Practice questions

CISSP (ISC2): Practice Questions

By The Exam Atlas Editorial Team · Verified 2026-05-31

A dozen original concept-check questions on core CISSP ideas. Choose an answer to reveal the explanation. Aim to reason like a risk-focused manager.

  1. Giving a user only the access strictly required to do their job is the principle of:

  2. Ensuring data has not been altered in an unauthorised way protects which part of the CIA triad?

  3. The Bell-LaPadula model is primarily designed to protect:

  4. Buying insurance to handle the financial impact of a risk is an example of risk:

  5. 'Defense in depth' means:

  6. Risk is most commonly assessed as a function of:

  7. Multi-factor authentication (MFA) requires:

  8. Which statement describes hashing rather than encryption?

  9. An access control model where the system enforces access using security labels and clearances is:

  10. The Recovery Time Objective (RTO) defines:

  11. The main purpose of separation of duties is to:

  12. 'Residual risk' is best described as:

Sources