Browse all practice questions for the ISC² Post Assessment Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the ISC² Post Assessment 2026 – Your Ultimate Cybersecurity Challenge! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Phrenal's anticipated sale of the laptop for $100 or more, while being prepared to accept less, is an example of what concept?
  • Describe the function of a firewall.
  • Why is Gary locked out of the production environment after three failed login attempts?
  • If two people want to use symmetric encryption to conduct a confidential conversation, how many keys do they need?
  • What is the difference between vulnerability and threat?
  • What does two-step verification add to the security process?
  • What is an access control list (ACL)?
  • What processes the labeling of documents to indicate their sensitivity?
  • Which common cloud service model offers the customer the most control of the cloud environment?
  • Which of the following is an example of a "something you are" authentication factor?
  • How can financial loss occur as a result of a data breach?
  • What is the primary benefit of user behavior analytics?
  • What does the term "incident escalation" refer to?
  • Who typically dictates policy within an organization?
  • What is the purpose of a business impact analysis (BIA)?
  • How does phishing typically deceive its targets?
  • What can be a consequence of failing to conduct proper security training for employees?
  • What is the goal of data loss prevention (DLP)?
  • What is a critical component of conducting a business impact analysis?
  • Why is data classification important in IT security?
  • What is the main purpose of conducting a vulnerability assessment?
  • What is the primary purpose of cryptography?
  • What are the key components of an incident response plan?
  • What is one primary benefit of using two-step verification?
  • What type of device is typically accessed by multiple users and is often used for specific purposes such as managing email or web pages?
  • What does the principle of "defense in depth" entail?
  • What is the primary purpose of security training for employees?
  • Which type of cybersecurity threat does a honeypot aim to mitigate?
  • Which of the following is probably most useful at the perimeter of a property?
  • If Suvid receives a message to reset the password when logging in, what is the most likely cause?
  • What is the role of security awareness training?
  • What is used to ensure that configuration management activities are effective?
  • What is the term for putting a bet on a roulette wheel?
  • What is the main advantage of using hashing for message integrity?
  • What factor will most significantly influence the duration of log retention?
  • What does a security audit evaluate?
  • What does malware refer to?
  • What should organizations do when a user leaves the company to maintain security?
  • What is the primary role of a chief information security officer (CISO)?
  • What is an encryption algorithm used for?
  • What is a risk associated with resuming normal operations too soon after a disaster recovery effort?
  • Define a brute force attack in cybersecurity terms.
  • What device is commonly useful to have on the perimeter between two networks?
  • What are the three main types of security controls?
  • What security measure is an example of technical control in a home network?
  • Which outcome is not a likely consequence of a data breach?
  • What is the most important reason to conduct security instruction for all employees?
  • Which tool monitors local devices to reduce threats from hostile software?
  • What is user behavior analytics (UBA)?
  • Which of the following is a common challenge when implementing a disaster recovery plan?
  • What does a comprehensive security architecture ensure?
  • What principle does the security at Parvi's workplace illustrate with controlled access and monitoring?
  • Why is proper alignment of security policy with business goals important?
  • How does a security information and event management (SIEM) system operate?
  • All visitors to a secure facility should be ______.
  • What is a possible long-term effect of a data breach on a company?
  • If Glen receives an email offering answers for an (ISC)² certification exam, what should he do?
  • When data has reached the end of the retention period, it should be:
  • When implementing logging mechanisms, which factor should organizations prioritize?
  • What type of control are the instructions requiring permission to cross red lines next to the runway?
  • In cybersecurity, what is a honeypot?
  • What is a security breach notification?
  • Which of the following is NOT typically a focus of log data security controls?
  • What is the main purpose of incident response in cybersecurity?
  • Why is regulatory compliance significant in IT security?
  • The Payment Card Industry (PCI) Council issues rules for merchants to follow when accepting credit cards; what type of document are these rules considered?
  • Which type of encryption allows public and private keys for secure communication?
  • What is the logical address assigned to a device connected to a network or the Internet?
  • What does an intrusion detection system (IDS) do?
  • What is the primary purpose of a security policy in an organization?
  • What is phishing?
  • What is multi-factor authentication (MFA)?
  • What is a cross-site scripting (XSS) attack?
  • What security concept is being applied when Larry and Fern must both present their own keys to enter the data center?
  • What is the primary goal of business continuity efforts?
  • What type of control do GPS transmitters installed in public vehicles represent?
  • What aspect does the ‘eradication’ component of an incident response plan focus on?
  • What constitutes a cyber threat actor?
  • Security needs to be provided to which category of data?
  • Which of the following statements is true regarding access controls in an IT environment?
  • To minimize risks, which approach would be a strategic choice for gamification in business decisions?
  • What is the purpose of non-repudiation in security?
  • Which is a fundamental aspect of a successful security training program?
  • Which control type is a policy preventing access to certain areas of a facility?
  • What is a zero-day vulnerability?
  • When Gary gets locked out after multiple login failures, what principle of security is being enforced?
  • Which protocol is most appropriate for securely transferring files over the internet?
  • What is the definition of social engineering in cybersecurity?
  • How can a vulnerability assessment improve cybersecurity?
  • Which control type includes the implementation of policies to enhance security awareness among employees?
  • What does the term "security posture" refer to?
  • What does a system that tracks user actions to provide accountability exemplify?
  • What is the function of a digital signature?
  • In risk management, a risk that is accepted and acknowledged by an organization is known as what?
