
Certified Information Systems Security Professional
Domain 3Objective 4
3.4 - Understand Security Capabilities of Information Systems (IS) (e.g., Memory Protection, Trusted Platform Module (TPM), Encryption/decryption) CISSP Practice Questions (Page 8)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
15concepts
13%of the exam
Questions 36–40
- 36
A company's web application sends sensitive customer data from a load balancer to a backend application server over an internal network. The network team has confirmed that the internal network is already isolated from the internet. The security team wants to protect the data from potential eavesdropping by other internal systems. What is the MOST appropriate control to protect this data?
Select an answer first - 37
A cloud provider offers Infrastructure-as-a-Service (IaaS) with a shared hypervisor. A customer is concerned about a malicious co-tenant VM using a hypervisor escape vulnerability to read the memory of the customer's VM. The customer also needs to protect the confidentiality of the VM's disk data from the cloud provider's administrators. Which combination of controls BEST addresses both concerns?
Select an answer first - 38
What is the purpose of key escrow?
Select an answer first - 39
Which statement correctly differentiates symmetric and asymmetric encryption?
Select an answer first - 40
What is a key characteristic of a Hardware Security Module (HSM) that distinguishes it from software-based key storage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.