Security and Risk Management
CISSP · 48 questions
- A county CISO is pressured by a council member to hide a ransomware disclosure from the public dashboard while still telling staff that the office follows ISC2 ethics. Which action best aligns with the ISC2 Code of Professional Ethics?
- A city HR director wants security staff to sign only the municipal employee handbook and skip any security-specific ethics acknowledgment. Why should leadership still require an organizational security code of ethics?
- A utilities security manager sees junior analysts sharing cracked commercial scanners 'to save the ratepayers money.' What is the most appropriate ethical response?
- A township contractor asks a security architect to soft-pedal assessment findings so a favorite vendor keeps the renewal. What should the architect do?
- A public-health clinic laptop with resident vaccination records is left unlocked on a picnic table during an outreach event. Which security pillar is primarily violated?
- A county assessor database shows parcel valuations silently altered overnight with no authorized change ticket. Which security pillar was primarily broken?
- A city's online permit portal is taken offline by a volumetric attack the week tax payments are due. Which security pillar is primarily at risk for residents who cannot file?
- A mayor's office disputes whether an emailed contract approval actually came from the city attorney. Which pair of concepts best addresses proving genuine origin and preventing credible denial of the act?
- A library consortium security program only tracks firewall uptime while the board's goal is protecting patron privacy and equitable access. What governance move best realigns security to the mission?
- After a municipal merger, nobody owns security decisions across former city and county IT. What should leadership establish first to restore oversight?
- A school district chart lists 'everyone is responsible for security' with no RACI for data owners versus custodians. How should leadership clarify roles?
- A transit agency must map controls for both federal grant auditors and card-payment compliance. Which approach best structures governance?
- After a breach, residents claim the city never researched reasonable safeguards before outsourcing billing. Which distinction best frames that claim?
- A parks department discovers a contractor exfiltrated membership PII. Beyond internal policy, what must leadership recognize?
- A GIS team installs extra seats of mapping software by sharing one license key across field tablets. What compliance problem does this primarily create?
- A tourism board wants to host resident contestant photos on a foreign social platform's free tier. Which concern should security raise first?
- A city CRM for 311 tickets includes medical notes from homeless outreach. What privacy approach should the security leader emphasize?
- A vendor contract promises 'bank-grade encryption' but the city also has a state records law. How should the security manager treat these drivers?
- An employee allegedly emailed sensitive permit lists to a personal account. HR wants an internal review before any police call. Which investigation type and purpose does that describe?
- A ransomware crew encrypts court case files; prosecutors may pursue criminal charges while the city also sues a negligent MSP. How do these investigation paths differ at CISSP breadth?
- A payment processor used for recreation fees triggers an industry-standard forensic review after suspected card skimming. What should the city security lead understand?
- A mayor demands a one-page 'encryption policy' that also lists exact cipher suites. How should the security manager separate the document types?
- Field crews need step-by-step wipe-and-return steps for retired tablets. Which document type should security publish?
- A recommended phishing-report habit is useful but not mandatory for seasonal volunteers. How should this artifact be classified?
- A county has draft policies that never left SharePoint. What does effective implementation still require?
- After a regional power outage, a city must restore systems under limited generator capacity. Stakeholders argue for 911 CAD, payroll, and the social-media desk. How should the business impact analysis prioritize restoration?
- Sanitation routing depends on a single SaaS vendor with no contracted alternate. What should the business impact analysis explicitly surface for continuity planning?
- After completing a BIA, a county has budget to harden only a subset of processes before storm season. What is the most appropriate next step for continuity investment?
- City council demands 'full continuity' for a rarely used intranet wiki equal to water SCADA HMI remote access. What should the security leader do?
- HR plans to skip a background check for a temporary records clerk who will handle sealed juvenile case files. What personnel security issue does this create?
- Seasonal park hire packets omit security policy acknowledgments and NDA language even though workers will use shared city devices. What control gap should be flagged?
- A network administrator is terminated on Monday, yet VPN and badge access remain active through Thursday. What personnel security failure is demonstrated?
- An external consultant is granted standing domain admin 'for convenience' with no contract security clauses or time-bound access. What should the city require instead?
- A permit-system risk workshop lists 'hackers' as the only entry without linking specific weaknesses in the application or its environment. What is missing for sound risk identification?
- Leadership wants a single red/yellow/green score for every city system without defined likelihood or impact criteria. What should the risk practitioner insist on?
- For a low-impact municipal brochure website, leadership considers cyber insurance and formally accepting residual risk after basic hardening. Which statement best describes this approach?
- Facilities labels a new lobby camera system 'preventive' though it primarily records incidents after they occur for later review. How should the control type be classified?
- A city's risk register is refreshed only during the annual budget cycle even though systems and threats change monthly. What improvement best aligns with sound risk management?
- A municipality invents a unique risk-scoring scheme that external auditors familiar with NIST- and ISO-class approaches cannot map. What should the security program prefer?
- Before launching a resident chatbot that answers tax questions, what security activity should the team perform early in design?
- Architects debating a new permitting portal disagree: one wants STRIDE-style threat categories; another says abuse cases are unnecessary because 'users are mostly honest.' What should the program choose?
- A transit mobile app adds in-app payments, but the team never revisits the threat model created for the earlier schedule-only release. What is required?
- Bargain network gear from an unknown reseller arrives with broken tamper-evident seals. What supply-chain risk concern should procurement and security raise first?
- A city is selecting a court e-filing SaaS provider. Which SCRM mitigation set best fits the procurement security requirements?
- A critical public-alert vendor offers no security SLA and no contractual right to audit. What SCRM gap does this represent?
- Annual sixty-slide PDF security training for city staff shows about two percent completion. Which change best improves awareness effectiveness?
- City help desks now face deepfake voice calls and AI-assisted phishing, but security training content has not been updated in years. What should the awareness program do?
- Leadership asserts 'we have training' but never tracks phishing click rates or other behavior-change indicators. What does an effective awareness program require?