Study. uk . com
  1. Home
  2. All questions
  3. Asset security

CISSP study material: Asset security

56 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 9. A defence supplier is building a cyber supply chain risk management (C-SCRM) programme guided by NIST SP 800-161 Rev. 1, which applies C-SCRM at several organisational levels. Which artefacts does that guidance expect the programme to produce? Choose three.
  2. 14. A hospital is retiring 400 laptop drives that held patient records. The security manager argues that only physical shredding can count as sanitisation and that a verified overwrite is worthless. The media sanitisation lead answers by citing the standard's own test for when media counts as sanitised. Which principle does the lead cite?
  3. 15. A cloud provider must decommission self-encrypting drives from a multi-tenant storage array inside a two-hour maintenance window far too short for a full-block overwrite of the array. Each drive holds ciphertext belonging to many tenants, and the drives are leased and must be returned to the lessor in working order. Which sanitisation method meets these constraints?
  4. 16. An agency system publishes public transit timetables. A falsified timetable would seriously mislead riders, an outage would merely inconvenience them, and the data is already public. The system owner wants one impact rating covering the whole system. How should the categorisation be performed?
  5. 17. A university drafts a single blanket handling rule covering every piece of personally identifiable information it holds, from published faculty office numbers to student health records. The privacy officer objects, citing the federal guidance on protecting such information. What does that guidance direct instead?
  6. 18. During an audit, a system owner claims the mapping of information types to impact categories binds the agency exactly as tightly as the requirement to categorise its systems. The auditor separates the two distinct assignments that legislation placed on the standards body. Which statement is accurate?
  7. 19. A logistics firm sends decommissioned equipment to a recycler. Some devices held only public route maps, while others held customer payment records, and the asset manager wants one defensible rule for choosing a disposal technique. Which rule matches the media sanitisation guidance?
  8. 20. A system owner is documenting, for each security objective, the kinds of compromise that could damage the mission. A colleague has written down only theft of data by an outsider. Which additional forms of compromise does the federal categorisation standard count? Choose three.
  9. 21. A privacy lead is scoping a programme against the federal guide to protecting personally identifiable information and must set the steering committee's expectations about the guide's actual reach. Which statements correctly describe its scope? Choose two.
  10. 26. A governance team wants one control catalogue to serve the whole organisation, so that a single register covers every obligation the board tracks. They ask which concerns beyond classic information security the twenty SP 800-53 Rev. 5 families already govern. Choose two.
  11. 67. An enterprise marks a patch as complete once its deployment console reports the package was pushed to the target group. An auditor later finds several of those servers still running the vulnerable version. Which activity closes the patch management cycle?
  12. 71. A skilled intruder held access to a domain member server for weeks, and the full set of techniques they used remains unknown. The team plans to rebuild the server from a backup taken before the earliest known activity. Which three actions should the recovery include? Choose three.
  13. 149. A media disposal policy lists overwriting, degaussing and shredding as its three sanitization methods. Under NIST SP 800-88 Rev. 2, why is that the wrong framing?
  14. 150. A laptop is being reissued to another employee inside the same office, and the data on it was categorised low. Which sanitization method does NIST SP 800-88 describe as sufficient here, and why?
  15. 151. An asset manager can apply either clear or purge to a batch of drives being redeployed, at similar cost. What does NIST SP 800-88 Rev. 2 advise?
  16. 152. A records team asks which sanitization method applies to a cloud storage bucket that is being decommissioned. Why is destroy not available to them?
  17. 153. A department proposes to sanitize printed patient records by running them through a bulk degausser, arguing this parallels how it handles tapes. What is wrong with the proposal?
  18. 154. A batch of drives has failed and no longer responds to the host interface. A technician proposes overwriting them before disposal. Which two objections does NIST SP 800-88 support? Choose two.
  19. 155. An administrator overwrites every user-addressable block of a solid-state drive and reports it sanitized. Why does NIST SP 800-88 treat this as unreliable?
  20. 156. A standard operating procedure still requires seven overwrite passes citing an old defence manual. Which two points does NIST SP 800-88 Rev. 2 make about this? Choose two.
  21. 157. A hosting provider must sanitize thousands of self-encrypting drives within a maintenance window that would not allow a full overwrite. Which technique does NIST SP 800-88 offer, and how does it work?
  22. 158. A tenant must purge data from a public cloud object store and cannot obtain physical access to the underlying hardware. Which technique does NIST SP 800-88 identify as often the only viable one?
  23. 159. A team plans to degauss a batch of modern high-coercivity hard drives with an older degausser and then resell them. Which two risks does NIST SP 800-88 identify? Choose two.
  24. 160. An operator degausses a batch of solid-state drives and records them as purged. Why is that record wrong?
