Practice questions · Cybersecurity

CISSP (ISC2): Practice Questions

expert 273 questions

Original concept-check questions on core CISSP ideas across the eight domains. Choose an answer to reveal the explanation, including why the other options are wrong. Aim to reason like a risk-focused manager. These are concept checks, not real exam questions.

By The Exam Atlas Editorial Team · Verified 2026-06-06 · ~341 min

  1. Identity & Access Management easy

    Giving a user only the access strictly required to do their job is the principle of:

  2. Security & Risk Management easy

    Ensuring data has not been altered in an unauthorised way protects which part of the CIA triad?

  3. Security Architecture & Engineering medium

    The Bell-LaPadula model is primarily designed to protect:

  4. Security & Risk Management easy

    Buying insurance to handle the financial impact of a risk is an example of risk:

  5. Security Architecture & Engineering easy

    'Defense in depth' means:

  6. Security & Risk Management medium

    Risk is most commonly assessed as a function of:

  7. Identity & Access Management easy

    Multi-factor authentication (MFA) requires:

  8. Security Architecture & Engineering medium

    Which statement describes hashing rather than encryption?

  9. Identity & Access Management medium

    An access control model where the system enforces access using security labels and clearances is:

  10. Security Operations medium

    The Recovery Time Objective (RTO) defines:

  11. Security & Risk Management medium

    The main purpose of separation of duties is to:

  12. Security & Risk Management medium

    'Residual risk' is best described as:

  13. Asset Security medium

    Labeling data as Public, Internal, Confidential and Restricted is an example of:

  14. Asset Security medium

    To ensure data on a decommissioned drive cannot be recovered, you should:

  15. Security Architecture & Engineering medium

    Symmetric encryption is generally preferred over asymmetric encryption for:

  16. Security Architecture & Engineering hard

    A hardware component that securely stores cryptographic keys on a device is a:

  17. Communication & Network Security medium

    Which protocol encrypts web traffic in transit?

  18. Communication & Network Security medium

    A stateful firewall differs from a stateless one because it:

  19. Communication & Network Security medium

    Dividing a network into zones so a breach in one cannot easily reach others is:

  20. Identity & Access Management medium

    SAML is most commonly used to enable:

  21. Identity & Access Management medium

    Promptly removing access when an employee leaves is part of:

  22. Security Assessment & Testing medium

    A penetration test differs from a vulnerability scan because it:

  23. Security Assessment & Testing hard

    Analyzing source code for flaws without running the application is:

  24. Security Assessment & Testing medium

    Regularly reviewing audit logs primarily supports:

  25. Security Operations medium

    The generally accepted order of incident response is:

  26. Security Operations medium

    A '3-2-1' backup strategy means:

  27. Security Operations medium

    Configuring a system to run only the services it actually needs is the principle of:

  28. Software Development Security medium

    Validating and sanitizing user input primarily prevents:

  29. Software Development Security medium

    Building security into every phase of development rather than adding it at the end describes a:

  30. Security & Risk Management medium

    Due diligence differs from due care in that due diligence is:

  31. Security & Risk Management hard

    A company calculates that a single flood would cause $200,000 in damage and that such a flood is expected once every 20 years. What is the annualized loss expectancy (ALE)?

  32. Security & Risk Management medium

    Which document tells employees what they must do, in mandatory language, and is the highest-level statement of management intent?

  33. Security & Risk Management medium

    A security manager decides not to operate a new service line at all because the risk is unacceptable and cannot be reduced affordably. This response is risk:

  34. Security & Risk Management medium

    Under most modern data protection laws, the party that determines the purposes and means of processing personal data is the:

  35. Security & Risk Management medium

    When a security manager faces a scenario question, ISC2 generally expects the first action to be the one that is:

  36. Security & Risk Management medium

    Quantitative risk analysis differs from qualitative analysis primarily because quantitative analysis:

  37. Security & Risk Management medium

    A clause in a contract stating that neither party will disclose the other's confidential information is most precisely a(n):

  38. Security & Risk Management hard

    The main reason to enforce mandatory vacations for staff in sensitive financial roles is to:

  39. Security & Risk Management medium

    An organization adopts a recognized control framework so it can structure and benchmark its security program. Which of the following is such a framework?

