Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 2Objective 1

2.1 - Identify and Classify Information and Assets CISSP Practice Questions (Page 5)

Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts
10%of the exam

Questions 21–25

  1. 21foundation · easy

    A document is classified as 'Confidential'. Which of the following handling procedures is MOST appropriate based on this classification?

    Select an answer first
  2. 22application · medium

    A security analyst is tasked with classifying the organization's assets. The analyst has already identified all assets and created an inventory. According to the asset classification process, what should the analyst do next?

    Select an answer first
  3. 23application · medium

    A multinational corporation is developing a data classification policy. The legal team notes that personal data of EU residents is subject to GDPR, while the marketing team wants to classify a product launch video as public. The CISO needs to ensure that classification criteria are consistent and defensible. Which set of criteria should the policy use to assign classifications?

    Select an answer first
  4. 24application · medium

    A financial services firm is implementing a data classification program. The compliance team has identified that customer financial records are subject to strict regulatory requirements, while marketing brochures have no regulatory impact. The CISO wants to ensure that classification labels directly influence the security controls applied. Which approach best aligns classification with control selection?

    Select an answer first
  5. 25application · medium

    A manufacturing company wants to improve its security posture by categorizing all physical and logical assets, including servers, network devices, software licenses, and intellectual property. The security manager needs to distinguish this effort from data classification. What is the primary purpose of asset classification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.