Certified Information Systems Security Professional
Validates expertise across eight domains of information security including security and risk management, asset security, security architecture, network security, identity management, security assessment, security operations, and software development security. Requires five years of paid work experience and targets experienced practitioners in leadership roles such as CISOs, security architects, and security managers. The premier cybersecurity certification globally, accredited under ISO/IEC 17024 and approved by the U.S. DoD under DoDM 8140.03.
Sample questions
A free preview of 15 source-grounded questions from this exam — answers and explanations included.
- Q1Security and Risk Managementeasy
An organization is evaluating its exposure to risks from products that may contain malicious functionality, be counterfeit, or be vulnerable due to poor manufacturing practices. Which statement best characterizes the underlying problem described in SP 800-161?
- A.Supply-chain cybersecurity risk is purely a regulatory concern and does not affect the operational integrity of acquired products.
- B.The risks are eliminated automatically once an enterprise signs a master services agreement with the vendor. That description departs from the actual abstract of the cited document.
- C.These risks are associated with an enterprise's decreased visibility into and understanding of how the technology they acquire is developed, integrated, and deployed.Correct answer
Sources
Questions are grounded in 150 references from official and authoritative materials.
- SP 800-123, Guide to General Server Security | CSRC
- SP 800-55 Vol. 1, Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures | CSRC
- SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations | CSRC
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems | CSRC