  40. Security & Risk Management easy

    A threat is best defined as:

  41. Security & Risk Management medium

    Why is senior management 'buy-in' considered essential to an information security program?

  42. Security & Risk Management medium

    An organization is legally required to keep tax records for seven years. The document that defines how long different records are kept and when they are destroyed is the:

  43. Security & Risk Management hard

    The (ISC)2 Code of Ethics canons are listed in a deliberate order. When two canons appear to conflict, a CISSP should resolve it by:

  44. Security & Risk Management easy

    A vulnerability is most accurately described as:

  45. Security & Risk Management easy

    Security awareness training is most effective when its main goal is to:

  46. Security & Risk Management medium

    A company keeps operating its legacy system and budgets for the expected losses because fixing it would cost more than the risk. This is a documented case of risk:

  47. Security & Risk Management medium

    Intellectual property that is protected only as long as it is kept secret, such as a recipe or algorithm, is a:

  48. Security & Risk Management hard

    In a quantitative risk analysis, the single loss expectancy (SLE) is calculated as:

  49. Security & Risk Management easy

    Why does CISSP guidance treat people as 'the weakest link' in security?

  50. Asset Security medium

    Who is ultimately accountable for deciding how a particular set of corporate data is classified and protected?

  51. Asset Security medium

    Protecting cardholder data while it is being processed in a server's memory is an example of protecting data:

  52. Asset Security medium

    The risk that deleted or overwritten data can still be recovered from storage media is known as data:

  53. Asset Security hard

    An organization must keep customer data on servers physically located within its own country to satisfy local law. This requirement reflects data:

  54. Asset Security medium

    Replacing the digits of a credit card number with a surrogate value that has no exploitable meaning, while keeping the format, is:

  55. Asset Security medium

    Under a typical four-tier scheme (Public, Internal, Confidential, Restricted), customer payment details would most appropriately be labelled:

  56. Asset Security medium

    The main security benefit of a clearly defined data retention schedule is that it:

  57. Asset Security easy

    Disguising portions of a value, such as showing a card as **** **** **** 1234 on a receipt, is best described as data:

  58. Asset Security hard

    Degaussing is an appropriate sanitization method for:

  59. Asset Security easy

    Assigning each major information asset a business owner who is responsible for its protection mainly supports:

  60. Asset Security medium

    A data custodian's responsibilities most accurately include:

  61. Asset Security hard

    When media is reused within the same security boundary but for a different purpose, the recommended action is to:

  62. Asset Security easy

    The primary purpose of classifying information is to:

  63. Security Architecture & Engineering medium

    The Biba security model is designed primarily to protect:

  64. Security Architecture & Engineering hard

    A digital signature provides integrity and non-repudiation by:

  65. Security Architecture & Engineering medium

    In public key cryptography, to send a message that only the intended recipient can read, the sender encrypts it with the recipient's:

  66. Security Architecture & Engineering hard

    The component in a trusted system that mediates all access between subjects and objects, and must be tamperproof, is the:

  67. Security Architecture & Engineering hard

    Two users who have never met need to agree on a shared secret over an insecure channel. The classic protocol designed for this is:

  68. Security Architecture & Engineering medium

    A certificate authority's main role in a public key infrastructure (PKI) is to:

  69. Security Architecture & Engineering medium

    The principle that a system should default to denying access unless access is explicitly granted is called:

  70. Security Architecture & Engineering hard

    A salted hash improves password storage over a plain hash primarily because the salt:

  71. Security Architecture & Engineering easy

    Keeping a security design simple and minimizing complexity is valuable mainly because:

  72. Security Architecture & Engineering medium

    A mantrap (access control vestibule) at a data centre entrance is designed primarily to prevent:

  73. Security Architecture & Engineering easy

    An organization wants to ensure a message's sender cannot later deny sending it. Which property is required?

  74. Security Architecture & Engineering hard

    Why is AES generally preferred over DES for new systems?

  75. Security Architecture & Engineering medium

    The security weakness of relying on 'security through obscurity' is that:

  76. Security Architecture & Engineering medium

    A fire suppression system that removes heat or oxygen rather than using water is preferred in a server room because:

  77. Security Architecture & Engineering hard

    The Clark-Wilson integrity model enforces integrity mainly through:

  78. Security Architecture & Engineering hard

    Perfect forward secrecy in a key exchange ensures that:

  79. Communication & Network Security medium

    At which layer of the OSI model do IP addressing and routing primarily operate?

