CISSP PRACTICE QUESTIONS – 20211015

Effective CISSP Questions

After risk assessment, your company plans to equip laptops used by sales representatives with FIPS 140-2 Level 3 compliant self-encrypting drives as a countermeasure to protect around 10% of confidential data stored on hard drives. You are analyzing the residual risk using a quantitative approach in another iteration of risk assessment after the risk treatment. Which of the following is the primary and direct factor subject to change due to the risk treatment? (Wentz QOTD)
A. Asset value
B. Exposure factor
C. Annual loss expectancy
D. Annualized rate of occurrence

Continue reading

CISSP PRACTICE QUESTIONS – 20211014

Effective CISSP Questions

An information system needs the official management decision given by a senior organizational official to authorize the operation and to accept the residual risk explicitly. Which of the following provides the final decision? (Wentz QOTD)
A. Risk-based auditing
B. Authoritative accreditation
C. Comprehensive security assessment
D. Third-party security evaluation using objective criteria

Continue reading

CISSP PRACTICE QUESTIONS – 20211012

Effective CISSP Questions

A financial specialist in your company needs a specific version of a spreadsheet that is enlisted in your company’s whitelist of approved software. As a member of the IT support team, which of the following should you do first? (Wentz QOTD)
A. Submit a change request to install the specified software
B. Download the software from the open-source community
C. Ensure the software is the latest version
D. Install the software stored on the company’s distribution points

Continue reading