CISSP DOMAIN 2: REVIEW QUESTIONS
AND ANSWERS WITH COMPLETE
SOLUTIONS
Question 1 How can an asset classification program improve the organization's
ability to achieve its goals and objectives?
A. By meeting the requirements imposed by the audit function B. By
controlling changes to production environments C. By enhancing ownership
principles D. By specifying controls to protect valuable assets
ANSWER: D. By specifying controls to protect valuable assets ✔✔
Explanation: Asset classification categorizes data and systems based on value,
sensitivity, and risk. This allows the organization to precisely assign and implement
the necessary security controls to protect its most critical assets, optimizing
resource allocation to achieve business objectives safely.
Question 2 What is the correct order of the asset lifecycle phases?
A. Create, use, share, store, archive, and destroy B. Create, share, use, archive,
store, and destroy C. Create, store, use, share, archive, and destroy D. Create,
share, archive, use, store, and destroy
ANSWER: C. Create, store, use, share, archive, and destroy ✔✔
Explanation: The standard data/asset lifecycle begins with creation (Create). Data
must then be immediately saved securely (Store) before it can be processed or
managed (Use), distributed to authorized parties (Share), put into long-term
retention for legal compliance (Archive), and finally, permanently removed
(Destroy).
Question 3 Which of the following is the BEST definition of defensible
destruction?
AND ANSWERS WITH COMPLETE
SOLUTIONS
Question 1 How can an asset classification program improve the organization's
ability to achieve its goals and objectives?
A. By meeting the requirements imposed by the audit function B. By
controlling changes to production environments C. By enhancing ownership
principles D. By specifying controls to protect valuable assets
ANSWER: D. By specifying controls to protect valuable assets ✔✔
Explanation: Asset classification categorizes data and systems based on value,
sensitivity, and risk. This allows the organization to precisely assign and implement
the necessary security controls to protect its most critical assets, optimizing
resource allocation to achieve business objectives safely.
Question 2 What is the correct order of the asset lifecycle phases?
A. Create, use, share, store, archive, and destroy B. Create, share, use, archive,
store, and destroy C. Create, store, use, share, archive, and destroy D. Create,
share, archive, use, store, and destroy
ANSWER: C. Create, store, use, share, archive, and destroy ✔✔
Explanation: The standard data/asset lifecycle begins with creation (Create). Data
must then be immediately saved securely (Store) before it can be processed or
managed (Use), distributed to authorized parties (Share), put into long-term
retention for legal compliance (Archive), and finally, permanently removed
(Destroy).
Question 3 Which of the following is the BEST definition of defensible
destruction?