  80. Communication & Network Security medium

    A demilitarized zone (DMZ) in network design is used to:

  81. Communication & Network Security medium

    Which attack involves an attacker secretly relaying and possibly altering communication between two parties who believe they are talking directly?

  82. Communication & Network Security medium

    A VPN using IPsec in tunnel mode primarily provides:

  83. Communication & Network Security hard

    Why is plain DNS (without DNSSEC) considered a security weakness?

  84. Communication & Network Security medium

    A network access control (NAC) solution primarily helps by:

  85. Communication & Network Security hard

    WPA2/WPA3 are preferred over WEP for wireless networks because WEP:

  86. Communication & Network Security medium

    Placing Internet of Things (IoT) devices on a separate, isolated VLAN is recommended chiefly to:

  87. Communication & Network Security medium

    The key difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS) is that an IPS:

  88. Communication & Network Security hard

    A SYN flood attack works by:

  89. Communication & Network Security medium

    Network Address Translation (NAT) contributes to security mainly by:

  90. Communication & Network Security medium

    Which protocol should replace Telnet for secure remote administration of network devices?

  91. Communication & Network Security hard

    The core idea of a zero trust network architecture is to:

  92. Communication & Network Security easy

    A captive portal on a guest Wi-Fi network is mainly used to:

  93. Communication & Network Security hard

    Why are out-of-band management networks used for critical infrastructure devices?

  94. Communication & Network Security hard

    ARP spoofing on a local network allows an attacker to:

  95. Identity & Access Management easy

    In access control terminology, the user or process requesting access to a resource is the:

  96. Identity & Access Management easy

    A fingerprint scan is an example of which authentication factor?

  97. Identity & Access Management hard

    Access control based on a user's department, time of day and device location, evaluated dynamically, best describes:

  98. Identity & Access Management easy

    In identity and access management, 'authorization' refers to:

  99. Identity & Access Management hard

    OAuth 2.0 is primarily a framework for:

  100. Identity & Access Management medium

    The main risk of accounts that retain access from previous roles after staff change jobs is called:

  101. Identity & Access Management hard

    A 'false acceptance' in a biometric system means the system:

  102. Identity & Access Management medium

    Single sign-on (SSO) improves usability but introduces the risk that:

  103. Identity & Access Management medium

    A time-based one-time password (TOTP) app provides which authentication factor?

  104. Identity & Access Management medium

    The purpose of an access recertification (periodic access review) is to:

  105. Identity & Access Management easy

    Provisioning, modifying, reviewing and deprovisioning user access over time is collectively known as:

  106. Identity & Access Management medium

    Why is privileged access management (PAM) given special attention compared with normal user access?

  107. Identity & Access Management hard

    Kerberos uses a trusted third party to issue tickets. The component that grants service tickets after initial authentication is the:

  108. Identity & Access Management medium

    Federated identity management primarily allows:

  109. Identity & Access Management medium

    The 'accounting' (or auditing) element of the AAA model refers to:

  110. Identity & Access Management hard

    Just-in-time (JIT) privileged access aims to reduce risk by:

  111. Security Assessment & Testing medium

    In a 'black box' penetration test, the tester is given:

  112. Security Assessment & Testing medium

    A 'false positive' in a vulnerability scan means the tool:

  113. Security Assessment & Testing medium

    Why is independence important when an organization undergoes a security audit?

  114. Security Assessment & Testing hard

    A SOC 2 Type II report is most useful to a customer because it:

  115. Security Assessment & Testing easy

    Reviewing whether terminated employees' accounts were actually disabled is an example of testing:

  116. Security Assessment & Testing hard

    Fuzz testing primarily evaluates software by:

  117. Security Assessment & Testing medium

    The main reason to define a clear scope and rules of engagement before a penetration test is to:

  118. Security Assessment & Testing hard

    Synthetic transaction monitoring tests a production system by:

  119. Security Assessment & Testing medium

    A code review where developers manually inspect each other's source code is best categorized as a:

  120. Security Assessment & Testing medium

    Why should an organization periodically test its backups by performing actual restores?

