Browse all practice questions for the ISC² Post Assessment Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

ISC² Post Assessment Practice Test 2026 - Free ISC² Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is the role of a security management framework?
  • What outcome does a Denial of Service (DoS) attack aim to achieve?
  • What is phishing?
  • In what way does security architecture impact an organization?
  • What is the purpose of change management in IT security?
  • Define risk management in cybersecurity.
  • If Glen receives an email offering answers for an (ISC)² certification exam, what should he do?
  • What is the main purpose of incident response in cybersecurity?
  • Why is it important to conduct penetration testing?
  • What device is commonly useful to have on the perimeter between two networks?
  • What security measure is an example of technical control in a home network?
  • What role does a certificate authority (CA) play in a network?
  • To ensure availability for a data center, it is best to plan for both resilience and what aspect of the elements in the facility?
  • What is the role of security awareness training?
  • Why is Gary locked out of the production environment after three failed login attempts?
  • What is the purpose of business continuity planning (BCP)?
  • What is the primary purpose of cryptography?
  • What is a threat vector in cybersecurity?
  • What is the term for putting a bet on a roulette wheel?
  • What does a system that tracks user actions to provide accountability exemplify?
  • What is the definition of social engineering in cybersecurity?
  • What is a critical component of conducting a business impact analysis?
  • What is the main goal of an incident response effort?
  • What is the function of a digital signature?
  • Which control type is a policy preventing access to certain areas of a facility?
  • What is the most fundamental goal of data loss prevention?
  • What is a risk associated with resuming normal operations too soon after a disaster recovery effort?
  • Which of the following is an example of a biometric access control mechanism?
  • The Payment Card Industry (PCI) Council issues rules for merchants to follow when accepting credit cards; what type of document are these rules considered?
  • Security needs to be provided to which category of data?
  • Who typically dictates policy within an organization?
  • Which type of drill assesses evacuation procedures during a disaster recovery effort?
  • For which asset is integrity considered the most important security aspect?
  • Why is proper alignment of security policy with business goals important?
  • When Gary gets locked out after multiple login failures, what principle of security is being enforced?
  • What is network segmentation?
  • What is the difference between vulnerability and threat?
  • In cybersecurity, what is a honeypot?
  • What are some common consequences of a data breach?
  • What does remediation in cybersecurity refer to?
  • What does the term "security posture" refer to?
  • What allows remote users to have secure access to the internal IT environment?
  • Which of the following is probably most useful at the perimeter of a property?
  • Which communication protocol should Barry use for secure and efficient file uploads to a web-based storage service?
  • What kind of control is the instruction that requires employees to receive security awareness training before using email?
  • What should organizations do when a user leaves the company to maintain security?
  • What device filters network traffic to enhance overall security and performance?
  • What type of control are the instructions requiring permission to cross red lines next to the runway?
  • What principle does the security at Parvi's workplace illustrate with controlled access and monitoring?
  • Which of the following is a common challenge when implementing a disaster recovery plan?
  • What factor will most significantly influence the duration of log retention?
  • Which of the following is the most critical aspect of an organization's disaster recovery efforts?
  • Phrenal's anticipated sale of the laptop for $100 or more, while being prepared to accept less, is an example of what concept?
  • What is the main purpose of conducting a vulnerability assessment?
  • What is the primary role of a chief information security officer (CISO)?
  • How can financial loss occur as a result of a data breach?
  • What is a cross-site scripting (XSS) attack?
  • What are the three main types of security controls?
  • When implementing logging mechanisms, which factor should organizations prioritize?
  • How is a "white hat hacker" defined?
  • In risk management, a risk that is accepted and acknowledged by an organization is known as what?
  • What does CIA stand for in information security?
  • Which type of cybersecurity threat does a honeypot aim to mitigate?
  • What is the primary purpose of a security policy in an organization?
  • Which of the following is an example of a "something you are" authentication factor?
  • What is the goal of data loss prevention (DLP)?
  • If a database manager can add or remove users but cannot read the data, this illustrates what type of access control?
  • The practice of ensuring data is only accessible to those authorized is known as what?
  • Which tool monitors local devices to reduce threats from hostile software?
  • What does "security architecture" refer to?
  • What is the purpose of a business impact analysis (BIA)?
  • What does endpoint security primarily focus on?
  • Which statement best describes the function of cryptography?
  • Which of the following is NOT typically a focus of log data security controls?
  • What aspect does the ‘eradication’ component of an incident response plan focus on?
  • If Tina discovers malware sharing in an online group, what is the recommended action?
  • If Suvid receives a message to reset the password when logging in, what is the most likely cause?
  • In business continuity terminology, what does 'critical functions' refer to?
  • What type of device is typically accessed by multiple users and is often used for specific purposes such as managing email or web pages?
  • What are the key components of an incident response plan?
  • How does qualitative risk assessment differ from quantitative risk assessment?
  • What type of encryption should a security analyst use to ensure message authenticity?
  • What aspect of information security does security architecture address?
  • How does a security information and event management (SIEM) system operate?
  • Which common cloud service model offers the customer the most control of the cloud environment?
  • What is a priority in the development of a business continuity plan?
  • Which control type includes the implementation of policies to enhance security awareness among employees?
  • Which type of cyber threat involves overwhelming a service to make it unavailable?
  • What is used to ensure that configuration management activities are effective?
  • What does the term "incident escalation" refer to?
  • Which outcome is not a likely consequence of a data breach?
  • Why is regulatory compliance significant in IT security?
  • In the context of cybersecurity, what does the abbreviation BCP stand for?
  • Which of the following is a fundamental component of perimeter security?
  • What does “containment” involve in the context of an incident response plan?
  • Which of the following best defines cryptography?
  • What is the most important reason to conduct security instruction for all employees?
  • In the situation where Prachi has permission checks, what does the access control list (ACL) represent?
  • What is one primary benefit of using two-step verification?
  • What constitutes a cyber threat actor?
  • How frequently should logs be reviewed for security purposes?
  • Which of the following is NOT a recognized data classification label?
  • Which type of fire-suppression system is typically considered the safest for humans?
  • What aspect of security can hinder productivity if not properly aligned with business needs?
  • What type of control do GPS transmitters installed in public vehicles represent?
  • In the context of encryption, what does the term "key" refer to?
  • In the context of risk management, what is defined as something or someone that poses a risk to an organization or asset?
  • Which term best describes Gelbi's account at Triffid, Inc. as he installs or removes software?
  • Which port is typically used for HTTP traffic when Carol is browsing the Web?
  • What is the primary purpose of a VPN in a network?
  • What is a possible long-term effect of a data breach on a company?
  • What does the principle of "defense in depth" entail?
  • What can be a consequence of failing to conduct proper security training for employees?
  • How does phishing typically deceive its targets?
  • What type of app allows users to perform certain functions but may also steal sensitive information?
  • How can a vulnerability assessment improve cybersecurity?
  • What type of attack involves intercepting and surveilling the communication traffic between two devices?
  • What is the main advantage of using hashing for message integrity?
  • What access control methodology would allow a manager to determine the conditions under which personnel can access systems?
  • What is a zero-day vulnerability?
  • What processes the labeling of documents to indicate their sensitivity?
  • Define a brute force attack in cybersecurity terms.
  • Which of the following terms describes the act of shifting the risk to another entity?
  • During an audit, what should Olaf, the security analyst, do when he knows Triffid is not adhering to security standards?
  • Who is responsible for approving an incident response policy?
  • What is the primary benefit of user behavior analytics?
  • What technique could be used to ensure a message has not been modified during transit?
  • What factor distinguishes a "something you have" authentication method?
  • What type of control would be most effective in ensuring cars do not collide with pedestrians?
  • What is a security incident?
  • Which is a fundamental aspect of a successful security training program?
  • What type of control is a software firewall that prevents certain traffic from entering a device?
  • Why is data classification important in IT security?
  • What is the primary goal of business continuity efforts?
  • What is the primary goal of implementing security awareness training in an organization?
  • To minimize risks, which approach would be a strategic choice for gamification in business decisions?
  • What is defined as a record of something that has occurred?
  • What is the key focus of a business impact analysis?
  • What type of attack might Ludwig notice that affects the availability of the environment?
  • What does the term "vulnerability" refer to in a security context?
  • Which control is NOT useful for managing visitors to a secure facility?
  • All visitors to a secure facility should be ______.
  • What does penetration testing involve?
  • Which access control method allows employees to access the necessary assets when transferring departments?
  • What is the primary purpose of security training for employees?
  • What is multi-factor authentication (MFA)?
  • What is the logical address assigned to a device connected to a network or the Internet?
  • What kind of control is MAC address filtering on a router?
  • What is the primary purpose of data loss prevention (DLP) systems?
  • What security concept is being applied when Larry and Fern must both present their own keys to enter the data center?
  • Which of the following incidents would fall under the responsibility of incident response teams?
  • What does a security audit evaluate?
  • What function does a rootkit serve?
  • When data has reached the end of the retention period, it should be:
  • What is a tool that inspects outbound traffic to reduce potential threats?
  • Security controls on log data should reflect what key factor?
  • Which protocol is most appropriate for securely transferring files over the internet?
  • If two people want to use symmetric encryption to conduct a confidential conversation, how many keys do they need?
  • What is a security breach notification?
  • What is the principle of least privilege?
  • Which of the following statements is true regarding access controls in an IT environment?
  • If Aphrodite discovers a coworker violating the acceptable use policy, what should she do?
  • What is the purpose of non-repudiation in security?
  • What does an intrusion detection system (IDS) do?
  • What is user behavior analytics (UBA)?
  • The Common Body of Knowledge (CBK) published by (ISC)² is recognized as what type of document in the industry?
  • Which type of encryption allows public and private keys for secure communication?
  • What does two-step verification add to the security process?
  • What does malware refer to?
  • What term describes data left behind on systems/media after deletion procedures?
  • What is the common term for a place where wires and conduits are run and equipment is placed to facilitate local networks?
  • What is likely to be included in a business continuity plan?
  • Which type of event poses the most risk?
  • Describe the function of a firewall.
  • An external attacker trying to access internal files is an example of what?
  • What does a comprehensive security architecture ensure?
  • What is an encryption algorithm used for?
  • Which measure is essential for ensuring data is securely disposed of after its retention period?
  • A human guard monitoring a hidden camera is an example of which type of control?
  • When Cheryl is browsing the Web, which protocol is she likely using?
  • Which cloud deployment model typically stores a single customer's data and functionality on specific systems or hardware?
  • What is a data breach?
  • If Zarma is asked about the types of questions in the (ISC)² certification exam, what should he do?
  • What is a common function of Anti-malware software?
  • What is an access control list (ACL)?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy