CISSP Practice Exam 1
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 52% Most missed: “Barry is an intern at Our Days Corp and needs to print his boss' schedule. Which…”

Contains practice exam questions from all eight domains, and they are weighted as follows:    
15% from Security and Risk Management    
10% from Asset Security    
13% from Security Architecture and Engineering    
13% from Communication and Network Security    
13% from Identity and Access Management    
12% from Security Assessment and Testing    
13% from Security Operations    
11% from Software Development Security    

CISSP Practice Exam 1
Time left 00:00
25 Questions

1. Which of these is NOT true?
2. Which of the following is the biggest risk of a company converting from Waterfall development to CI/CD?
3. Jorda, a computer engineer, wishes to add routers that make routing decisions based on hop count only. Which protocol should she select?
4. During the change management process, the process of scheduling the installation of a change should occur at which step?
5. Webber, a systems administrator, has installed a new service that requires port 59040 to be used. The service continually fails until he realizes that the firewall must be programmed to allow port 59040. When this new service is blocked, it is considered to be which of the following?
6. Shivani is a network engineer, and her manager recognizes hundreds of phishing attacks coming from the country of Hackistan. Which access control model is BEST used to deny these attacks?
7. Many social networking sites, such as Facebook, protect communications with which service to secure conversations from hackers?
8. When interrogating a suspect or interviewing a witness, ideally, how many investigators should be in the room during the questioning?
9. Which of the following is the BEST example of exception management?
10. A centralized system that correlates, analyzes, and retains log files for the entire corporate network is known as which device?
11. Joseph is a network engineer and suspects that a new switch on the network is fraudulent. What step can he take to test whether it belongs on the network?
12. Marylin has just opened her new GolfCo golf supply business and is ready to take orders on her brand-new multi-function fax machine. A few months later, she receives several complaints, stating that someone representing GolfCo is demanding payments for fees already paid, and desires repayment by gift cards. What is the MOST LIKELY problem here?
13. Non-compete agreements are generally unenforceable because of which reason?
14. Which of the following is an electro-mechanical type of alarm system?
15. Out of the following encryption methods, which system is considered impossible to crack?
16. The device that resides on system motherboards to manage encryption and passwords is called what?
17. Paul is part of the network security team, and they are setting up Wi-Fi that allows any employee to connect to the network when at the office. Which feature should he recommend for network security?
18. Tiger is a software engineer who has convinced his supervisor to delay the project for 1 month to code security mitigations. Why did his supervisor take his advice?
19. Billy is a CISO and proposes to his security team the idea of using a virtual machine snapshot to deploy a virtual desktop infrastructure (VDI). The snapshot image is also known as a(n) what?
20. Madea is a security manager and is updating policies for staff and vendors. Controls in this area are considered which of the following?
21. Which is the BEST mitigation for zero-day attacks?
22. Which VPN protocol operates at layer 2 of the OSI model using 256-bit encryption?
23. For single sign-on systems, what does geo-velocity mean?
24. Tyler has been notified that she has just made a purchase of $150 from Tarmert that she does not recognize. Her email reports several messages regarding bad login attempts to other online stores. What is MOST LIKELY occurring?
25. Which ports are considered the well-known ports?