CertKeen
ISC2Beta · expanding bank

CISSP Practice Exam

Practice questions for the ISC2 CISSP exam (outline effective April 15, 2024), written from a security manager's and architect's perspective across all eight domains: the ISC2 Code of Ethics, nonrepudiation, governance and due diligence, GDPR transfers, intellectual property, investigation standards, policy documents, business continuity and BIA metrics, personnel security, risk analysis and acceptance, STRIDE threat modeling, SBOMs and security champions; data ownership, classification, minimization, retention and legal holds, crypto-shredding, end-of-support assets, data in use, scoping and DRM; Bell-LaPadula, Biba and Clark-Wilson, secure defaults, Common Criteria, TPM, container isolation, post-quantum migration, key management, PKI design, side-channel attacks and facility fire and HVAC controls; TLS 1.3, IPsec, converged protocols, micro-segmentation, out-of-band management, 802.1X, CDN, SDN, NAC, transmission media, third-party remote access and VoIP; Kerberos, OpenID Connect, federation and provisioning, access control models, access reviews, privileged and service accounts, identity proofing, NIST password guidance and phishing-resistant MFA; SOC reports, penetration testing, purple teams, synthetic transactions, coverage analysis, log time sync, KRIs, backup verification, disclosure, exceptions and audit independence; fraud-detection controls, forensic integrity, law enforcement involvement, UEBA, emergency change, need-to-know, incident containment, honeypots, vulnerability prioritization, recovery sites, DR testing, life safety and travel security; and SAST, SCA, IAST, maturity models, Agile security, secrets handling, source code escrow, input validation, API authorization and deployment controls. Every question includes a written explanation.

100 questions · 12 free preview

$19 · lifetime access
Try free sample

Studying more than one? every exam for $79

Free sample questions

  1. Sample · question 1 · Senior management ultimate security accountability

    A breach at Kilbride Outfitters exposed thousands of customer records. The board wants to confirm where ultimate accountability for protecting the organization's information assets lies. Who carries this accountability?

    • A.Each employee whose account was used in the breach
    • B.The help desk staff who reset user passwords
    • C.Senior management, led by the chief executive and the boardcorrect
    • D.The network team that operates the firewalls

    Why: Senior management holds ultimate responsibility for protecting the organization's assets; it may delegate security tasks to the CISO and technical teams, but it cannot delegate the accountability. Network teams, help desk staff and individual users perform specific duties within the security program, yet none of them own the overall responsibility to the board, regulators and shareholders.

    Open this question on its own page →
  2. Sample · question 2 · Wassenaar Arrangement export of cryptography

    Tarnwell Devices plans to ship hardware encryption appliances to a newly opened subsidiary abroad. The compliance lead reminds the security manager that many countries control exports of such dual-use items under a multilateral regime. Which regime is she referring to?

    • A.The Wassenaar Arrangementcorrect
    • B.The Budapest Convention
    • C.The Digital Millennium Copyright Act
    • D.The Payment Card Industry Data Security Standard

    Why: The Wassenaar Arrangement is a multilateral export control regime for conventional arms and dual-use goods and technologies, and many participating states base their export rules for cryptographic products on its lists. The Budapest Convention deals with cooperation on cybercrime, the DMCA is a US copyright law, and PCI DSS is an industry standard for protecting payment card data.

    Open this question on its own page →
  3. Sample · question 3 · Brewer-Nash model prevents conflicts of interest

    Ellery Advisory, a consulting firm, serves several competing airlines. Once a consultant has accessed one airline's confidential data, the system must stop that consultant from accessing data belonging to any rival airline. Which security model fits this requirement?

    • A.Brewer-Nashcorrect
    • B.Clark-Wilson
    • C.Biba
    • D.Bell-LaPadula

    Why: The Brewer-Nash, or Chinese Wall, model changes a subject's permissions dynamically based on what it has already accessed, so after a consultant works with one company's data, the data of companies in the same conflict-of-interest class becomes off-limits. Biba and Clark-Wilson focus on integrity, and Bell-LaPadula enforces fixed confidentiality levels rather than history-based conflict rules.

    Open this question on its own page →
  4. Sample · question 4 · Known-plaintext cryptanalytic attack

    An attacker has captured several encrypted invoices from Dalby Wholesale. Every invoice begins with the same publicly known company letterhead text, and the attacker uses those matching plaintext and ciphertext pairs to try to recover the key. What kind of attack is this?

    • A.A ciphertext-only attack
    • B.A birthday attack
    • C.A chosen-ciphertext attack
    • D.A known-plaintext attackcorrect

    Why: In a known-plaintext attack, the analyst has samples of both plaintext and the corresponding ciphertext, here the predictable letterhead, and uses them to deduce the key or algorithm behavior. A ciphertext-only attack has no plaintext at all, a chosen-ciphertext attack requires the ability to have chosen ciphertexts decrypted, and a birthday attack looks for hash collisions.

    Open this question on its own page →
  5. Sample · question 5 · Air-gapped network physical segmentation

    Holloway Water operates a safety system that must have no electronic path at all to the corporate network or the internet. Software updates are carried in on verified removable media. Which form of segmentation does this design use?

    • A.An air gapcorrect
    • B.A site-to-site VPN
    • C.A VLAN
    • D.A screened subnet

    Why: An air-gapped network is physically separated, with no wired or wireless connection to other networks, so data crosses only through controlled media transfers. VLANs and VPNs are logical segmentation on shared infrastructure, and a screened subnet is a perimeter zone that is still connected to both internal and external networks.

