Home > General Studies (Hindi) > Quizzes > CISSP Domain 1: Security and Risk Management
CISSP Domain 1: Security and Risk Management
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 45% Most missed: “Montrie is required to destroy card verification value (CVV) codes after transac…”

Domain 1: Security and Risk Management Practice Questions
Questions from the following topics are included in this domain:
Basics of security and risk management
    Differing data roles and responsibilities
    Identifying administrative, physical, and technical controls
    Ethics of security professionals
    Administrative policies, procedures, and guidelines
    Object categorization and classification
    Importance of security training

CISSP Domain 1: Security and Risk Management
Time left 00:00
25 Questions

1. Sofia, a senior manager, needs to get a Linux update installed on her team's server. Central IT has not performed the update even after being asked three times. Sofia selects a team member to install it and work around the IT department. This is BEST referred to as:
2. Roger, the chief financial officer (CFO) of NUS Micro, just received an email from his boss requesting he immediately wire $50 million to China to close a business deal. He calls his boss but cannot reach him. The email looks genuine, including the email address and domain name. He wires the money, only to find out later that his boss did not make this request. This represents which type of attack?
3. Garbine performs inspections of whether security policies, procedures, standards, and guidelines are followed according to the organization's security objectives. What is her role for the firm?
4. Simon needs to calculate risk. Which formula will he use?
5. Gwendolyn completes all the backups for her cloud subscribers. What is her role at the company?
6. Lleyton is planning on hiring 50 new engineers. What should be his FIRST step when reviewing new candidates?
7. Trevor is considering transferring much of his organization's data to the cloud. Which vendor-neutral certification helps him to validate that the cloud provider has good security quality assurance (QA)?
8. Kei, a security manager, just completed a risk assessment with his team, and they determined that the new planned plant location was too dangerous, so they decided not to expand there. Which risk response did his team use?
9. An organization is initiating the qualitative risk analysis process. Which of the following is NOT part of the process?
10. Dito works in the Detroit office of the organization, and Greg states a management opportunity is soon opening and guarantees that Dito will get the job. Dito would feel more comfortable if the verbal guarantee came with a(n):
11. Zosimo works for Maximo Smartphones, and for years, their new smartphone plans have been leaked to the public 2 years ahead of time, hurting sales. What is the BEST administrative control he can use to stop this?
12. Novak is preparing a DR exercise and emails the emergency task lists to the DR teams for review. Which type of exercise is he running?
13. Shewan's credit card information was stolen, and she realizes this occurred at the AXQA store. She believes the owner should go to prison. Which would MOST LIKELY occur?
14. Zulene has spent weeks collecting pricing, performance, and tuning data to conduct her risk assessment meeting. Now that she has all the data, her team will perform which type of risk analysis?
15. Ons, a security manager, is working with her team to develop and update policies for staff and vendors. Controls in this area are considered which of the following?
16. NIST outlines security controls to put in place of federal agencies in which Special Publication (SP)?
17. Viktor is conducting a risk assessment and needs to determine the percentage of risk his organization would suffer if an asset is compromised. Which of the following signifies this aspect of risk?
18. Victoria has worked in several departments of the company, including marketing, quality, and production. An audit found she still has privileges in all of her past departments even though she works in finance. This is called:
19. Teecee is running the computer sales department and sees that her team has sold $600,000 of their yearly goal of $1,000,000. What are the key performance indicator (KPI) and the key goal indicator (KGI)?
20. Dorian automatically backs up his smartphone nightly to the cloud. Does this represent safety, confidentiality, integrity, or availability?
21. Which of the following is NOT a directive control type?
22. Attacks such as dumpster diving, phishing, baiting, and piggybacking all represent a class of attacks called:
23. Coop, a security manager, practices decrypting secure documents. He has plain text of some of the files and needs to decrypt the rest. Which attack should he use?
24. Daniil has finished a successful career with DDA Motors. As part of the exit interview, he's required to return everything Except for:
25. Rafael, a systems administrator, notices that spam and phishing attacks are increasing. Which is the next BEST step he can take to safeguard the organization?