
Certified Information Systems Security Professional
Domain 2Objective 3
2.3 - Provision Information and Assets Securely CISSP Practice Questions (Page 2)
Part of the Asset Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
3concepts
10%of the exam
Questions 6–10
- 6
A financial services firm is implementing a new data governance program. The Chief Information Officer (CIO) has designated the head of each business unit as the individual responsible for the data their unit creates, including determining its classification and approving access requests. The IT department is tasked with implementing the technical controls and maintaining the systems that store the data. Which of the following best describes the role of the head of each business unit in this arrangement?
Select an answer first - 7
A company is implementing a data loss prevention (DLP) solution. The DLP solution will monitor data in use, in motion, and at rest. The security team needs to define rules for what constitutes sensitive data. Which of the following is the most important input for defining these rules?
Select an answer first - 8
A university's research department stores sensitive research data on a network file share. The data is owned by the principal investigator (PI) of each research project. The IT department manages the file server and performs backups. A graduate student who is a member of a research project needs access to the data for analysis. Who is responsible for granting the student access to the data?
Select an answer first - 9
A company has a policy that all data must be classified at the time of creation. However, employees often forget to classify new documents, and the documents are stored with a default classification of 'Internal'. This has led to some sensitive documents being under-classified. Which of the following is the most effective way to address this issue?
Select an answer first - 10
A large enterprise has an asset inventory that is maintained in a spreadsheet by a single administrator. The administrator is leaving the company, and the new security manager discovers that the inventory is incomplete and outdated. The company is required to report to regulators on the location and classification of all data assets. Which of the following is the most effective way to improve the accuracy and completeness of the inventory?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.