  121. Security Assessment & Testing medium

    Key risk indicators (KRIs) and key performance indicators (KPIs) in a security program are mainly used to:

  122. Security Assessment & Testing medium

    A 'gray box' penetration test is characterized by the tester having:

  123. Security Assessment & Testing medium

    When a vulnerability assessment produces a long list of findings, the security manager should first:

  124. Security Operations medium

    In digital forensics, maintaining a documented chain of custody is essential because it:

  125. Security Operations medium

    During incident response, the containment phase is intended to:

  126. Security Operations medium

    A business impact analysis (BIA) is performed mainly to:

  127. Security Operations medium

    The recovery point objective (RPO) specifies the:

  128. Security Operations medium

    A 'hot site' as a disaster recovery facility is best described as one that:

  129. Security Operations medium

    Formal change management exists primarily to:

  130. Security Operations medium

    A SIEM platform adds value over isolated log files mainly because it:

  131. Security Operations medium

    Why should organizations protect log files from modification by ordinary users and administrators?

  132. Security Operations hard

    The principle behind keeping golden images and configuration baselines is to:

  133. Security Operations hard

    When investigating an incident, why is it best practice to work from a forensic copy rather than the original media?

  134. Security Operations hard

    The maximum tolerable downtime (MTD) for a business function represents:

  135. Security Operations medium

    A primary reason to apply patches through a managed patch management process rather than ad hoc is to:

  136. Security Operations hard

    Egress filtering at the network boundary is used mainly to:

  137. Security Operations medium

    Why is a tabletop exercise valuable for incident response and business continuity readiness?

  138. Security Operations easy

    The first priority during any incident or disaster response should be:

  139. Software Development Security hard

    A SQL injection vulnerability is best prevented by:

  140. Software Development Security medium

    Cross-site scripting (XSS) primarily allows an attacker to:

  141. Software Development Security hard

    Storing user passwords using a slow, salted hashing algorithm (such as bcrypt) rather than a fast hash is recommended because it:

  142. Software Development Security medium

    The principle of 'secure defaults' in software design means that:

  143. Software Development Security medium

    Why is it risky for an application to display detailed internal error messages (such as stack traces) to end users?

  144. Software Development Security hard

    Performing threat modeling early in the development lifecycle helps teams to:

  145. Software Development Security hard

    A buffer overflow vulnerability occurs when a program:

  146. Software Development Security medium

    Integrating automated security scanning into a CI/CD pipeline (often called 'shift left') aims to:

  147. Software Development Security medium

    Why should developers avoid hardcoding credentials or API keys directly in source code?

  148. Software Development Security hard

    A software composition analysis (SCA) tool primarily helps secure software by:

  149. Software Development Security medium

    Validating input on the server side, even when client-side validation already exists, is necessary because:

  150. Software Development Security hard

    A race condition (time-of-check to time-of-use, TOCTOU) flaw arises when:

  151. Software Development Security medium

    Why is it important to manage and patch open-source libraries an application depends on?

  152. Security & Risk Management medium

    An organization documents who is accountable, responsible, consulted and informed for each security task using a RACI chart. This primarily improves:

  153. Security & Risk Management medium

    A company must comply with GDPR for its European customers. The maximum administrative fine under GDPR for the most serious violations is set as the higher of a fixed sum or a percentage of:

  154. Security & Risk Management hard

    Threat modeling using the STRIDE method helps categorize threats. The 'R' in STRIDE stands for:

  155. Security & Risk Management hard

    A security manager wants to compare the cost of a proposed control against the loss it is expected to prevent. The most appropriate figure to justify the control is the reduction in:

  156. Security & Risk Management medium

    When a third-party vendor will process the company's customer data, the strongest way to ensure the vendor maintains required security controls is to:

  157. Security & Risk Management easy

    The primary goal of a security governance program, as opposed to day-to-day security management, is to:

  158. Security & Risk Management medium

    An organization treats a newly discovered risk by both buying insurance and adding a detective control. Using two responses for one risk is best described as:

  159. Security & Risk Management medium

    Under the concept of 'standard of due care', an organization is expected to:

  160. Security & Risk Management easy

    A multinational must follow different privacy laws in each country it operates in. The discipline of ensuring the organization meets all applicable laws, regulations and contracts is called:

