Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 2Objective 6

2.6 - Determine Data Security Controls and Compliance Requirements CISSP Practice Questions (Page 3)

Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
10%of the exam

Questions 11–15

  1. 11foundation · easy

    An organization is implementing a security control framework. They decide to include only the controls that are relevant to their systems and exclude controls that do not apply to their environment. Which process does this describe?

    Select an answer first
  2. 12application · medium

    A small law firm handles sensitive client data and must comply with the General Data Protection Regulation (GDPR) for its EU clients. The firm has limited IT staff and budget. They are implementing security controls and need to determine which controls are required. Which approach is most appropriate for scoping and tailoring controls?

    Select an answer first
  3. 13application · medium

    A company allows employees to use personal devices to access corporate email and documents. The security team is concerned about sensitive data being uploaded to personal cloud storage accounts. They need a solution that can monitor and control access to cloud applications, enforce data loss prevention policies, and provide visibility into shadow IT. Which solution best addresses these concerns?

    Select an answer first
  4. 14application · medium

    A government contractor must protect classified information and comply with federal regulations. The contractor also handles commercial data that is not classified. The security team is selecting a security standard to guide their control implementation. Which standard is most appropriate for the classified data?

    Select an answer first
  5. 15foundation · easy

    Which data state is most directly associated with the need for encryption protocols such as TLS or IPsec to protect confidentiality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.