Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CISSP Practice Questions with Explanations

Updated 12 min read
Key takeaway

These original CISSP practice questions use short workplace scenarios to test risk judgment, security design, access control, assessment, operations, and software security.

  • Choose the best answer before opening each explanation.
  • The explanations show why the recommended action fits the stated goal and why plausible alternatives are premature, incomplete, or aimed at another problem.
On this page7 sections
  1. How to use these CISSP questions
  2. Practice set
  3. What the set tests
  4. Review the distractors, not only the answer
  5. Turn misses into a focused revision loop
  6. Limits of practice scores
  7. A compact routine for original questions

How to use these CISSP questions

Treat each item as a decision, not a vocabulary quiz. Read the facts, identify what the organization needs, and decide what should happen first or best. Then compare your reasoning with the explanation. The questions below are original study material written for this article. They are not ISC2 exam questions and do not predict an official score.

For useful practice, hide the answer and explanation until you have selected an option. State your reason in one sentence. If you are unsure, mark the item uncertain even when you guess correctly. The goal is to find reasoning gaps while there is time to correct them.

What to recordUseful noteWhy it helps
Chosen answerLetter and confidenceSeparates knowledge from a lucky guess.
Decision ruleOne sentence explaining the best choiceShows whether you understood the scenario's priority.
DistractorWhy the closest alternative failsReveals common sequencing and scope errors.
Review actionConcept or skill to revisitTurns a missed question into the next study step.

Practice set

Question 1: establish accountability

A company plans to move customer records into a cloud service. The security team has compared technical controls, but no business owner has classified the records or approved their retention period. What should the security manager do first?

  1. Select the cloud provider with the largest number of security certifications.
  2. Ask the data owner to classify the information and define its business and handling requirements.
  3. Encrypt every field with a key controlled only by the security team.
  4. Begin a penetration test against the provider's public interface.

Answer: B. The organization needs an accountable owner and a classification decision before it can choose proportionate safeguards or retention. Certifications, encryption, and testing can contribute to assurance, but none determines the business sensitivity or lawful handling requirements of these records. The security manager should facilitate the decision and advise on risk; the data owner remains responsible for the asset decision.

A is an assurance input, not a substitute for the company's own requirements. C proposes a control before the information and access model are understood. D tests a narrow technical surface and does not resolve ownership or retention. The word 'first' matters: establish the requirements that later design and assessment must satisfy.

Question 2: contain an active incident

An endpoint alert shows a workstation communicating with a known malicious host. The employee is still signed in, and the response team has not yet preserved volatile evidence. The organization has an approved incident plan. What is the best immediate response?

  1. Reimage the workstation immediately so the attacker loses access.
  2. Isolate the workstation from the network under the incident plan while preserving evidence and documenting actions.
  3. Wait for the employee's manager to confirm whether the traffic was authorized.
  4. Publish a notice to customers before determining whether their data was affected.

Answer: B. The active connection creates a containment need. Isolation limits further communication while the response team preserves evidence and follows its authorized process. The facts say the incident plan is approved, so responders can act within it. They should record what they do and coordinate investigation and recovery.

A may destroy evidence and skips the investigation. C delays containment despite a credible alert. D communicates before the impact is understood and the response team has established what happened. In a different scenario, immediate isolation could disrupt a safety-critical service, so business impact and established response authority matter. Here, the prompt gives no such exception.

Question 3: choose an access control

A finance employee transfers to a role that no longer requires access to payroll administration. The identity system shows the old privilege is still active. What is the best action?

  1. Keep the privilege until the next annual access review to avoid disrupting work.
  2. Remove or adjust the access through the approved change process, then verify the role's remaining permissions.
  3. Share the account with the employee's replacement so both can finish the transition.
  4. Disable multifactor authentication because the employee is changing roles.

Answer: B. Access should track current job duties. The organization should promptly change the authorization, preserve an accountable record, and verify that the user retains only the access needed for the new role. An annual review is useful detective control, but it should not leave known excess privilege in place.

A leaves a known access problem active. C destroys individual accountability and creates shared credentials. D weakens authentication without addressing authorization. The useful distinction is that authentication establishes who is using an account; authorization determines what that identity may do.

Question 4: interpret an assessment finding

An internal vulnerability scan reports an old server as critical because a version string is outdated. The system owner says the vulnerable service is disabled, and network rules block access to the server. What should the assessor do next?