  161. Security & Risk Management medium

    An employee reports a colleague pressuring them to bypass a control 'just this once'. According to the manager mindset, the security manager should first:

  162. Security & Risk Management medium

    The main purpose of a job rotation policy as a security control is to:

  163. Security & Risk Management easy

    A risk register is best described as:

  164. Security & Risk Management medium

    An organization adopts ISO/IEC 27001. The central artefact this standard requires an organization to establish and maintain is a(n):

  165. Security & Risk Management medium

    A 'qualitative' risk technique that gathers anonymous expert opinions over several rounds to reach consensus is the:

  166. Security & Risk Management easy

    The principal reason to classify a security incident's severity early in incident handling is to:

  167. Security & Risk Management hard

    A company calculates that a server failure causes a single loss expectancy of $50,000 and occurs on average twice per year. A proposed control costing $30,000 per year would cut the failure rate in half. Is the control cost-justified?

  168. Security & Risk Management medium

    Why does CISSP guidance stress aligning the security program with the organization's mission and objectives?

  169. Security & Risk Management easy

    When a company shares a draft acquisition deal with an outside advisory firm, which agreement most directly limits how that firm may use and share the confidential information?

  170. Asset Security easy

    An asset inventory that records hardware, software and data the organization owns primarily supports security by:

  171. Asset Security hard

    A 'data steward' role in data governance is generally responsible for:

  172. Asset Security easy

    Encrypting an entire laptop hard drive so that all stored data is protected if the device is lost is an example of protecting data:

  173. Asset Security hard

    Combining many individually low-sensitivity records so that the combined dataset reveals sensitive information is the security concern known as:

  174. Asset Security medium

    The recommended action for highly classified media that has reached end of life and will leave the organization's control is to:

  175. Asset Security easy

    Marking a printed report 'Confidential' in its header and footer is an example of:

  176. Asset Security easy

    An organization shares a dataset with researchers but first removes names, addresses and IDs so individuals cannot be readily identified. This process is:

  177. Asset Security medium

    Why must a data owner consider the entire data lifecycle (creation, storage, use, sharing, archival, destruction) rather than just storage?

  178. Asset Security easy

    In data governance terms, a 'data processor' under typical privacy law is the party that:

  179. Asset Security hard

    A 'scoping' decision when applying a baseline of security controls to a system means the organization:

  180. Asset Security easy

    A government uses classification levels Top Secret, Secret, Confidential and Unclassified. Information whose unauthorized disclosure could cause 'exceptionally grave damage' is typically labelled:

  181. Security Architecture & Engineering easy

    A cipher that encrypts data one bit or byte at a time, often used where data arrives continuously, is a:

  182. Security Architecture & Engineering medium

    A 'collision' in a cryptographic hash function occurs when:

  183. Security Architecture & Engineering medium

    The isolation provided by sandboxing an application means the application:

  184. Security Architecture & Engineering hard

    Which statement correctly distinguishes the ECB block cipher mode from CBC?

  185. Security Architecture & Engineering hard

    A trusted computing base (TCB) refers to:

  186. Security Architecture & Engineering medium

    Why is hardcoding a single, never-changing encryption key into thousands of shipped devices a poor design?

  187. Security Architecture & Engineering medium

    The cryptographic property ensuring that even a tiny change in input produces a drastically different output is the:

  188. Security Architecture & Engineering hard

    An organization wants confidentiality, integrity and authenticity for messages in one operation. The class of algorithm designed for this is:

  189. Security Architecture & Engineering easy

    Placing critical servers in a locked cage within a data centre, in addition to building access control, is an example of:

  190. Security Architecture & Engineering easy

    The use of a hardware security module (HSM) in an enterprise is primarily to:

  191. Security Architecture & Engineering hard

    Why is reusing the same initialization vector (IV) with the same key in certain cipher modes dangerous?

  192. Security Architecture & Engineering hard

    A 'fail secure' electronic door lock during a power outage will:

  193. Security Architecture & Engineering easy

    Embedding security requirements into a system from the earliest design stage, rather than bolting them on later, reflects the principle of:

  194. Security Architecture & Engineering hard

    A side-channel attack against a cryptographic device works by:

  195. Security Architecture & Engineering medium

    Why does CISSP guidance recommend not creating your own custom encryption algorithm for production use?