    Open this question on its own page →
  6. Sample · question 6 · Role-based access control by job function

    Ashbury Hospital has thousands of staff whose system permissions depend on their job, such as nurse, pharmacist or billing clerk, and people change jobs often. The identity manager wants permissions assigned to job functions instead of to individuals. Which model should be implemented?

    • A.Discretionary access control
    • B.Mandatory access control
    • C.Identity-based access control lists on each file
    • D.Role-based access controlcorrect

    Why: Role-based access control assigns permissions to roles that represent job functions and then assigns users to roles, so a job change means moving the person to a different role rather than editing many individual permissions. Discretionary access control leaves decisions to data owners, mandatory access control relies on labels and clearances, and per-file identity ACLs are exactly the individual-level management the hospital wants to avoid.

    Open this question on its own page →
  7. Sample · question 7 · Misuse case testing of abuse scenarios

    Before launching a gift card feature, Beacon Coffee's test team writes scenarios describing how a dishonest user might try to redeem one card twice or create value from nothing, and then tests the application against them. What type of testing is this?

    • A.Usability testing
    • B.Misuse case testingcorrect
    • C.Regression testing
    • D.Smoke testing

    Why: Misuse case, or abuse case, testing models how an attacker or dishonest user might deliberately abuse functionality and then verifies that the application resists those actions. Regression testing checks that changes have not broken existing features, smoke testing is a quick check that a build basically works, and usability testing evaluates how easy the feature is for legitimate users.

    Open this question on its own page →
  8. Sample · question 8 · Breach and attack simulation platforms

    Carrick Insurance wants to check continuously, rather than once a year, that its email filtering, endpoint and network controls still block common attack techniques after every configuration change. Which solution BEST meets this need?

    • A.A quarterly questionnaire completed by each control owner
    • B.A breach and attack simulation platform running automated attack scenarioscorrect
    • C.An annual third-party audit of the information security policies
    • D.A larger SIEM license so that more log sources can be collected

    Why: Breach and attack simulation tools run automated, safe simulations of real attack techniques on a schedule and report which controls blocked or detected them, providing continuous validation as the environment changes. Policy audits and self-assessment questionnaires check documentation and opinions rather than real control behavior, and collecting more logs does not by itself test whether controls work.

    Open this question on its own page →
  9. Sample · question 9 · Proactive hypothesis-driven threat hunting

    After reading a threat intelligence report about a group that targets logistics firms, analysts at Morland Freight form a hypothesis about how the group would operate and search their own logs and endpoints for those traces, even though no alert has fired. What activity are they performing?

    • A.Penetration testing
    • B.Threat huntingcorrect
    • C.Vulnerability scanning
    • D.Incident triage

    Why: Threat hunting is a proactive, often hypothesis-driven search for signs of adversaries that existing controls may have missed, frequently guided by threat intelligence. Vulnerability scanning looks for weaknesses rather than intruders, incident triage begins only after an alert or report, and penetration testing simulates an attack instead of searching for real attacker activity.

    Open this question on its own page →
  10. Sample · question 10 · Lessons learned after incident closure

    Glenmore Pharmaceuticals has just closed a significant phishing incident: affected accounts were reset and systems restored. What is the main purpose of the meeting the incident manager is now scheduling with everyone involved?

    • A.To decide whether the original containment actions should be reversed
    • B.To identify and discipline the employees who clicked the phishing link
    • C.To start collecting volatile evidence from the affected endpoints
    • D.To review the incident and the response, and agree on improvementscorrect

    Why: The lessons learned review takes place after recovery and examines what happened, what worked, what did not and what should change, feeding improvements back into controls, detection and the response plan. Its purpose is improvement rather than blame, containment decisions belong to earlier phases, and volatile evidence must be collected at the start of an incident, long before closure.

    Open this question on its own page →
  11. Sample · question 11 · Access control vestibule stops tailgating

    Guards at Stanwick Data Center have seen visitors follow badge-holding employees through the main entrance without badging in themselves. Which physical control BEST prevents this?

    • A.Security cameras that record the entrance around the clock
    • B.Brighter lighting around the car park and entrance
    • C.An access control vestibule that admits one authenticated person at a timecorrect
    • D.A sign at the entrance reminding staff not to hold the door

    Why: An access control vestibule uses two interlocked doors and admits one authenticated person at a time, physically preventing tailgating and piggybacking. Lighting and cameras deter and record incidents but do not stop someone from following an employee through, and a reminder sign depends entirely on staff behavior.

    Open this question on its own page →
  12. Sample · question 12 · Cold site characteristics and recovery time

    Ravensworth Council is comparing recovery site options. One proposal offers a facility with power, cooling and floor space but no installed servers or data, at the lowest monthly cost. What is the main trade-off of this option?

    • A.It is a mirrored site, so data would be replicated continuously in real time
    • B.It is a hot site, so it is the most expensive choice even though it is the quickest one to bring online
    • C.It is a cold site, so recovery is slow because equipment and data must be brought incorrect
    • D.It is a mobile site, so it would be delivered on trailers to the council's location

    Why: A cold site provides only the basic environment, so hardware must be installed, systems built and data restored before operations resume, which gives a long recovery time in exchange for low cost. Hot and mirrored sites already have equipment and current data and cost far more, and a mobile site is a self-contained unit transported to the location when needed.

    Open this question on its own page →

Like the sample?

Other practice exams