
Certified Information Systems Security Professional
Domain 2Objective 6
2.6 - Determine Data Security Controls and Compliance Requirements CISSP Practice Questions (Page 2)
Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)
18questions here
4free pages
4concepts
10%of the exam
Questions 6–10
- 6
A pharmaceutical company shares clinical trial reports with external regulatory partners via a secure document portal. The reports contain personally identifiable information (PII) and must not be forwarded, printed, or screenshotted. The company also needs to track who accesses each document and revoke access remotely if a partner's account is compromised. Which data protection method best meets these requirements?
Select an answer first - 7
A company is designing a secure data storage solution for sensitive customer data. The data is stored in an encrypted database, transmitted over TLS to authorized users, and processed in memory by applications. The security team is evaluating controls for each data state. Which control is most appropriate for protecting data in use?
Select an answer first - 8
A company is implementing a data protection strategy for sensitive documents shared with external partners. The documents contain trade secrets and must be protected even after they are downloaded. The company also needs to prevent unauthorized access to the documents if a partner's account is compromised. Which combination of controls best meets these requirements?
Select an answer first - 9
An organization operating in the European Union must select a security standard to comply with legal requirements for protecting the personal data of EU citizens. Which standard is most directly applicable?
Select an answer first - 10
A multinational corporation must protect personal data of EU residents. The company's legal team confirms that the General Data Protection Regulation (GDPR) applies. The company also has contractual obligations with a US client to protect the client's trade secrets. The security team is selecting a security standard to guide their control implementation. Which standard is most appropriate to satisfy both regulatory and contractual requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.