Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 3Objective 4

3.4 - Understand Security Capabilities of Information Systems (IS) (e.g., Memory Protection, Trusted Platform Module (TPM), Encryption/decryption) CISSP Practice Questions (Page 7)

Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
15concepts
13%of the exam

Questions 31–35

  1. 31application · medium

    A financial services firm runs a high-frequency trading application on a shared cloud host. The application processes sensitive order data in memory, and the security team is concerned about a malicious co-tenant process using speculative execution or memory-scraping attacks to read that data. The application cannot be re-architected to use a separate physical host. Which control would BEST protect the confidentiality of the in-memory data while the application is executing?

    Select an answer first
  2. 32foundation · easy

    What is the primary purpose of a cryptographic hash function?

    Select an answer first
  3. 33foundation · easy

    Which memory protection mechanism is specifically designed to prevent the exploitation of buffer overflow vulnerabilities by making the memory addresses of code and data unpredictable?

    Select an answer first
  4. 34foundation · easy

    What is a key advantage of application-level encryption over storage-level encryption?

    Select an answer first
  5. 35application · medium

    A healthcare organization is deploying new laptops to remote clinicians. The security policy requires that the devices be verified as booting only trusted, unmodified operating system components before they are allowed to connect to the corporate VPN. The organization uses a centralized management console to enforce this policy. Which combination of technologies should the security architect specify?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.