  1. Close the finding because the owner has explained the controls.
  2. Validate the service state and relevant network exposure, then assess residual risk against the organization's criteria.
  3. Demand an immediate rebuild because every critical scan result proves exploitation.
  4. Remove the server from the asset inventory so it no longer appears in future scans.

Answer: B. A scan result is evidence that needs context and validation. The assessor should test whether the service is actually disabled and whether the network restrictions work, then document the remaining risk using defined criteria. A control may reduce likelihood or exposure without eliminating the underlying vulnerability.

A accepts an assertion without sufficient evidence. C confuses a scanner label with proof that exploitation is occurring and prescribes a response before validation. D corrupts the inventory and hides risk. Assessment quality depends on reliable evidence, defined scope, and clear reporting of limitations.

Question 5: protect a cryptographic key

A service encrypts database backups, but the backup files and the decryption key are stored in the same administrator-accessible location. Which change most directly reduces the chance that one compromise exposes both?

  1. Store the key separately in an access-controlled key management system and restrict key use to the backup process.
  2. Increase the backup frequency while leaving the key and files together.
  3. Rename the key file and remove its extension.
  4. Allow all database administrators to retrieve the key for troubleshooting.

Answer: A. Separation of duties and protected key management reduce the chance that access to the encrypted data also grants access to the means of decryption. The service should have only the permissions necessary to perform its assigned function, with key use monitored and recoverable through an approved process.

B improves recovery point options but does not address the shared compromise. C is obscurity, not a security boundary. D broadens exposure. Key protection also requires lifecycle decisions such as generation, rotation, revocation, backup, and recovery; the best design depends on the system's availability and recovery requirements.

Question 6: select a development control

A development team discovers that a new application accepts user input directly in a database query. The release is still in testing. Which response best addresses the defect and improves future releases?

  1. Use parameterized queries, test the correction, and add the issue to secure development guidance and review checks.
  2. Rely on the web application firewall to block suspicious strings after release.
  3. Disable all database logging so sensitive values cannot appear in logs.
  4. Delay remediation until the next annual penetration test confirms the issue.

Answer: A. Parameterized queries address the unsafe query construction at its source. Testing verifies that the fix works and has not broken intended behavior. Updating guidance and review checks can prevent similar defects in later code. The development team should also evaluate whether test data or logs expose sensitive information.

B can be a defense in depth control, but it should not replace a code correction when the defect is known. C may remove useful audit evidence and does not fix the query. D knowingly leaves a preventable flaw in the release path. Security practices are strongest when they are integrated into the lifecycle rather than postponed to a periodic test.

Question 7: respond to a recovery constraint

A business impact analysis identifies a customer service as critical. During an exercise, the technical team restores data successfully, but the service cannot authenticate users because its identity dependency was omitted from the recovery design. What should the recovery owner do?

  1. Record the exercise as successful because the database was restored.
  2. Update the dependency map and recovery plan, then test restoration of the service and its identity dependencies together.
  3. Buy additional storage for database backups.
  4. Replace the business impact analysis with a list of servers.

Answer: B. Recovery is measured against the business service, not one component in isolation. The failed identity dependency shows that the plan missed a relationship needed to deliver the service. Update the plan and exercise the end-to-end dependency chain, including people and procedures where relevant.

A mistakes component restoration for business recovery. C addresses storage capacity without the demonstrated failure. D removes the business view that established criticality and needed recovery outcomes. A good recovery exercise exposes assumptions before a real outage forces the organization to discover them.

Question 8: handle a policy exception

A project owner asks to bypass a required security review because a customer demo is tomorrow. The review process allows exceptions when an authorized risk owner accepts the residual risk. What should the security professional do?

  1. Approve the exception verbally because the deadline is close.
  2. Document the specific risk and compensating controls, route the request to the authorized risk owner, and record the decision and expiration.
  3. Block the project indefinitely without explaining the security concern.
  4. Ask the project team to mark the review complete so the system accepts the release.

Answer: B. The stated policy provides a controlled exception path. The security professional should explain the risk, identify any compensating controls, and ensure the authorized owner accepts the residual risk. The decision should be recorded and time-bounded so the temporary exception does not become permanent by neglect.

A bypasses authority and leaves no defensible record. C ignores the approved process and does not help the owner make an informed decision. D falsifies compliance evidence. The security role is to advise and protect the process; the named risk owner accepts business risk within the organization's authority structure.

