✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Security Concepts and Practices
A hospital's patient vital-signs monitoring system must remain accessible to clinicians at all times, even during a power outage or network disruption. The design team accepts a small residual risk of unauthorized viewing because the ward already has controlled physical access. Which principle of the CIA triad is being prioritized in this design decision?
The scenario explicitly prioritizes continuous access to data (uptime, resilience to outages) over restricting who can view it, which is the definition of availability.
Question 2 of 12 · Domain 2: Access Controls
A defense contractor must implement an access control model where every object carries a classification label and every subject has a clearance level, and only a designated security administrator—not individual data owners—can change those labels. Which access control model BEST meets this requirement?
MAC uses system-enforced labels (classification/clearance) that only a central authority (security administrator) can assign or modify, matching classic multi-level security environments like military and defense systems.
Question 3 of 12 · Domain 3: Risk Identification, Monitoring, and Analysis
A mid-sized company identifies a risk of data loss from a rare but catastrophic natural disaster affecting its primary data center. Rather than building a costly redundant site, the company purchases a comprehensive business interruption and data recovery insurance policy to cover potential losses. Which risk treatment strategy does this BEST represent?
Risk transfer shifts the financial impact of a risk to a third party, such as an insurance company, without reducing the likelihood or eliminating the risk itself.
Question 4 of 12 · Domain 4: Incident Response and Recovery
A company detects ransomware rapidly spreading across its internal network. The incident response team immediately disconnects the infected endpoints from the network switch and disables their network interfaces to stop the spread while analysis continues. Which phase of the incident response lifecycle does this action represent?
Containment focuses on limiting the scope and impact of an incident, such as isolating infected hosts from the network, before removing the threat or restoring systems.
Question 5 of 12 · Domain 5: Cryptography
A company needs to encrypt large volumes of data at rest with the fastest possible performance while using a single shared secret between the application and the storage service. Which algorithm BEST meets this requirement?
AES-256 is a symmetric block cipher, making it fast for bulk data encryption at rest and using a single shared key between parties.
Question 6 of 12 · Domain 6: Network and Communications Security
A network administrator discovers that an attacker successfully accessed traffic on a VLAN other than the one to which their switch port was assigned, by sending frames with two stacked 802.1Q tags. Investigation shows all trunk ports are still using VLAN 1 as the native VLAN and Dynamic Trunking Protocol (DTP) is enabled by default. Which action BEST prevents this double-tagging VLAN hopping attack going forward?
Double-tagging attacks rely on the outer tag being stripped by the switch handling the untagged native VLAN, exposing the inner tag to the target VLAN. Moving the native VLAN to an unused, explicitly tagged VLAN ID and disabling DTP (so trunks can't be auto-negotiated by rogue devices) removes the mechanism the attack depends on.
Question 7 of 12 · Domain 7: Systems and Application Security
A security analyst notices that a critical business server is exhibiting unusually high outbound network traffic to an unfamiliar external IP address. No new files have been written to disk, and antivirus signature scans return clean results. Memory analysis reveals a malicious script running entirely in RAM, injected into a legitimate process. Which type of malware is MOST likely responsible for this activity?
Fileless malware operates in memory, injects into legitimate running processes, and leaves no file artifacts on disk, which is why signature-based antivirus fails to detect it. This matches the described behavior exactly.
Question 8 of 12 · Domain 1: Security Concepts and Practices
According to the (ISC2) Code of Ethics, when the four canons conflict, which is the correct priority order from highest to lowest?
The official (ISC2) Code of Ethics canon order is: protect society, act honorably, provide diligent service, and advance the profession — in that exact priority when canons conflict.
Question 9 of 12 · Domain 2: Access Controls
A university wants students to access resources hosted at partner universities using only their home institution's credentials, without creating separate accounts at each partner site. Which technology BEST supports this requirement?
SAML-based federation allows a trusted identity provider (the home institution) to assert a user's identity to relying parties (partner universities), enabling cross-organizational single sign-on without duplicate accounts.
Question 10 of 12 · Domain 3: Risk Identification, Monitoring, and Analysis
A security team needs to identify unpatched operating systems, missing security patches, and default configurations across 500 servers without attempting to exploit any weaknesses found. Which activity BEST meets this requirement?
A vulnerability scan is an automated process that identifies known weaknesses, missing patches, and misconfigurations by comparing system states against a vulnerability database, without actively exploiting them.
Question 11 of 12 · Domain 4: Incident Response and Recovery
A forensic investigator is called to seize a laptop suspected of being used in a data exfiltration incident. Which action BEST preserves the integrity of the evidence and maintains proper chain of custody?
A write-blocker prevents any modification to the original media during imaging, and documenting every transfer of custody (who, what, when, why) with timestamps is the core requirement of chain of custody, ensuring the evidence remains admissible.
Question 12 of 12 · Domain 5: Cryptography
An organization wants to verify that a downloaded software update has not been altered in transit and also confirm which vendor released it. Which cryptographic mechanism BEST provides both integrity and authenticity?
A digital signature uses the vendor's private key to sign a hash of the file; verifying it with the vendor's public key confirms both that the file wasn't altered (integrity) and that it came from the vendor (authenticity/non-repudiation).
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $249 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 7 domains: Security Concepts and Practices (16%), Access Controls (15%), Risk Identification, Monitoring, and Analysis (15%), Incident Response and Recovery (14%), Cryptography (9%), Network and Communications Security (16%), Systems and Application Security (15%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.