
Certified Information Systems Security Professional
Domain 2Objective 1
2.1 - Identify and Classify Information and Assets CISSP Practice Questions (Page 2)
Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
10%of the exam
Questions 6–10
- 6
A company has a data classification policy with four levels. The policy states that 'Restricted' data must be encrypted at rest and in transit, and access must be logged and monitored. A new system is being deployed that will process 'Restricted' data, but the system's design does not support encryption at rest. The project manager wants to proceed with the deployment. What should the security team do?
Select an answer first - 7
An organization is implementing a data classification program. What is the most direct benefit of this initiative?
Select an answer first - 8
A company uses three asset classification levels: Critical, Important, and Minor. A database server that supports the company's primary customer-facing application is considered Critical. Which protection measure is most appropriate for this asset?
Select an answer first - 9
In the asset classification process, what is the primary purpose of the 'labeling' step?
Select an answer first - 10
What is the primary purpose of data classification in an organization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.