CISSP DOMAIN 1: REVIEW QUESTIONS
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
||UPDATED 2026
Question 1: Alice needs to secure highly valuable data. To protect it, she creates a
backup on a USB flash drive and stores that drive inside a secure safe deposit box.
Which two core pillars of the CIA triad is she addressing with these actions?
A. Confidentiality and Integrity
B. Confidentiality and Availability
C. Integrity and Availability
D. Availability and Non-repudiation
Answer: ✔✔ B. Confidentiality and Availability
Question 2: When developing a business continuity and disaster recovery plan, an
organization's Recovery Time Objective (RTO) must never exceed which of the
following metrics?
A. A strict 12-hour window
B. The timeframe required to notify the public
C. The Maximum Allowable Downtime (MAD)
D. The maximum timeline mandated by industry regulators
Answer: ✔✔ C. The Maximum Allowable Downtime (MAD)
Question 3: According to the professional code of ethics, an ISC² certified security
professional is required to prioritize service to which entity above all others?
A. The employing client or company
B. The cybersecurity industry
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
||UPDATED 2026
Question 1: Alice needs to secure highly valuable data. To protect it, she creates a
backup on a USB flash drive and stores that drive inside a secure safe deposit box.
Which two core pillars of the CIA triad is she addressing with these actions?
A. Confidentiality and Integrity
B. Confidentiality and Availability
C. Integrity and Availability
D. Availability and Non-repudiation
Answer: ✔✔ B. Confidentiality and Availability
Question 2: When developing a business continuity and disaster recovery plan, an
organization's Recovery Time Objective (RTO) must never exceed which of the
following metrics?
A. A strict 12-hour window
B. The timeframe required to notify the public
C. The Maximum Allowable Downtime (MAD)
D. The maximum timeline mandated by industry regulators
Answer: ✔✔ C. The Maximum Allowable Downtime (MAD)
Question 3: According to the professional code of ethics, an ISC² certified security
professional is required to prioritize service to which entity above all others?
A. The employing client or company
B. The cybersecurity industry