2.0 Asset Security CISSP Practice Quiz
80 exam-style questions covering 10% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regional health system is updating its data classification scheme ahead of an HHS audit. A new control baseline must address information and asset classification. What should be included?
- A. Define classification levels based on business value, sensitivity, legal obligations, and potential impact of disclosure or alteration
- B. Apply classification labels to the database name, not the data inside
- C. Skip classification on backups and reports because the source store is labeled
- D. Strip classification banners from documents because users find them distracting
Classification should reflect the value and risk of the information or asset to the organization. This is the correct answer.
A global investment bank is updating data classification for trading-floor systems. An assessment identifies inconsistent practice for information and asset classification. Which action should the security professional prioritize?
- A. Review classification periodically and when business use, regulation, or data sensitivity changes
- B. Ignore backups and report extracts because the master record is already labeled
- C. Remove classification headers and footers because they're an aesthetic concern
- D. Default everything to public so the access control problem disappears
Classification can become inaccurate as data use and obligations change. This is the correct answer.
A pharmaceutical contract manufacturer is reviewing how it labels regulated batch records. A risk review finds a gap related to information and asset classification. Which response is most appropriate?
- A. Have DBAs unilaterally assign classification with no business-owner involvement
- B. Assign an accountable data owner to determine classification and approve handling requirements
- C. Use storage location as the only attribute that determines data classification
- D. Treat downstream copies as inheriting classification with no re-evaluation
Data owners understand business impact and are responsible for classification decisions. This is the correct answer.
A SaaS provider is mapping customer data flows ahead of a SOC 2 Type II audit. The data governance committee asks for guidance on information and asset classification. Which approach best aligns with CISSP practice?
- A. Skip data-level classification and use database-of-residence instead
- B. Include physical assets, information assets, software, services, and removable media in the asset inventory
- C. Skip labeling and access controls on derived reports built from classified data
- D. Disable visual classification labels because users complain they're noisy
Asset security requires knowing what exists before applying protection. This is the correct answer.
A research university is reconciling federal grant data protection obligations across labs. The security team must make an asset security decision involving information and asset classification. What is the best recommendation?
- A. Skip handling controls on data warehouses derived from classified sources
- B. Tie classification categories to control baselines such as encryption, access review, retention, and disposal requirements
- C. Suppress classification banners to keep PDF reports tidy
- D. Mark all information as public to avoid having to manage tiered access
Classification is useful when it drives practical security requirements. This is the correct answer.
A federal contractor is reconciling CUI handling against revised NIST 800-171 requirements. The CISO asks how to strengthen information and asset classification without disrupting business operations. What should be recommended?
- A. Mark every dataset 'public' to streamline information sharing
- B. Let infrastructure teams declare classification levels without business input
- C. Classify information consistently across structured data, unstructured data, backups, reports, and derived datasets
- D. Treat 'lives in DB-X' as the entire classification rule for the contents
Sensitive information can appear in many forms and should not lose classification because it changes format. This is the correct answer.
A regional utility is reviewing classification of OT historian data after an OSHA inquiry. A new control baseline must address information and asset classification. What should be included?
- A. Allow storage operators to assign classification with no consultation
- B. Inherit classification from the database object rather than the data semantics
- C. Identify asset custodians separately from asset owners when operational responsibility differs from business responsibility
- D. Treat backup copies as classification-irrelevant because the source is labeled
Owners decide value and requirements, while custodians operate or maintain assets. This is the correct answer.
A consumer fintech is renewing its data inventory after a privacy incident in a peer firm. The security team must make an asset security decision involving information and asset classification. What is the best recommendation?
- A. Hide classification markings to make documents look 'cleaner'
- B. Apply 'public' as the universal classification to make sharing easy
- C. Treat DBAs as data owners and skip business engagement in classification
- D. Use labels or metadata so users and systems can recognize the classification and apply handling rules
Classification must be visible or machine-readable to support consistent protection. This is the correct answer.
Key Terms in This Domain
- NIST Risk Management Framework: NIST SP 800-37 lifecycle for managing information system risk
- ISO 27001: International standard for an information security management system (ISMS)
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- DRM: Digital Rights Management: controls on use of digital content
- HSM: Hardware Security Module: tamper-resistant key management device
- SOC 2: Service Organization Controls report on security/availability/confidentiality
- Due Care: Reasonable steps an organization takes to protect assets
- Due Diligence: Ongoing effort to investigate, assess, and verify controls and risks
- Risk Avoidance: Eliminate the activity or asset that introduces the risk
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/asset-security/
<a href="https://quizbuffet.com/isc2-cissp/asset-security/">CISSP (ISC2) Asset Security practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 3.0 Security Architecture and Engineering
- 4.0 Communication and Network Security
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.