
Certified Information Systems Security Professional
Domain 1Objective 4
1.4 - Understand Legal, Regulatory, and Compliance Issues That Pertain to Information Security in a Holistic Context CISSP Practice Questions (Page 1)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
11concepts
16%of the exam
Questions 1–5
- 1
What is the primary purpose of import/export control regulations in the context of information security?
Select an answer first - 2
A company operating in multiple US states discovers a breach affecting customers in 40 states. The company's legal team is determining notification obligations. Which factor is most critical in determining which state laws apply?
Select an answer first - 3
An employee at a manufacturing company uses their corporate credentials to access the HR database and exfiltrates salary data, which they sell to a competitor. Which type of cybercrime best describes this activity?
Select an answer first - 4
A graphic design agency uses a commercial stock photo library. A designer downloads an image and uses it in a client's marketing campaign without checking the license. The license is for 'editorial use only.' What is the most significant legal risk for the agency?
Select an answer first - 5
Which of the following is a key characteristic of the NIST Cybersecurity Framework (CSF)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.