Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

ISC2 CISSP Newest Exam with accurate detailed answers

Rating
-
Sold
-
Pages
33
Grade
A+
Uploaded on
09-01-2026
Written in
2025/2026

ISC2 CISSP Newest Exam with accurate detailed answers

Institution
ISC2 CISSP
Course
ISC2 CISSP

Content preview

2



ISC2 CISSP Newest Exam with accurate detailed answers
|| || || || || || ||




CIA Triangle - ✔✔Cornerstone of infosec. Confidentiality, Integrity, Availability
|| || || || || || || ||




Confidentiality (CIA Triangle) - ✔✔prevention of unauthorized disclosure of information; || || || || || || || || || ||




prevention of unauthorized read access to data
|| || || || || ||




Integrity (CIA Triangle) - ✔✔prevention of unauthorized modification of data; prevention of
|| || || || || || || || || || || ||




unauthorized write access to data || || || ||




Availability (CIA Triangle) - ✔✔ensures data is available when needed to authorized users
|| || || || || || || || || || || ||




Opposing forces to CIA - ✔✔DAD: disclosure, alteration, destruction
|| || || || || || || ||




identification - ✔✔the process by which a subject professes an identity and accountability is
|| || || || || || || || || || || || || ||




initiated; ex: typing a username, swiping a smart card, waving a proximity device (badging in),
|| || || || || || || || || || || || || || ||




speaking a phrase, etc - always a two step process with authenticating
|| || || || || || || || || || ||




authentication - ✔✔verification that a person is who they say they are; ex: entering a password or
|| || || || || || || || || || || || || || || || ||




PIN, biometrics, etc - always a two step process with identifying
|| || || || || || || || || ||




authorization - ✔✔verification of a person's access or privileges to applicable data
|| || || || || || || || || || ||




auditing (monitoring) - ✔✔recording a log of the events and activities related to the system and
|| || || || || || || || || || || || || || || ||




subjects


accounting (accountability) - ✔✔reviewing log files to check for compliance and violations in
|| || || || || || || || || || || || ||




order to hold subjects accountable for their actions
|| || || || || || ||

,2


non-repudiation - ✔✔a user cannot deny having performed a specific action || || || || || || || || || ||




subject - ✔✔an entity that performs active functions to a system; usually a person, but can also be
|| || || || || || || || || || || || || || || || ||




script or program designed to perform actions on data
|| || || || || || || || ||




object - ✔✔any passive data within the system
|| || || || || || ||




ISC2 Code of Ethics Canons (4) - ✔✔1. protect society, commonwealth, infrastructure
|| || || || || || || || || || ||




2. act honorably, justly, responsibly, legally
|| || || || ||




3. provide diligent and competent service
|| || || || ||




4. advance and protect the profession
|| || || || ||




strictly applied in order; exam questions in which multiple canons could be the answer, choose the
|| || || || || || || || || || || || || || ||




highest priority per this order
|| || || || ||




policy - ✔✔mandatory high level management directives; components of policy
|| || || || || || || || ||




1. purpose: describes the need for policy
|| || || || || ||




2. scope: what systems, people, facilities, organizations are covered
|| || || || || || || ||




3. responsibilities: specific duties of involved parties
|| || || || || ||




4. compliance: effectiveness of policy, violations of policy
|| || || || || || ||




procedure - ✔✔low level step by step guide for accomplishing a task
|| || || || || || || || || || ||




standard - ✔✔describes the specific use of technology applied to hardware or software;
|| || || || || || || || || || || || ||




mandatory


guideline - ✔✔discretionary recommendations (e.g. not mandatory)
|| || || || || ||

,2




baseline - ✔✔a uniform way of implementing a standard
|| || || || || || || ||




3 access/security control categories - ✔✔1. administrative: implemented by creating org policy,
|| || || || || || || || || || || ||




procedure, regulation. user awareness/training also fall here
|| || || || || ||




2. technical: implemented using hardware, software, firmware that restricts logical access to a
|| || || || || || || || || || || || ||




system
3. physical: locks, fences, walls, etc
|| || || || ||




preventive access control || ||




(can be administrative, technical, physical) - ✔✔prevents actions from occurring by applying
|| || || || || || || || || || || ||




restrictions on what a user can do. example: privilege level
|| || || || || || || || ||




detective access control || ||




(can be administrative, technical, physical) - ✔✔controls that alert during or after a successful
|| || || || || || || || || || || || || ||




attack; alarm systems, or closed circuit tv
|| || || || || ||




corrective access control || ||




(can be administrative, technical, physical) - ✔✔repairing a damaged system; often works hand
|| || || || || || || || || || || || ||




in hand with detective controls (e.g. antivirus software)
|| || || || || || ||




recovery access control || ||




(can be administrative, technical, physical) - ✔✔controls to restore a system after an incident has
|| || || || || || || || || || || || || || ||




occurred;


deterrent access control || ||




(can be administrative, technical, physical) - ✔✔deters users from performing actions on a
|| || || || || || || || || || || || ||




system

, 2


compensating access control || ||




(can be administrative, technical, physical) - ✔✔additional control used to compensate for
|| || || || || || || || || || || ||




weaknesses in other controls as needed || || || || ||




risk formula - ✔✔risk = threat x vulnerability x impact
|| || || || || || || || ||




market approach (for calculating intangible assets) - ✔✔assumes the fair value of an asset reflects
|| || || || || || || || || || || || || ||




the price which comparable assets have been purchased in transactions under similar
|| || || || || || || || || || || || ||




circumstances


income approach (for calculating intangible assets) - ✔✔the value of an asset is the present value
|| || || || || || || || || || || || || || || ||




of the future earning capacity that an asset will generate over the rest of its lifecycle
|| || || || || || || || || || || || || || ||




cost approach (for calculating intangible assets) - ✔✔estimates the fair value based on cost of
|| || || || || || || || || || || || || || ||




replacement


exposure factor (EF) - ✔✔percentage of value the asset lost due to incident
|| || || || || || || || || || || ||




single loss expectancy (SLE) - ✔✔asset value (AV) times exposure factor
|| || || || || || || || || ||




AV x EF = SLE
|| || || ||




expressed in a dollar value || || || ||




annual rate of occurrence (ARO) - ✔✔number of losses suffered per year
|| || || || || || || || || || ||




annualized loss expectancy (ALE) - ✔✔yearly cost due to risk || || || || || || || || ||




SLE x ARO = ALE || || || ||




legally defensible security - ✔✔to obtain legal restitution a company must demonstrate a crime
|| || || || || || || || || || || || || ||




was committed, suspect committed that crime, and took reasonable efforts to prevent the crime
|| || || || || || || || || || || || ||

Written for

Institution
ISC2 CISSP
Course
ISC2 CISSP

Document information

Uploaded on
January 9, 2026
Number of pages
33
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$22.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Ruiz Liberty University
Follow You need to be logged in order to follow users or courses
Sold
102
Member since
1 year
Number of followers
1
Documents
14010
Last sold
1 week ago
Top-Quality Study Materials for Success – Ace Your Exams with Expert Resources!

Access high-quality study materials to help you excel in your exams. Get notes, summaries, and guides tailored to your courses!

3.2

15 reviews

5
4
4
4
3
2
2
1
1
4

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions