# Credential-Domain Knowledge Check (Original Questions)

Version 1 · checked 2026-10-07. Five questions per credential; one point per question. Answers and rationales follow each item.

**Important:** This is a short Dojo diagnostic, not an official item, exam simulation, full practice exam, or pass predictor. Do not use it instead of official study materials. All questions and choices are original and do not reproduce ISC2 or ISACA exam questions.

## Original CISSP®-related checks

### 1. Security and Risk Management

A team asks you to “review our customer-facing AI feature,” but the environment and permitted methods are missing. What should happen first?

A. Begin if you use read-only tools  
B. Collect public information first  
C. Confirm the approver, target, methods, time window, and exclusions in writing  
D. Ask the AI agent to define a safe scope

**Answer: C.** Stop until authorization boundaries are explicit. Read-only or public-information work is not a substitute for approval.

### 2. Asset Security

A learner is about to share an evidence packet. A synthetic log contains an unrelated email address and a token-like string. What is best?

A. Share the full log for reproducibility  
B. Remove unrelated personal information and secrets while retaining the minimum relevant source, time, and context  
C. Claim the token-like string is valid  
D. Copy the original to everyone's personal device

**Answer: B.** Preserve only the relevant minimum; do not disclose unrelated personal data or secrets.

### 3. Security Architecture and Engineering

A fictional exercise assistant has tools to read supplied logs, browse arbitrary URLs, send files, and run commands. The task is only to review a supplied synthetic log. Which setup is safest?

A. Enable everything and rely on the prompt  
B. Allow only the required read tool, disable the rest, and define a human stop procedure  
C. Allow arbitrary commands and inspect logs afterward  
D. Open network access when the agent thinks it is needed

**Answer: B.** Enforce least privilege and controls in the environment, not only in a prompt.

### 4. Communication and Network Security

During a paper exercise, the agent suggests contacting an external URL. The exercise specification permits no external traffic. What should happen?

A. Visit it if it uses HTTPS  
B. Try DNS resolution only  
C. Do not connect; stop and report the scope mismatch to the facilitator  
D. Use a VPN to anonymize the connection

**Answer: C.** Do not perform an unapproved network action; stop and record the mismatch.

### 5. Identity and Access Management

Which credential design is best for the exercise assistant?

A. Put shared administrator credentials in the workbook  
B. Use short-lived least-privilege access and require human approval where needed  
C. Put a long-lived token in the prompt for convenience  
D. Let the assistant obtain credentials itself

**Answer: B.** Limit role, duration, and approval; keep credentials out of prompts and materials.

### 6. Security Assessment and Testing

A four-line synthetic log says “scope document missing” and “no external action.” Which report is justified?

A. The system was not compromised  
B. A compromise occurred  
C. This excerpt records a missing scope document and no external action, but activity outside the excerpt and impact are unknown  
D. The agent is certified safe

**Answer: C.** Separate what the log shows from what cannot be inferred.

### 7. Security Operations

The log excerpt is short and its coverage and completeness are unverified. What should the report preserve?

A. State that it is the complete log  
B. Record source, time, fixture identifier, scope, and known gaps  
C. Fill missing periods with typical behavior  
D. Publish raw logs for reproducibility

**Answer: B.** State provenance, coverage, and uncertainty without overstating completeness.

### 8. Software Development Security

Which is the most verifiable acceptance condition for an agent-policy change?

A. “Improve security”  
B. “Prevent all future issues”  
C. “In a tabletop replay with missing authorization fields, refuse the action, log the reason, and make no external connection”  
D. “The owner thinks it looks good”

**Answer: C.** It defines the boundary, expected behavior, record, and absence of external effects.

## Original CISA®-related checks

### 1. Information Systems Auditing Process

An audit request lacks an approver and identified assets. What should the auditor do first?

A. Collect a sample immediately  
B. Confirm authority, independence, and scope; resolve the gaps  
C. Ask the technical team to guess the scope  
D. Continue because the impact seems small

**Answer: B.** Establish authority and scope before planning and collecting evidence.

### 2. Governance and Management of IT

An administrator verbally asks for an “immediate test,” but the formal approval path is unclear. What matters most?

A. Treat the administrator's title as approval  
B. Check the organization's policy for the authorized decision-maker, responsibility, and approval record  
C. Delegate approval to the agent  
D. Proceed if results remain secret

**Answer: B.** Verify the accountable authority and governance evidence.

### 3. Information Systems Acquisition, Development and Implementation

Which evidence is most useful in a post-implementation review of a change?

A. A chat message from the developer saying “done”  
B. Test results against agreed acceptance criteria, change approval, deviations, and remediation records  
C. Only a screenshot from before the change  
D. The number of changed code lines

**Answer: B.** Judge the implementation against approved requirements using post-change evidence.

### 4. Information Systems Operations and Business Resilience

A gap is found in log retention, but its impact is unknown. What is the best report?

A. State that an incident definitely occurred  
B. Identify the missing period, systems, and log sources; state that impact assessment is incomplete  
C. Reconstruct missing logs from assumptions  
D. Omit the issue to avoid overstatement

**Answer: B.** Separate facts, scope, and unresolved impact.

### 5. Protection of Information Assets

A file for evidence sharing contains personal information and secrets. What is the best action?

A. Distribute the unmodified file broadly as audit evidence  
B. Preserve the protected original appropriately and prepare a restricted, minimized, redacted sharing copy  
C. Send it to a personal email account  
D. Delete both copies without a record

**Answer: B.** Protect confidentiality while preserving evidence integrity and minimizing access.

## Review

The score is only the number correct on this 5- or 8-item original check. It does not predict a credential exam result. Record missed domains and study them using the current official outline and resources. Facilitators should track question version and source review date.