  196. Security Architecture & Engineering hard

    A water sprinkler system that keeps pipes empty until a fire is detected, then fills and discharges, is a:

  197. Security Architecture & Engineering medium

    The main security advantage of using well-defined trust boundaries in a system architecture is that they:

  198. Security Architecture & Engineering easy

    Storing a copy of an encryption key with a trusted third party so data can be recovered if the original key is lost is called:

  199. Security Architecture & Engineering medium

    A common reason quantum computing concerns cryptographers is that sufficiently powerful quantum computers could:

  200. Communication & Network Security easy

    A subnet that hosts public-facing servers and sits between two firewalls, isolating them from the internal network, is commonly called a:

  201. Communication & Network Security easy

    At which OSI layer do MAC addresses and Ethernet switching primarily operate?

  202. Communication & Network Security medium

    A DNS amplification attack abuses open DNS resolvers to:

  203. Communication & Network Security hard

    The main purpose of 802.1X in a wired or wireless network is to:

  204. Communication & Network Security medium

    Why is using TLS 1.2 or 1.3 preferred over older SSL 3.0?

  205. Communication & Network Security easy

    A proxy server that sits between internal users and the internet, fetching content on their behalf, primarily provides:

  206. Communication & Network Security hard

    VLAN hopping is an attack in which an attacker:

  207. Communication & Network Security easy

    The security benefit of disabling unused physical switch ports is to:

  208. Communication & Network Security medium

    A 'smurf' attack achieves denial of service by:

  209. Communication & Network Security medium

    Segmenting a network so that payment-card systems are isolated from general office systems is most directly driven by the goal of:

  210. Communication & Network Security medium

    The primary reason to prefer SNMPv3 over SNMPv1/v2c for managing network devices is that SNMPv3:

  211. Communication & Network Security medium

    A 'honeypot' deployed on a network is intended to:

  212. Communication & Network Security easy

    Why is broadcasting an open (unencrypted) Wi-Fi network for sensitive business use a poor choice?

  213. Communication & Network Security medium

    A 'replay attack' on a network protocol succeeds when an attacker:

  214. Communication & Network Security hard

    The main security purpose of an email gateway that performs SPF, DKIM and DMARC checks is to:

  215. Communication & Network Security medium

    Why is placing a database server directly in the internet-facing DMZ generally discouraged?

  216. Communication & Network Security medium

    A 'directory traversal' attack against a web server attempts to:

  217. Identity & Access Management easy

    The first step in the identity and access management process, before authentication, is:

  218. Identity & Access Management medium

    The 'crossover error rate' (CER) of a biometric system is the point where:

  219. Identity & Access Management easy

    Role-based access control (RBAC) assigns permissions based on:

  220. Identity & Access Management easy

    An access control list (ACL) attached to a file specifies:

  221. Identity & Access Management hard

    OpenID Connect builds on OAuth 2.0 to add a standardized way to:

  222. Identity & Access Management medium

    Why are shared 'generic' accounts (for example one login used by a whole team) discouraged?

  223. Identity & Access Management hard

    A 'password spraying' attack differs from classic brute force because the attacker:

  224. Identity & Access Management medium

    Assigning a new employee access by adding them to predefined role groups rather than copying a colleague's permissions is preferred because it:

  225. Identity & Access Management medium

    An identity provider (IdP) in a federated SSO arrangement is the party that:

  226. Identity & Access Management hard

    Why is enforcing account lockout after several failed login attempts a useful control, but with a trade-off?

  227. Identity & Access Management medium

    A 'capability table' in access control is organized by:

  228. Identity & Access Management medium

    The main reason to require re-authentication before a user performs a highly sensitive action (such as changing payment details) is to:

  229. Identity & Access Management medium

    In the access control matrix model, the rows typically represent subjects and the columns represent:

  230. Identity & Access Management hard

    Why is single sign-off (centralized session termination) an important companion to single sign-on?

