
Certified Information Systems Security Professional
Domain 7Objective 1
7.1 - Understand and Comply with Investigations CISSP Practice Questions (Page 4)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
13%of the exam
Questions 16–20
- 16
A security analyst discovers an employee's workstation has been used to access unauthorized data. The analyst needs to preserve evidence for a potential legal proceeding. Which action is most appropriate to maintain the integrity of the evidence?
Select an answer first - 17
An investigator needs to recover deleted files from a suspect's computer. Which type of digital artifact is most likely to contain remnants of the deleted files?
Select an answer first - 18
During an incident investigation, a security analyst seizes a suspect's laptop. What is the primary purpose of maintaining a chain of custody document for this evidence?
Select an answer first - 19
Which investigative technique involves questioning individuals to gather information about an incident?
Select an answer first - 20
A forensic analyst is investigating a malware infection on a Windows workstation. The analyst needs to determine the malware's persistence mechanism. Which artifact is most likely to reveal how the malware maintains persistence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.