What the set tests

QuestionPrimary ideaReasoning habit
1Governance and ownershipSet requirements before selecting safeguards.
2Incident responseContain under authority while preserving evidence.
3Identity and accessAlign authorization with current duties.
4AssessmentValidate evidence and assess residual risk.
5CryptographySeparate protected data from key access.
6Software securityCorrect the defect and improve the lifecycle.
7Business continuityRestore the service and its dependencies.
8Risk governanceUse an approved, documented exception path.

Review the distractors, not only the answer

A strong explanation does more than repeat the right choice. Ask what fact makes it best, which distractor is closest, and what changed condition would make that distractor reasonable. In Question 2, isolating the endpoint fits the stated active threat and approved plan. If disconnecting it would endanger a critical industrial process, responders would need to weigh that safety constraint and use the incident plan's alternative containment measures.

This counterfactual habit keeps rules from turning into rigid slogans. 'Always isolate first' is not a reliable universal rule. The defensible action depends on the threat, business impact, role, and policy. On the exam, use the facts provided. Do not invent a special constraint to rescue a weaker option, but do notice an explicit one.

Also distinguish actions that operate at different levels. A firewall rule can reduce exposure, but it does not establish data ownership. A scan can identify a possible weakness, but it does not prove impact. Encryption can protect confidentiality, but it does not determine who should have authorization. The answer often comes from matching the action to the actual gap.

Turn misses into a focused revision loop

After the set, sort each miss into one cause: missing knowledge, incorrect sequence, misread constraint, unsupported assumption, or weak explanation. Then choose a specific follow-up. Read about data-owner accountability for Question 1; practice first-response ordering for Question 2; draw an identity lifecycle for Question 3. Reattempting a memorized question immediately can show recognition rather than learning, so revisit the concept later with a different scenario.

If you answer correctly but cannot explain why the distractors fail, keep the question in your review list. Confidence should come from a reason, not from familiarity with a phrase. Good notes are short: 'A known access mismatch should be corrected through the role-change process; annual review is too late.' That sentence will help more than copying the full explanation.

For a timed session, answer each item once and move forward. The CISSP computer-adaptive exam does not let you return to a submitted item. Practice making a careful choice based on the stated evidence, without spending several minutes trying to disprove every alternative. A realistic practice routine should include quiet, sustained work and a review period after the set.

Limits of practice scores

These items are instructional examples, not a calibrated exam. They do not reproduce ISC2's item selection or scoring model. The official CISSP result is reported as pass or fail, and ISC2 does not publish a raw percentage that guarantees a pass. A percentage on a small practice set only describes performance on that set.

Use practice results to find weak concepts and reasoning habits. Track performance across mixed sets from more than one session, but do not turn an unofficial percentage into a promised outcome. If one set is unusually easy or difficult, review the explanations and compare the skills tested before changing your exam date.

A compact routine for original questions

  1. Answer a small mixed set without notes.
  2. For each response, write the fact in the stem that supports your choice.
  3. Explain why the strongest distractor is not best under the stated conditions.
  4. Mark guesses and correct answers with weak explanations as uncertain.
  5. Schedule a delayed review of the concepts behind uncertain responses.
  6. Use the error pattern to choose the next study topic, then test transfer with a new scenario.

The point is not to collect familiar answers. It is to become more reliable at reading the situation, selecting the appropriate security action, and explaining the decision in context. That habit transfers better to an adaptive exam than memorizing answer letters.

Common questions

Are these official ISC2 CISSP questions?

No. They are original practice scenarios written for this article. They are not copied from ISC2 materials, do not reveal protected exam content, and are not calibrated to predict a candidate's official result.

How many CISSP questions should I practice at a time?

Choose a set small enough to review carefully. A useful session includes time to explain correct answers, diagnose misses, and record uncertain guesses. Completing more questions without reviewing the reasoning can repeat the same error.

What should I do when two CISSP answers both seem right?

Return to the stated objective and constraints. Compare which option addresses the immediate gap at the correct level and sequence. Reject choices that assume facts the scenario does not provide or bypass the organization's authority and process.

Can a practice score tell me whether I will pass?

No. These questions are not an official or calibrated exam, and ISC2 does not publish a raw-percentage cutoff. Use your results to guide study, not as a guaranteed prediction.