Asset Security
CISSP · 30 questions
- Building-permit PDFs, sealed adoption records, and public meeting agendas sit in the same file share without labels. What Domain 2 practice should drive their different handling?
- SCADA historian servers and lobby information kiosks are inventoried under one generic 'IT equipment' class with identical controls. What correction is needed?
- A city records clerk invents ad-hoc labels such as "super-secret-plus" that no other department recognizes. What should the information security program prefer for classification?
- Public works posts FOIA-ready monthly road reports, but a supervisor marks every file Confidential, blocking routine public release. What risk does this primarily illustrate?
- After water-quality lab results are labeled Sensitive, which next step best reflects how classification should drive asset security?
- Printed jury questionnaires marked Confidential sit unattended on a shared courthouse printer overnight. Which action best addresses the underlying asset-security gap?
- USB drives holding open case files circulate among court interns with no labels or checkout record. What should management require first?
- Child-welfare caseworkers discuss open cases, including names and addresses, at a crowded municipal cafeteria. Which control gap is most directly illustrated?
- An assessor emails a spreadsheet labeled Confidential—containing taxpayer identifiers—unencrypted to a personal Gmail account for weekend work. What does this primarily violate?
- Guided tour groups walk through operations areas where detailed classified facility maps remain posted on open walls. What should the security program tighten?
- Requests for access to the property-tax database stall because no official will approve them—ownership of the information asset was never assigned. What should the city establish?
- After a flood damages city hall, recovery stalls because the city cannot list which servers, badges, and workstations existed in the building. What capability was missing?
- Emergency management maintains custom routing algorithms and proprietary GIS layers that are critical to response, yet they appear nowhere in the asset register. What should the inventory include?
- New municipal laptops ship straight to end users with local administrator rights and no full-disk encryption. Which asset-security practice was skipped?
- Retired public-safety radios still appear as "active" in the configuration management database months after collection. What asset-management principle is most clearly broken?
- A contractor stores and processes photos submitted through the city's 311 app. Which mapping of data roles is most accurate?
- A summer festival wristband app demands each attendee's full Social Security number solely to pick up a colored band at the gate. What principle should the privacy and asset-security review apply?
- Chat logs from a temporary COVID information hotline are kept forever "just in case," long after the program ended and beyond any legal hold. What should govern these records?
- Surplus office PCs sold at the city auction still yield recoverable files with common freeware tools. Which issue must disposal procedures address before sale or reuse?
- The city shreds Confidential paper on schedule but has no approved destruction process for failed hard drives pulled from servers. What should asset security require?
- Badge-system software will reach vendor end-of-life next fiscal year, and no replacement budget line exists. How should the security program treat this situation?
- Perimeter firewall appliances are past vendor end-of-support and no longer receive security patches. What is the most accurate asset-security assessment?
- A litigation hold requires preserving certain email records even though the mail platform will be replaced next quarter. Which distinction should guide planning?
- A court e-filing module will lose vendor support in eighteen months. What timing best aligns with asset-security practice?
- Smart thermostats across city buildings are abandoned by the manufacturer with no further firmware updates. What should the asset-security response prioritize?
- File servers encrypt taxpayer data at rest, yet internal APIs send Social Security numbers in cleartext across the city WAN. Which data-protection gap is illustrated?
- A small public library cannot implement every control in a full federal baseline yet still handles patron privacy data. What approach best fits asset-security practice?
- A county assessor’s office needs encryption and logging baselines for resident tax files. Leadership wants something defensible at audit time, not tips pulled from random blogs. How should the security architect select those standards?
- Residents’ tax return PDFs keep leaving the city network through clerks’ personal webmail accounts. Which control class best detects and blocks that exfiltration while still allowing approved business email?
- Facilities staff store digital building plans in an unsanctioned consumer cloud drive that IT cannot see or govern. Which control approach best restores visibility and policy enforcement over that shadow SaaS use?