Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 2Objective 6

2.6 - Determine Data Security Controls and Compliance Requirements CISSP Practice Questions (Page 1)

Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
10%of the exam

Questions 1–5

  1. 1application · medium

    A financial services firm is implementing a new customer relationship management (CRM) system that will store customer financial data. The firm must comply with the Payment Card Industry Data Security Standard (PCI DSS) for the credit card data processed in the system. The CRM also handles non-card personal data that is not subject to PCI DSS. The security team is defining the scope of controls. Which approach best aligns with PCI DSS requirements?

    Select an answer first
  2. 2application · medium

    A healthcare organization is implementing a new patient portal that allows patients to view their medical records online. The portal transmits data between the patient's browser and the web server using HTTPS. The organization also stores the records in an encrypted database. Which data states are protected by these controls?

    Select an answer first
  3. 3foundation · easy

    After selecting a set of security controls, an organization adjusts the control parameters to better fit their specific operational environment and risk tolerance. Which process does this represent?

    Select an answer first
  4. 4foundation · easy

    A security analyst is reviewing the data lifecycle and needs to categorize data that is currently being processed by a CPU in memory. Which data state does this scenario represent?

    Select an answer first
  5. 5foundation · easy

    A security administrator wants to prevent sensitive documents from being copied to USB drives or sent via email outside the organization. Which data protection method is most appropriate for this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.