Browse all practice questions for the CISSP Domain 1 – Security and Risk Management Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 1 Practice Test 2026 – Complete Security and Risk Management Prep course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What does control analysis primarily assess?
  • What does PCI-DSS stand for and relate to?
  • Integrity in data security is dependent on which other principle?
  • What is the purpose of Annualized Loss Expectancy (ALE)?
  • What are the three elements included in the CIA triad?
  • What does the GLBA focus on protecting?
  • Which of the following falls under Type II Authentication?
  • What is the primary focus of Authentication in information security?
  • Which of the following represents a method of Authentication?
  • What must be ensured for evidence to be admissible according to the Best Evidence Rule?
  • What type of attacker is primarily government or state-sponsored, using the internet as a tool against certain systems?
  • What does the ISO 27000 series emphasize regarding the management of information security?
  • In terms of objects and subjects in security, what does a subject refer to?
  • What does authorization determine in an access control model?
  • What is Residual Risk defined as?
  • What constitutes a common attack related to patents?
  • Which type of Authentication involves something you know?
  • Which category of access control is designed to prevent an attack from happening?
  • What aspect of availability ensures a resource is easy to use and understand?
  • What is a key legal limitation associated with trade secrets?
  • Which type of Authentication does NOT rely on physical attributes?
  • Too much availability can negatively influence which of the following?
  • Who carries the most liability in an organization regarding security?
  • What does the OECD Privacy Guideline primarily address?
  • Which of the following defines a threat in security terms?
  • Which of the following methods is critical to maintaining the integrity of evidence?
  • In the acquisition process, what should organizations ensure about their standards?
  • Which action is typically taken to mitigate insider threats?
  • What is typically included in agreements with third parties to ensure security compliance?
  • What characterizes an insider threat?
  • Who is most likely to be responsible for ensuring accountability in an organization?
  • What best describes the purpose of contractual rights in third-party agreements?
  • What strategy can mitigate the likelihood of falling victim to targeted phishing attacks?
  • Which principle is NOT part of security governance principles?
  • Which security measure breaches the condition of integrity through data alteration?
  • What is a common method to ensure data confidentiality while in transport?
  • Which type of Authentication utilizes geolocation as a factor?
  • Which step is NOT part of the 9-step process for Risk Management Framework?
  • Which concept poses a significant risk associated with honeypots?
  • Non-repudiation in cybersecurity primarily utilizes which two concepts?
  • What is the impact of excessive confidentiality on data management?
  • What is the principle of Defense in Depth in security management?
  • What can result from gross negligence under SOX?
  • What proof standard is typically required in Administrative Law?
  • What does "CIA" stand for in security terminology?
  • What framework is recommended for risk management according to the NIST guidelines?
  • What type of access control detects an attack during or after it has occurred?
  • What does Type III Authentication refer to?
  • What could a Type I Authentication method include?
  • Which category do hardware and software components fall under in security controls?
  • What is the role of chain of custody in legal evidence?
  • According to IAB's Ethics and the Internet, which action is prohibited?
  • What is the primary characteristic of entrapment in a legal context?
  • What is forensic imaging primarily concerned with?
  • What is the focus of management in the context of governance?
  • What is the legal requirement of the Security Breach Notification Law?
  • Which attack vector is characterized by targeting specific individuals with personalized messages?
  • How are standards characterized in a security context?
  • Who are referred to as Script Kiddies?
  • Which ISO standard directs how to protect Personal Health Information (PHI)?
  • Which governance principle emphasizes accessing only necessary information?
  • Why is evidence integrity a vital consideration in legal proceedings?
  • How does a government attacker typically operate?
  • What do administrative (directive) controls encompass?
  • Which access control type aims to reduce the severity of an attack after it occurs?
  • Which element of the IAAA framework involves ensuring user identity is established?
  • What is a Hacktivist known for?
  • Circumstantial evidence is best defined as which of the following?
  • Which aspect does NOT contribute to establishing a chain of custody?
  • What do the principles of Availability in security depend on?
  • What is the primary purpose of accountability in cybersecurity?
  • Which risk response strategy involves applying efforts to reduce the risk?
  • Which of the following has a heavy impact on individual liability in security matters?
  • What capabilities does the PATRIOT Act of 2001 expand?
  • What area does SOX of 2002 regulate?
  • COBIT is designed to align IT goals with what?
  • Which of the following is a characteristic of mandatory procedures?
  • What risk response strategy involves knowing the risk exists and accepting the implications?
  • Which of the following laws specifically addresses consumer privacy in financial institutions?
  • Which of the following is one of the Ten Commandments from the Computer Ethics Institute?
  • What defines guidelines in the context of organizational policies?
  • Layered defense primarily improves which three aspects of information security?
  • What kind of risk management approach does OCTAVE represent?
  • Which type of law is enacted by government agencies?
  • When integrating new technology, what should standards reflect?
  • Before utilizing honeypots, what is a crucial step that should be taken?
  • Which type of phishing attack is specifically targeted at senior leadership within an organization?
  • Which law is most commonly used to prosecute computer crimes?
  • What is the primary goal of confidentiality in security practices?
  • Which principle is emphasized in the (ISC)2 code regarding professional behavior?
  • Which of the following best describes the intent of the Ten Commandments from the Computer Ethics Institute?
  • What characterizes the EU Data Protection Directive?
  • What describes a GreyHat hacker?
  • What defines a trade secret?
  • What does the ECPA protect against?
  • What is the main consequence of Civil Law or Tort Law?
  • What is auditing in the context of information security?
  • What is the main focus of the ISO 27000 series?
  • Which type of hacker is typically known as an ethical hacker?
