
Certified Information Systems Security Professional
Domain 1Objective 4
1.4 - Understand Legal, Regulatory, and Compliance Issues That Pertain to Information Security in a Holistic Context CISSP Practice Questions (Page 3)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
11concepts
16%of the exam
Questions 11–15
- 11
An organization wants to align its information security management practices with an internationally recognized standard that provides a framework for establishing, implementing, and improving an information security management system (ISMS). Which standard should the organization use?
Select an answer first - 12
Which of the following is the best example of a cybercrime that primarily targets the availability of systems or data?
Select an answer first - 13
Which of the following is an example of an industry standard that mandates security controls for organizations that handle payment card data?
Select an answer first - 14
An organization is using a commercial software product. A security audit reveals that the organization has installed the software on more devices than the license permits. What is the most direct security and compliance risk associated with this situation?
Select an answer first - 15
A security analyst is categorizing a recent incident where an attacker used a phishing email to trick an employee into revealing their credentials. Which type of cybercrime does this incident best represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.