  231. Identity & Access Management easy

    Audit logging that records which administrator changed a user's permissions and when primarily supports the AAA element of:

  232. Security Assessment & Testing medium

    A 'walk-through' (structured review) test of a disaster recovery plan involves:

  233. Security Assessment & Testing medium

    The key difference between a vulnerability assessment and an audit is that an audit primarily:

  234. Security Assessment & Testing hard

    When interpreting CVSS scores for prioritization, a higher base score generally indicates:

  235. Security Assessment & Testing medium

    The main reason to use both automated scanning and manual testing in a security assessment is that:

  236. Security Assessment & Testing medium

    A 'parallel test' of a disaster recovery plan means the organization:

  237. Security Assessment & Testing easy

    Why is it important to retest a vulnerability after the fix is applied (validation)?

  238. Security Assessment & Testing easy

    Reviewing a representative subset of records rather than every record during an audit is called:

  239. Security Assessment & Testing medium

    A 'red team' engagement differs from a standard penetration test mainly because it:

  240. Security Assessment & Testing medium

    The purpose of including a 'remediation timeline' with severity ratings in an assessment report is to:

  241. Security Assessment & Testing medium

    Why should security testing in a production environment be carefully controlled and authorized?

  242. Security Assessment & Testing medium

    A 'full interruption' test of a business continuity plan is the most thorough but also the riskiest because it:

  243. Security Assessment & Testing medium

    Tracking metrics such as mean time to detect (MTTD) and mean time to respond (MTTR) helps a security program by:

  244. Security Assessment & Testing easy

    Why is comparing assessment results against a defined baseline useful over time?

  245. Security Assessment & Testing medium

    The main reason an auditor collects and retains evidence for findings is to:

  246. Security Operations medium

    The first action when a serious security incident is confirmed, after ensuring people are safe, is usually to:

  247. Security Operations medium

    The 'eradication' phase of incident response is where the team:

  248. Security Operations hard

    A 'warm site' as a recovery facility is best characterized as one that has:

  249. Security Operations medium

    Why does CISSP guidance place 'lessons learned' as a distinct final phase of incident response?

  250. Security Operations medium

    Correlating external threat intelligence feeds with internal logs primarily helps operations teams to:

  251. Security Operations medium

    Why are administrators advised to use separate accounts for routine work and for privileged administration?

  252. Security Operations medium

    The principle of 'least privilege for service accounts' means service accounts should:

  253. Security Operations hard

    A 'cold site' is the cheapest recovery option but has the longest recovery time because it:

  254. Security Operations medium

    Why should an organization define and rehearse a communication plan as part of incident response?

  255. Security Operations medium

    The operations practice of 'configuration management' primarily helps security by:

  256. Security Operations hard

    During the recovery phase of incident response, monitoring restored systems closely is important because:

  257. Security Operations easy

    Why is it best practice to store at least one backup copy offsite or in a separate region?

  258. Security Operations hard

    A 'jump server' (jump box) used to administer sensitive systems improves security by:

  259. Security Operations medium

    Why should an organization log and review privileged user activity more closely than ordinary user activity?

  260. Security Operations hard

    The purpose of an emergency 'break-glass' procedure for privileged access is to:

  261. Security Operations medium

    Why does the manager mindset favour containing an active breach before immediately rebuilding affected servers?

  262. Software Development Security easy

    The OWASP Top Ten is best described as:

  263. Software Development Security hard

    Insecure deserialization vulnerabilities arise when an application:

  264. Software Development Security hard

    The principle of 'complete mediation' in secure software design requires that:

  265. Software Development Security medium

    Why is it important to validate the authorization of a request server-side even after a user is authenticated?

  266. Software Development Security hard

    A cross-site request forgery (CSRF) attack tricks a logged-in user's browser into:

  267. Software Development Security medium

    Using a 'least privilege' database account for a web application means the application's database user should:

  268. Software Development Security medium

    Why is it risky to trust data from a hidden HTML form field or a client-side cookie for pricing or access decisions?

  269. Software Development Security medium

    Code signing of a software package primarily provides:

  270. Software Development Security medium

    Why is maintaining a software bill of materials (SBOM) increasingly recommended?

  271. Software Development Security medium

    Separating the development, testing and production environments primarily serves to:

  272. Software Development Security hard

    Why should an application enforce contextual output encoding when displaying user-supplied content in a web page?

  273. Software Development Security hard

    A web application that lets a user change a numeric account ID in the URL and view another user's data suffers from:

Practice questions FAQ

Are these real CISSP exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources