CISSP Asset Security: 47 practice questions
12 of the 47 Asset Security questions in the Certsqill CISSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISSP? Take the free 5-min readiness check →
1. Data owner: Who is responsible for determining the classification level of organizational data and approving a
- Data owner ✓Correct. The data owner (typically a business manager or executive) is responsible for classifying data and approving who can access it. They bear business accountability for the data.
- Data custodianIncorrect. The data custodian (typically IT operations) implements the controls specified by the data owner — backups, access controls, encryption. They don't determine classification.
- Data userIncorrect. Data users consume data in their day-to-day work. They have no authority to classify data or approve others' access.
- Security administratorIncorrect. Security administrators implement technical security controls. Classification and access approval are business decisions made by the data owner.
Data owner = responsible for classification and access approval. Data custodian = implements controls. Data user = consumes data.
2. Physical destruction of the drives by degaussing them: Which data destruction method BEST ensures the data can
- Deleting all files and then emptying the Recycle Bin before the drives are handed off for disposalIncorrect. Deleting files and emptying the recycle bin only removes directory entries. Data is trivially recoverable. This is the least secure method.
- Physical destruction of the drives by degaussing them and then shredding or incinerating the remains ✓Correct. For Top Secret data, physical destruction is the gold standard — degaussing destroys magnetic data, followed by physical shredding or incineration ensures no recovery is possible.
- Standard formatting of each drive using the operating system's built-in format command before reuseIncorrect. Standard formatting only removes file system metadata. Data remains recoverable with forensic tools. This is completely inadequate for sensitive data.
- Overwriting each drive one to three times with random data per the DoD 5220.22-M sanitization standardIncorrect. Overwriting (DoD standard) is adequate for many use cases, but for Top Secret government data, physical destruction is required. Modern SSDs make guaranteed overwriting unreliable.
Top Secret data disposal: physical destruction (degaussing + shredding/incineration) is the only method that guarantees irrecoverable destruction.
3. Secret classification requires controlled access: Which classification level requires this level of concern, a
- The analyst should move the document to a shredder right away to prevent any further exposure of its contents to unauthorized staff in the open officeIncorrect. Destroying government classified documents without authorization is itself a security violation. The document should be secured and the incident reported.
- No action is needed, because Secret sits exactly one classification level below Top Secret and therefore does not call for any special handling or controlled storage by staffIncorrect. All classified information (Confidential, Secret, Top Secret) requires controlled handling and storage. There is no 'relaxed handling' level among classified tiers.
- Secret classification requires controlled access; the analyst should secure the document immediately and report the security violation per incident response procedures ✓Correct. Secret information can cause serious damage to national security if disclosed. It must be secured in approved storage facilities. An unattended Secret document is a security violation requiring immediate action and reporting.
- Because the document is sitting inside an internal office where all employees already hold a clearance, there is no need for the analyst to take any protective or reporting actionIncorrect. Need-to-know applies separately from clearance. Even cleared employees cannot access Secret information they don't need to know. An open office is not a secure area for Secret materials.
Secret documents left unattended = security violation. Secure the document immediately, report the incident — need-to-know applies regardless of clearance level.
4. Information Rights Management: Which technology BEST addresses this requirement?
- File encryption, which scrambles the document at rest so only holders of the correct decryption key can open itIncorrect. Encryption controls access to the file itself but once decrypted by an authorized user, they can print, forward, or copy the decrypted content freely.
- Data Loss Prevention (DLP), which inspects and blocks sensitive content from leaving the organization by email or endpointIncorrect. DLP monitors and blocks sensitive data from leaving the organization via network, email, or endpoints. It does not control what authorized users can do WITHIN the organization with documents they legitimately access.
- Access control lists (ACLs), which specify precisely which users may read, write, or execute a given protected resourceIncorrect. ACLs control who can access a resource (read, write, execute) but cannot control how a user uses the content after they have read access — they can still print or forward.
- Information Rights Management (IRM/DRM), which embeds no-forward and no-print usage rules directly into the document ✓Correct. IRM/DRM embeds usage restrictions directly into documents and emails. Controls can prevent forwarding, printing, copying, and editing even for users who have read access.
IRM/DRM embeds usage controls (no forward, no print, expiry) directly into documents — enforces restrictions even for users with legitimate read access.
5. Immediately suspend the automated deletion policy: What action is legally required?
- Immediately suspend the automated deletion policy for relevant data and implement a legal hold to preserve potentially relevant evidence ✓Correct. Upon notice of litigation, organizations have a duty to preserve potentially relevant evidence (spoliation prevention). Continuing to delete data under normal retention policies can result in spoliation sanctions.
- Obtain a formal court order first, before suspending any automated deletion, so that the correct legal procedure is observedIncorrect. Waiting for a court order while data is being deleted is not acceptable. The duty to preserve arises upon reasonable anticipation of litigation — organizations must act proactively.
- Preserve only the records that have already been specifically subpoenaed, and allow the normal automated deletion of all other data to continueIncorrect. The legal hold applies to all potentially relevant data, not just what has been specifically subpoenaed. Broad preservation is required when the scope is not yet defined.
- Continue deleting the data on the existing retention schedule, since the deletion policy was approved well before the litigation notice arrivedIncorrect. Knowingly deleting relevant data after litigation notice is spoliation — destruction of evidence. This creates serious legal liability regardless of pre-existing policy.
Litigation notice triggers legal hold duty — immediately suspend automated deletion for potentially relevant data to prevent spoliation.
6. Data remanence: What is the PRIMARY concern from a security perspective?
- Availability risk — the provider is likely to breach its uptime SLAs while it decommissions and then repurposes the mediaIncorrect. Repurposing media after decommissioning is normal operations. The security risk is the residual data on that media.
- Data remanence — residual data from the previous customer may persist on the storage media and be accessible to the new customer ✓Correct. Data remanence is the residual representation of data that remains on storage media after deletion. Without proper sanitization, previous customers' data could be read by new users.
- Hardware degradation — the storage media will wear out and fail more quickly because it is being reused across many different customersIncorrect. Hardware lifecycle is a maintenance concern, not a security concern. The primary security risk is data from previous customers being accessible.
- Storage performance — the incoming customer may not receive sufficient throughput or IOPS from media previously provisioned to another tenantIncorrect. Performance is an operational concern. The security concern is confidentiality of previous customers' data.
Data remanence: residual data persists on storage media after deletion. Proper sanitization (cryptographic erasure, overwriting, degaussing) required before repurposing.
7. Confidential / Proprietary: In a commercial (non-government) data classification scheme, which level typically
- Private, the tier that typically covers employee personal records such as salaries, benefits, and internal HR filesIncorrect. In commercial classification, Private typically refers to employee personal information (HR records, salaries) — sensitive but below Confidential/Proprietary.
- Top Secret, the tier reserved for information whose disclosure would cause the most severe damage possibleIncorrect. Top Secret is a government classification level, not a commercial one. Commercial organizations use labels like Confidential, Private, Sensitive, Public.
- Confidential / Proprietary, the tier covering trade secrets and strategic data whose leak causes serious harm ✓Correct. In commercial classification, Confidential/Proprietary is the highest sensitivity level — trade secrets, financial data, strategic plans, customer PII. Disclosure causes significant competitive or regulatory harm.
- Sensitive, the tier for internal data that requires careful handling but still sits below the strongest protection levelIncorrect. Sensitive is typically a lower tier in commercial classification, covering data requiring care but not at the highest protection level.
Commercial classification highest to lowest: Confidential/Proprietary → Private → Sensitive → Public. Government: Top Secret → Secret → Confidential → Unclassified.
8. Cryptographic erasure or multi-pass overwriting of all: What is the MINIMUM required data sanitization before
- Reinstalling the operating system on each laptop, on the basis that this deletes all previous user dataIncorrect. Reinstalling the OS overwrites system files but leaves most user data recoverable with forensic tools. Previous confidential data can still be retrieved from unoverwritten sectors.
- Performing no sanitization at all, since the data on the laptops was merely confidential rather than government classifiedIncorrect. Confidential commercial data requires sanitization before any hardware leaves organizational control. Classification level (government) is different from sensitivity — confidential financial data warrants careful disposal.
- Performing a factory reset through the operating system's built-in settings menu before the laptops are donatedIncorrect. Factory reset typically only removes file system metadata. Data remains recoverable. Some modern devices with full-disk encryption may make factory reset more effective, but this cannot be assumed.
- Cryptographic erasure or multi-pass overwriting of all drives to prevent data recovery by forensic tools ✓Correct. Laptops that processed confidential data require sanitization that prevents forensic recovery. Multi-pass overwriting (DoD standard) or cryptographic erasure are minimum requirements before public reuse.
Confidential data laptops require cryptographic erasure or multi-pass overwriting before donation — OS reinstall and factory reset leave data forensically recoverable.
9. Tokenization — replace the PAN with a non-sensitive token: Which technique BEST reduces PCI scope while allowi
- Tokenization — replace the PAN with a non-sensitive token; the actual PAN is stored in a secure token vault, removing most systems from PCI scope ✓Correct. Tokenization replaces the PAN (Primary Account Number) with a token. Systems handling only tokens are removed from PCI DSS scope. The token vault maintains the mapping. Tokens can be used for analytics.
- Hashing — apply an irreversible one-way hash to each credit card number before storage, so the original PAN itself never sits in the analytics databaseIncorrect. Hashing is one-way — you cannot recover the original PAN from a hash. This prevents using the stored data for recurring billing (can't send the original PAN for payment processing).
- Data masking — overwrite most of the digits with asterisks, such as **** **** **** 1234, before the card number is written to storage for later useIncorrect. Masking is for display purposes (show last 4 digits only). Masked data cannot be used to process payments — you can't run billing with masked card numbers.
- Encryption — encrypt every stored credit card number, on the basis that systems holding only encrypted values sit outside PCI DSS scopeIncorrect. Systems handling encrypted cardholder data (even encrypted PANs) remain in PCI DSS scope because the encryption keys are also present. Encryption does not reduce PCI scope as effectively as tokenization.
Tokenization replaces PANs with tokens, removing most systems from PCI scope; the token vault holds the mapping for recurring billing while tokens enable analytics.
10. Network DLP — inspects email traffic at the mail gateway: Which DLP deployment mode enabled this detection?
- Discovery DLP — scans stored data at rest for credit card numbers well before the employee ever attempts to email it outIncorrect. Discovery DLP scans stored data at rest to find sensitive data. It does not intercept outbound transmissions in real-time.
- Network DLP (inline mode) — inspects email traffic at the mail gateway before it leaves the organization's perimeter ✓Correct. Network DLP in inline mode sits in the traffic path at the perimeter (mail gateway/proxy) and can inspect outbound email content, detecting and blocking sensitive data before transmission.
- Endpoint DLP — an agent installed on the user's own workstation intercepts and blocks the outbound email at the local levelIncorrect. Endpoint DLP could also achieve this, but the question describes the DLP detecting and blocking at the email level — this describes a network/gateway-level control. Both are valid deployment modes but the scenario describes network-level blocking.
- Cloud DLP — Gmail's own built-in DLP feature inspects the attachment and blocks it on the receiving provider's sideIncorrect. The organization's DLP system blocked the email — not Gmail's. Gmail DLP would only work for Google Workspace users, not personal Gmail receiving attachments.
Network DLP inline at the mail gateway inspects outbound email content and can block transmission of sensitive data before it leaves the organization.
11. Confidential — because the data contains PHI regulated: Which classification level is MOST appropriate and wha
- Confidential — because the data contains PHI regulated under HIPAA and disclosure is limited to those with a treatment, payment, or operations relationship ✓Correct. PHI under HIPAA is restricted to authorized parties with a legitimate need (treatment, payment, operations). The 'Confidential' level reflects the regulatory obligation, limited disclosure scope, and sensitivity that define this classification.
- Internal Use Only — because access to the prescription histories is limited to organizational staff and contracted external partners rather than being released to the general public at largeIncorrect. 'Internal Use Only' typically covers non-public business information without specific regulatory protection. PHI carries legal penalties for unauthorized disclosure under HIPAA and therefore warrants a higher classification than generic internal data.
- Public — because insurance partners and billing staff already access the records, indicating the data is approved for broad distributionIncorrect. Broad authorized access within defined relationships does not make data public. Public classification means the data may be freely disclosed to anyone; PHI can never be public, since disclosure outside authorized relationships violates HIPAA.
- Top Secret — because patient health data is inherently sensitive and therefore demands the very highest protection tier available within any data classification scheme in useIncorrect. 'Top Secret' is a government/military classification for national-security information. Healthcare organizations use schemes like Public/Internal/Confidential/Restricted. Applying a military tier to commercial healthcare data is a category error, even though PHI is sensitive.
PHI under HIPAA is Confidential — legally restricted, limited to authorized relationships (treatment, payment, operations), with significant penalties for unauthorized disclosure.
12. Data Owner — responsible for classifying the data: Which role does the HR director hold?
- Data Custodian — because the HR director personally manages the employee records day-to-day within the human resources department and its systemsIncorrect. The Data Custodian is typically IT: implementing controls, managing storage, performing backups, and enforcing the access policy the Owner sets. Here the HR director sets policy while IT implements it, so custodial responsibilities are not what the director holds.
- Data Owner — responsible for classifying the data, determining access policy, and accepting residual risk for the data asset ✓Correct. The Data Owner is a senior business role (not IT) that decides what data is collected, how it is classified, who may access it, and accepts accountability for the asset. The HR director's decisions on retention, classification, and access authorization are hallmarks of data ownership.
- Data User — because the HR director regularly accesses and consumes the employee records to support routine business decisions and reporting activitiesIncorrect. Data Users access and use data within defined constraints (for example, HR analysts running reports). The HR director's defining actions are policy-setting and accountability, not consumption, so this role does not describe the scenario.
- Data Steward — because the HR director oversees the ongoing data quality and governance processes surrounding the recordsIncorrect. A Data Steward focuses on data quality, metadata, and governance processes (consistent definitions, data lineage). The scenario instead emphasizes classification authority, access authorization, and retention policy, which are Data Owner responsibilities.
The Data Owner (HR director) classifies data, sets access policy, and accepts accountability. The Custodian (IT) implements those controls. Users consume the data.
35 more Asset Security questions
The remaining 35 questions in this domain are part of the full CISSP bank — 497 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISSP readiness — freeOther CISSP domains
- Security and Risk Management — 89 questions →
- Security Architecture and Engineering — 87 questions →
- Communication and Network Security — 63 questions →
- Identity and Access Management (IAM) — 63 questions →
- Software Development Security — 59 questions →
- All 497 CISSP questions →