CISSP PRACTICE QUESTIONS – 20201125

Effective CISSP Questions

An unknown vulnerability is discovered after conducting a vulnerability scanning against your company’s official web site. You are analyzing it and calculating its score based on CVSS v3.1. Which of the following is not a mandatory metric?
A. Attack Vector (AV)
B. Exploit Code Maturity (E)
C. User Interaction (UI)
D. Privileges Required (PR)

Continue reading

CISSP PRACTICE QUESTIONS – 20201124

Effective CISSP Questions

You are conducting a vulnerability assessment against your company’s official web site. Which of the following should be scanned first?
A. Known weaknesses in the CWE List
B. Known vulnerabilities in the CVE List
C. Undiscovered or unknown vulnerabilities
D. The attack surface determined after the threat modeling

Continue reading

CISSP PRACTICE QUESTIONS – 20201123

Effective CISSP Questions

In a threat modeling meeting, the development team identified a couple of attack vectors. Most of them appear in the OWASP Top 10. Which of the following should be done first to address the attack surface?
A. Prioritize and sort the attack vectors
B. Calculate the risk exposure of each attack vector
C. Submit a change request to revise the architectural design
D. Evaluate and determine the scope of the attack surface to be addressed

Continue reading

CISSP PRACTICE QUESTIONS – 20201118

Effective CISSP Questions

Your company is implementing a solution for customer analytics that extracts, transforms, and loads data into the enterprise data warehouse from various information systems that collect and process customer data, subject to change as customers may move to new places and switch to new phones, etc. Which of the following is the best role to enforce data consistency and quality?
A. Data controller
B. Data owner
C. Data steward
D. Data custodian

Continue reading