  25. 161. A disposal record classifies degaussing as a destroy technique because the drive is unusable afterwards. How does NIST SP 800-88 Rev. 2 classify degaussing?
  26. 162. Which set of processes does NIST SP 800-88 Rev. 2 give as the physical techniques associated with the destroy method?
  27. 163. A field team drills a hole through each retired drive and records the media as destroyed. Why does NIST SP 800-88 reject this?
  28. 164. A vendor offers shredding as the disposal route for drives that held highly sensitive records. What limitation does NIST SP 800-88 Rev. 2 place on shredding and pulverising?
  29. 165. An architect is checking whether a storage product's cryptographic erase can be relied on. Which two conditions does NIST SP 800-88 Rev. 2 set? Choose two.
  30. 166. A product datasheet says its cryptographic erase destroys the wrapping key rather than the data encryption key. What follows from this, under NIST SP 800-88 Rev. 2?
  31. 167. A firm is deciding whether to sanitize retired media in house or ship it to a contractor. Which two considerations does NIST SP 800-88 Rev. 2 raise? Choose two.
  32. 168. A drive is labelled as 1 terabyte, but its controller performs internal compression and holds additional physical capacity. What does NIST SP 800-88 Rev. 2 conclude about sanitizing it?
  33. 169. A team can either overwrite through ordinary write commands or issue the drive's dedicated sanitize command. What trade-off does NIST SP 800-88 Rev. 2 describe?
  34. 170. An analyst records that confidentiality was lost when an attacker altered records in place without reading them. Under FIPS 199, how should this be classified?
  35. 171. An analyst must translate FIPS 199 impact levels into plain language for a business audience. Which mapping is correct?
  36. 172. A hospital categorises a system whose failure would stop emergency admissions entirely and could endanger patients' lives. Which two conditions in the FIPS 199 definition of high impact does this meet? Choose two.
  37. 173. A payroll system outage would leave the organisation able to keep paying staff but with markedly reduced effectiveness, and would cause significant but not life-threatening harm to individuals. Which FIPS 199 impact level fits?
  38. 174. An analyst categorises a published statistics dataset and wants to record that confidentiality is irrelevant to it. What does FIPS 199 permit for an information type?
  39. 175. A system holds two information types. One is moderate for confidentiality and low for integrity; the other is low for confidentiality and high for integrity. What is the system's FIPS 199 category?
  40. 176. An analyst wants to record a system's confidentiality objective as not applicable because the system holds only public data. Why does FIPS 199 forbid this at system level?
  41. 177. A system's routing tables, password file and key management data are being categorised. What does FIPS 199 require for such system information?
  42. 178. A programme presents its FIPS 199 categorisation as the completed risk assessment for a new system. Why is that claim wrong?
  43. 179. A data owner asks who decides what counts as an information type such as investigative or proprietary data. What does FIPS 199 say?
  44. 180. An agency asks whether FIPS 199 governs the categorisation of its classified holdings and its national security systems. What is the position?
  45. 181. A privacy officer is told the PII confidentiality impact level is simply the FIPS 199 confidentiality level under another name. What distinguishes the two, under NIST SP 800-122?
  46. 182. A team is setting the PII confidentiality impact level for a new dataset. Which three factors does NIST SP 800-122 offer for that decision? Choose three.
  47. 183. A dataset covers only twenty individuals, and an analyst proposes lowering its PII impact level on that basis. What does NIST SP 800-122 say about using quantity this way?
  48. 184. Two lists hold identical fields - name, address and telephone number. One is newsletter subscribers, the other is undercover officers. A reviewer says they must carry the same PII impact level. Why is that wrong?
  49. 185. A customer record system and a billing table sit on the same host with no effective separation between them, and together identify individuals. Under NIST SP 800-122, how is that data described?
  50. 186. A dataset could be joined with a public electoral register to identify individuals, though no such join has been made. Under NIST SP 800-122, what is the correct term?
  51. 187. A research team removes direct identifiers from a dataset but keeps a sealed key allowing subjects to be re-identified if a safety issue arises. Under NIST SP 800-122, may they call the result anonymised?
  52. 188. A marketing team wants to keep every field it has ever collected in case it proves useful later. Which two practices does NIST SP 800-122 recommend instead? Choose two.
  53. 189. A privacy programme starts by writing encryption standards for the personal data it knows about. What does NIST SP 800-122 make its first recommendation, and why?
  54. 190. An analyst determines that a dataset does not meet the definition of personally identifiable information, and proposes to remove it from the protection programme entirely. What does NIST SP 800-122 advise?
  55. 191. A study guide written in 2019 describes media sanitization using clear, purge and destroy and cites the 2014 edition of NIST SP 800-88. What has changed since?
  56. 192. A privacy team wants to know how the protection owed to a given piece of personal data is pegged to a wider federal scale. Which relationship does NIST SP 800-122 set out?