Conflict of interest

B.

Bribery

C.

Illegal practice

D.

Irresponsible practice

Buy Now
Questions 55

Fill in the blank with an appropriate phrase.______________ is used to provide security mechanisms for the storage, processing, and transfer of data.

Options:

A.

Data classification

Buy Now
Questions 56

Fill in the blank with an appropriate phrase. _______is a branch of forensic science pertaining to legal evidence found in computers and digital storage media.

Options:

A.

Computer forensics

Buy Now
Questions 57

You are the project manager of the NGQQ Project for your company. To help you communicate project status to your stakeholders, you are going to create a stakeholder register. All of the following information should be included in the stakeholder register except for which one?

Options:

A.

Identification information for each stakeholder

B.

Assessment information of the stakeholders' major requirements, expectations, and potential influence

C.

Stakeholder classification of their role in the project

D.

Stakeholder management strategy

Buy Now
Questions 58

Which of the following is a formula, practice, process, design, instrument, pattern, or compilation of information which is not generally known, but by which a business can obtain an economic advantage over its competitors?

Options:

A.

Utility model

B.

Cookie

C.

Copyright

D.

Trade secret

Buy Now
Questions 59

You work as the Senior Project manager in Dotcoiss Inc. Your company has started a software project using configuration management and has completed 70% of it. You need to ensure that the network infrastructure devices and networking standards used in this project are installed in accordance with the requirements of its detailed project design documentation. Which of the following procedures will you employ to accomplish the task?

Options:

A.

Configuration identification

B.

Physical configuration audit

C.

Configuration control

D.

Functional configuration audit

Buy Now
Questions 60

Which of the following is a process of monitoring data packets that travel across a network?

Options:

A.

Password guessing

B.

Packet sniffing

C.

Shielding

D.

Packet filtering

Buy Now
Questions 61

Which of the following is a name, symbol, or slogan with which a product is identified?

Options:

A.

Copyright

B.

Trademark

C.

Trade secret

D.

Patent

Buy Now
Questions 62

In which of the following SDLC phases is the system's security features configured and enabled, the system is tested and installed or fielded, and the system is authorized for processing?

Options:

A.

Initiation Phase

B.

Development/Acquisition Phase

C.

Implementation Phase

D.

Operation/Maintenance Phase

Buy Now
Questions 63

What is a stakeholder analysis chart?

Options:

A.

It is a matrix that documents stakeholders' threats, perceived threats, and communication needs.

B.

It is a matrix that identifies all of the stakeholders and to whom they must report to.

C.

It is a matrix that documents the stakeholders' requirements, when the requirements were created, and when the fulfillment of the requirements took place..

D.

It is a matrix that identifies who must communicate with whom.

Buy Now
Questions 64

Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC) is based on the Mandatory Access Control (MAC) policy?

Options:

A.

Division A

B.

Division D

C.

Division B

D.

Division C

Buy Now
Questions 65

Which of the following penetration testing phases involves reconnaissance or data gathering?

Options:

A.

Attack phase

B.

Pre-attack phase

C.

Post-attack phase

D.

Out-attack phase

Buy Now
Exam Code: ISSMP
Exam Name: ISSMPĀ®: Information Systems Security Management Professional
Last Update: Sep 12, 2026
Questions: 218

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11