  • According to the (ISC)2 Code of Ethics, which of the following is a primary focus?
  • What is the meaning of Compensating controls in risk management?
  • In the context of IT, what is considered secondary evidence?
  • Which of the following would be included in result documentation?
  • What does PCI-DSS stand for, and what is its primary purpose?
  • What does the Risk Formula state?
  • What is a primary function of physical controls?
  • How long does copyright protection last for an individual creator?
  • Which statement best describes the nature of US privacy regulation?
  • What role do C-level executives play in governance?
  • What approach does ISO 27005 provide for risk management?
  • What is a key function of the Authorization process?
  • What is a key component of HIPAA in relation to data protection?
  • Which type of Authentication includes physical items like tokens or smart cards?
  • What is patent infringement typically characterized by?
  • Continuous improvement in an organization’s security governance is aimed at achieving what?
  • What does ISO 27002 primarily provide guidance on?
  • In relation to federal rules regarding evidence, what does Rule 803 allow for?
  • What is commonly implemented as a technical measure to combat phishing attacks?
  • What is a key focus of Administrative Law?
  • Which statement is true regarding the Security Breach Notification Law in most states?
  • What is the nature of security policies within an organization?
  • What does due care refer to in the context of IT security?
  • What does the Fourth Amendment specifically protect citizens from?
  • What is one effective method for preventing social engineering email attacks?
  • Which of the following describes the attributes of a typical bot controlled by a botnet?
  • In terms of data privacy, what does 'due diligence' refer to?
  • When splitting or divesting from a company, what is essential to maintain concerning data?
  • What is the primary focus of the Wassenaar Arrangement?
  • What are procedures primarily characterized as?
  • What is the definition of Identification in the context of security?
  • What is the primary focus of qualitative risk analysis?
  • Which of the following is NOT a type of risk response strategy?
  • What does ITIL stand for in the context of information technology?
  • Which of the following describes the assurance that the widest range of subjects can interact with a resource?
  • What does due diligence pertain to in IT security?
  • Which principle is viewed as the primary goal of a security infrastructure?
  • What type of risk response involves shifting the risk management responsibility to a third party?
  • What inherently makes hearsay generally inadmissible in court?
  • What are the three main rules outlined by HIPAA regarding PHI?
  • What type of compliance is associated with Private Regulations?
  • The implementation of which standard is essential for an organization to achieve compliance with information security best practices?
  • Which ISO standard focuses on how to measure success of an ISMS?
  • How can cybersquatting be legally defined?
  • Which of the following is NOT a mandate under HIPAA?
  • What type of agreement is commonly associated with third-party interactions regarding security?
  • What is the primary focus of the FRAP methodology?
  • Which term refers to unauthorized individuals attempting to access systems?
  • What is the primary goal of the COSO framework for an IT organization?
  • What is the purpose of ISO 27004?
  • What is the primary purpose of a botnet controlled by a bot-herder?
  • How does enticement differ from entrapment?
  • What does vulnerability identification involve?
  • Malicious attacks and component failures are threats to which principle?
  • What is the purpose of baselines or benchmarks in an organization?
  • What element does the layered defense strategy aim to enhance in a security framework?
  • Which principle relates to being correct and accurate in data representation?
  • What is included in the ISC2 Code of Ethics Canons?
  • What is the primary intent of typosquatting?
  • What is an example of what security policies might cover?
  • Which of the following is considered direct evidence?
  • How many laws are covered in the CISSP exam according to the standard curriculum?
  • Which term describes computers infected with malware that are controlled remotely by a botnet?
  • What does likelihood determination assess in risk management?
  • What should employees be familiar with regarding their organization?
  • Which of the following describes an exception to copyright laws?
  • What does the concept of confidentiality in security aim to protect?
  • What does maintaining Integrity ensure in a data environment?
  • What defines a BlackHat hacker?
  • What type of evidence supports facts but may not stand alone as proof?
  • What is a botnet?
  • Which of the following is an example of Identification?
  • What type of phishing attack involves using voice communication platforms?
  • What is the primary role of a vulnerability in risk management?
  • What defines collaborative evidence in legal terms?
  • Which element in the IAAA framework corresponds to tracking accountability?
  • To which areas does Defense in Depth apply?
  • Which ISO standard focuses on the establishment, implementation, control, and improvement of an Information Security Management System (ISMS)?
  • What term describes a true reflection of reality?
  • In legal terms, gray areas in the law are determined by what?
  • In the context of Authentication, what does Type V represent?
  • What does the principle of availability ensure?
  • Which of the following best describes the EU's approach to privacy?
  • What is a primary goal of implementing Defense in Depth within an organization?
  • Which term refers to the expected cost if a risk occurs once?
  • What is the primary characteristic of negligence in legal terms?
  • What is the maximum duration that registered trademarks can remain valid?
  • What does Integrity refer to in the context of security?
  • How do technical controls primarily help in an organization?
  • What is the formal definition of Authorization?
  • Which of the following is a method for establishing non-repudiation?
  • Which concept ensures that an action cannot be denied after it has been performed?
  • What does accountability in a security context often involve?
  • What type of evidence is described as tangible and physical?
  • What is meant by the term "Total Risk" in risk analysis?
  • Which principle is characterized by being responsible for actions and outcomes?
  • In terms of email attacks, what does 'training and awareness' refer to?
  • What is one of the criteria for a patent to be granted?
  • In Criminal Law, what is required to prove a case?
  • What is typically included in physical controls?
  • What aspect does the prudent person rule emphasize in due care?
  • Which type of email attack is characterized by its targeted approach, often at specific individuals?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy