CISSP practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q11In which of the following security models is the subject's clearance compared to the object's classification such that specific rules can be applied to control how the subject-to-object interactions take place?
✓ Correct answer: D. Bell-LaPadula model
A system that employs the Bell-LaPadula model is called a multilevel security system because users with different clearances use the system, and the system processes data at different classification levels. The level at which information is classified determines the handling procedures that should be used. The BellLaPadula model is a state machine model that enforces the confidentiality aspects of access control. A matrix and security levels are used to determine if subjects can access different objects. The subject’s clearance is compared to the object’s classification and then specific rules are applied to control how subjectto-object interactions can take place. This model uses subjects, objects, access operations (read, write, and read/write), and security levels. Subjects and objects can reside at different security levels and will have relationships and rules dictating the acceptable activities between them.
Q12Of the following choices, what is not a valid security practice related to special privileges?
✓ Correct answer: C. Grant access equally to administrators and operators
Special privileges should not be granted equally to administrators and operators. Instead, personnel should be granted only the privileges they need to perform their job. Special privileges are activities that require special access or elevated rights and permissions to perform administrative and sensitive job tasks. Assignment and usage of these privileges should be monitored, and access should be granted only to trusted employees.
Q13Which of the following identifies vendor responsibilities and can include monetary penalties if the vendor doesn’t meet the stated responsibilities?
✓ Correct answer: C. Service level agreement (SLA)
A service level agreement identifies responsibilities of a third party such as a vendor and can include monetary penalties if the vendor doesn’t meet the stated responsibilities. A MOU is in informal agreement and does not include monetary penalties. An ISA defines requirements for establishing, maintaining, and disconnecting a connection. SaaS is one of the cloud‐based service models and does not specify vendor responsibilities.
Q14The two main types of routing protocols are used to make routing decision based on either distance-vector routing protocols or link-state routing protocols. However, there are a handful of De facto and proprietary interior protocols in use. <br/><br/>Which De facto protocol uses link-state algorithms to send out routing table information?
✓ Correct answer: D. Open Shortest Path First
Open Shortest Path First (OSPF) is a De facto protocol using link-state algorithms to send out routing table information. The use of algorithms allow for smaller, more frequent routing table updates to take place. This provides a more stable network than Routing Information Protocol, but requires more memory and CPU resources to support the extra processing. OSPF allows for a hierarchical routing network that has a backbone link connecting all subnets together.
Q15What is needed to allow an external client to initiate a communication session with an internal system if the network uses a NAT proxy?
✓ Correct answer: D. Static mode NAT
Static mode NAT is needed to allow an outside entity to initiate communications with an internal system behind a NAT proxy.
Q16At which OSI model layer does the IPSec protocol function?
✓ Correct answer: D. Network
IPSec operates at the Network layer (layer 3).
Q17Which of the following is a Bluetooth-based attack that relates to gaining unauthorized access through a Bluetooth connection?
✓ Correct answer: B. Bluesnarfing
The attack that relates to gaining unauthorized access through a Bluetooth connection is a Bluesnarfing attack.<br/><br/>Bluesnarfing is the gaining of unauthorized access through a Bluetooth connection. This access can be gained through a phone, PDA, or any device using Bluetooth. Once access has been gained, the attacker can copy any data in the same way they would with any other unauthorized access. Blue jacking is the sending of unsolicited messages or spam over the Bluetooth connection.
Q18What block size is used by the Advanced Encryption Standard?
✓ Correct answer: C. 128 bits
The Advanced Encryption Standard uses a 128‐bit block size, despite the fact that the Rijndael algorithm it is based on allows a variable block size.
Q19What is an advantage of RSA over DSA?
✓ Correct answer: C. It can provide digital signature and encryption functionality.
RSA can be used for data encryption, key exchange, and digital signatures. DSA can only be used for digital signatures.
Q20What TCP/IP communications port is used by Transport Layer Security traffic?
✓ Correct answer: D. 443
Transport Layer Security uses TCP port 443 for encrypted client‐server communications.
Use the free CISSP Exam Prep 2026 Test sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.