  • What is network segmentation?
  • Which access control method allows employees to access the necessary assets when transferring departments?
  • What access control methodology would allow a manager to determine the conditions under which personnel can access systems?
  • What is a tool that inspects outbound traffic to reduce potential threats?
  • What aspect of information security does security architecture address?
  • In the context of encryption, what does the term "key" refer to?
  • What is the primary goal of implementing security awareness training in an organization?
  • An external attacker trying to access internal files is an example of what?
  • During an audit, what should Olaf, the security analyst, do when he knows Triffid is not adhering to security standards?
  • Which type of fire-suppression system is typically considered the safest for humans?
  • Which control is NOT useful for managing visitors to a secure facility?
  • If Zarma is asked about the types of questions in the (ISC)² certification exam, what should he do?
  • Which term best describes Gelbi's account at Triffid, Inc. as he installs or removes software?
  • What term describes data left behind on systems/media after deletion procedures?
  • Which measure is essential for ensuring data is securely disposed of after its retention period?
  • What function does a rootkit serve?
  • Which type of event poses the most risk?
  • The Common Body of Knowledge (CBK) published by (ISC)² is recognized as what type of document in the industry?
  • What does “containment” involve in the context of an incident response plan?
  • Which of the following terms describes the act of shifting the risk to another entity?
  • What is the primary purpose of data loss prevention (DLP) systems?
  • What outcome does a Denial of Service (DoS) attack aim to achieve?
  • A human guard monitoring a hidden camera is an example of which type of control?
  • What aspect of security can hinder productivity if not properly aligned with business needs?
  • What role does a certificate authority (CA) play in a network?
  • What type of encryption should a security analyst use to ensure message authenticity?
  • What kind of control is the instruction that requires employees to receive security awareness training before using email?
  • What kind of control is MAC address filtering on a router?
  • What is a data breach?
  • Which type of cyber threat involves overwhelming a service to make it unavailable?
  • What is the key focus of a business impact analysis?
  • What is the role of a security management framework?
  • In what way does security architecture impact an organization?
  • What does the term "vulnerability" refer to in a security context?
  • What is the principle of least privilege?
  • What is a threat vector in cybersecurity?
  • Which of the following best defines cryptography?
  • What does "security architecture" refer to?
  • What is the primary purpose of a VPN in a network?
  • What does remediation in cybersecurity refer to?
  • How frequently should logs be reviewed for security purposes?
  • Which of the following incidents would fall under the responsibility of incident response teams?
  • What is a priority in the development of a business continuity plan?
  • What is the main goal of an incident response effort?
  • What type of control would be most effective in ensuring cars do not collide with pedestrians?
  • Which cloud deployment model typically stores a single customer's data and functionality on specific systems or hardware?
  • What are some common consequences of a data breach?
  • Which of the following is an example of a biometric access control mechanism?
  • In the situation where Prachi has permission checks, what does the access control list (ACL) represent?
  • If Aphrodite discovers a coworker violating the acceptable use policy, what should she do?
  • What is a security incident?
  • Which port is typically used for HTTP traffic when Carol is browsing the Web?
  • What is likely to be included in a business continuity plan?
  • Why is it important to conduct penetration testing?
  • What type of control is a software firewall that prevents certain traffic from entering a device?
  • Which type of drill assesses evacuation procedures during a disaster recovery effort?
  • What is the most fundamental goal of data loss prevention?
  • What device filters network traffic to enhance overall security and performance?
  • What type of attack might Ludwig notice that affects the availability of the environment?
  • Which communication protocol should Barry use for secure and efficient file uploads to a web-based storage service?
  • The practice of ensuring data is only accessible to those authorized is known as what?
  • How is a "white hat hacker" defined?
  • In business continuity terminology, what does 'critical functions' refer to?
  • If Tina discovers malware sharing in an online group, what is the recommended action?
  • What does endpoint security primarily focus on?
  • Which of the following is a fundamental component of perimeter security?
  • Security controls on log data should reflect what key factor?
  • To ensure availability for a data center, it is best to plan for both resilience and what aspect of the elements in the facility?
  • When Cheryl is browsing the Web, which protocol is she likely using?
  • What technique could be used to ensure a message has not been modified during transit?
  • In the context of risk management, what is defined as something or someone that poses a risk to an organization or asset?
  • What is the purpose of change management in IT security?
  • Which of the following is NOT a recognized data classification label?
  • Which of the following is the most critical aspect of an organization's disaster recovery efforts?
  • For which asset is integrity considered the most important security aspect?
  • What type of app allows users to perform certain functions but may also steal sensitive information?
  • What type of attack involves intercepting and surveilling the communication traffic between two devices?
  • What is a common function of Anti-malware software?
  • What factor distinguishes a "something you have" authentication method?
  • What is defined as a record of something that has occurred?
  • What is the purpose of business continuity planning (BCP)?
  • What does CIA stand for in information security?
  • What allows remote users to have secure access to the internal IT environment?
  • What does penetration testing involve?
  • Define risk management in cybersecurity.
  • Which statement best describes the function of cryptography?
  • How does qualitative risk assessment differ from quantitative risk assessment?
  • In the context of cybersecurity, what does the abbreviation BCP stand for?
  • If a database manager can add or remove users but cannot read the data, this illustrates what type of access control?
  • Who is responsible for approving an incident response policy?
  • What is the common term for a place where wires and conduits are run and equipment is placed to facilitate local networks?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy