CISSP Sample Questions

CISSP Sample Questions & Answers

Risk management and governance lead eight domains that also span asset protection, secure design, network and communication security, identity and access, assessment and testing, day-to-day operations, and building security into software development.

Launch the full CISSP simulator →

Free CISSP Sample Questions with Answers

Real questions from the Certified Information Systems Security Professional practice test — answers and explanations included. Showing 10 of 21 free samples.

  1. Question 1

    When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?

    Show answer & explanation

    Correct answer: B

    This is the CORRECT answer. According to ISO 27001 and 27002, management responsibilities can only be defined when standards are established. The standards provide the framework and requirements that determine what management responsibilities are needed for information security governance. Without standards defining the security requirements and controls, it is impossible to assign appropriate management responsibilities.

  2. Question 2

    Which of the following types of technologies would be the MOST cost-effective method to provide a reactive control for protecting personnel in public areas?

    Show answer & explanation

    Correct answer: D

    This is the CORRECT answer. Hiring a guard to protect the public area is the most cost-effective reactive control for protecting personnel in public areas. A reactive control responds to incidents as they occur, and a security guard can immediately respond to threats, incidents, or emergencies involving personnel or visitors. This human control provides flexibility, judgment, and real-time response capabilities that automated systems cannot match. The other options are either preventive controls (mantraps, enclosures) or require more expensive infrastructure investments compared to hiring security personnel. Guards can also serve multiple functions including access control, emergency response, and incident reporting, making them highly cost-effective for public area protection.

  3. Question 3

    An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?

    Show answer & explanation

    Correct answer: C

    This is the CORRECT answer. Defense in depth requires a balanced focus on People, Technology, and Operations as the three PRIMARY elements. This concept, fundamental to CISSP Security Architecture domain, recognizes that effective security cannot be achieved through technology alone. People include security awareness, training, and proper procedures. Technology encompasses the security tools and controls. Operations involve the processes, procedures, and management practices that tie everything together. The other options represent phases or activities within security programs but are not the foundational elements of defense in depth strategy. Reference: https://www.giac.org/paper/gsec/3873/information-warfare-cyber-warfare-future-warfare/106165

  4. Question 4

    Intellectual property rights are PRIMARY concerned with which of the following?

    Show answer & explanation

    Correct answer: D

    This is the CORRECT answer. Intellectual property rights are primarily concerned with the right of the owner to control the delivery method of their creation. This relates to the CISSP Legal and Compliance domain, covering how intellectual property can be distributed, accessed, and used. Control over delivery method encompasses licensing terms, distribution channels, access restrictions, and usage limitations. While financial gain and copyright maintenance are important considerations, the fundamental right is about controlling how the intellectual property reaches and is used by others. This control ensures the owner can enforce licensing agreements, prevent unauthorized distribution, and maintain the integrity of their intellectual creation.

  5. Question 5

    A control to protect from a Denial-of-Service (DoS) attach has been determined to stop 50% of attacks, and additionally reduces the impact of an attack by 50%.

    What is the residual risk?

    Show answer & explanation

    Correct answer: A

    This is the CORRECT answer. The residual risk is 25%. This question tests quantitative risk analysis from the CISSP Security Assessment domain. To calculate residual risk: First, the control stops 50% of attacks, so 50% still occur. Of those attacks that do occur (50%), the impact is reduced by 50%, meaning only 50% of the original impact remains. Therefore: 50% (attacks that occur) × 50% (remaining impact) = 25% residual risk. This calculation demonstrates how layered controls work together - prevention controls reduce likelihood while impact reduction controls minimize damage when prevention fails. Understanding residual risk calculations is essential for risk management and justifying security investments.

  6. Question 6

    In the Open System Interconnection (OSI) model, which layer is responsible for the transmission of binary data over a communications network?

    Show answer & explanation

    Correct answer: A

    This is the CORRECT answer. In the OSI model, the Physical Layer (Layer 1) is responsible for the transmission of binary data over a communications network. This relates to the CISSP Communication and Network Security domain. The Physical Layer handles the actual electrical, optical, or radio signals that represent binary 1s and 0s, including voltage levels, cable specifications, connector types, and transmission media characteristics. The Data-Link Layer (Layer 2) handles frame formatting and error detection, the Network Layer (Layer 3) manages routing and logical addressing, and the Application Layer (Layer 7) provides network services to applications. Understanding the OSI model layers is fundamental for network security architecture and troubleshooting communication security issues.

  7. Question 7

    What is the term commonly used to refer to a technique of authentication one machine to another by forging packets from a trusted source?

    Show answer & explanation

    Correct answer: D

    This is the CORRECT answer. Spoofing refers to the technique of authenticating one machine to another by forging packets from a trusted source. This falls under the CISSP Communication and Network Security domain. IP spoofing involves modifying packet headers to make them appear to originate from a trusted or legitimate source when they actually come from an attacker. This technique is used in various attacks including denial of service, session hijacking, and bypassing access controls. Smurfing is a specific type of DDoS attack, Man-in-the-Middle involves intercepting communications, and session redirect involves manipulating session tokens. Understanding spoofing techniques is essential for implementing proper network authentication and anti-spoofing controls.

  8. Question 8

    Which of the following entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership responsibilities?

    Show answer & explanation

    Correct answer: B

    This is the CORRECT answer. Risk management entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership. This is a core concept from the CISSP Security and Risk Management domain. Effective risk management requires comprehensive data classification, asset inventory, and clear ownership assignment to establish accountability and responsibility. This process involves mapping data flows, understanding business dependencies, and ensuring proper stewardship of information assets. Security governance provides the framework, risk assessment evaluates threats, and security portfolio management coordinates investments, but risk management specifically encompasses the identification and ownership assignment activities described in the question.

  9. Question 9

    Which of the following mandates the amount and complexity of security controls applied to a security risk?

    Show answer & explanation

    Correct answer: C

    This is the CORRECT answer. Risk mitigation mandates the amount and complexity of security controls applied to a security risk. This concept is fundamental to the CISSP Security and Risk Management domain. Risk mitigation strategies determine whether to accept, avoid, transfer, or reduce risks, which directly influences the selection and implementation of security controls. The level of risk mitigation chosen dictates the investment in preventive, detective, and corrective controls. Risk tolerance defines organizational appetite for risk, security vulnerabilities are weaknesses to be addressed, and security staff implement controls, but risk mitigation is the strategic decision that determines the scope and intensity of security control implementation.

  10. Question 10

    When determining who can accept the risk associated with a vulnerability, which of the following is MOST important?

    Show answer & explanation

    Correct answer: C

    This is the CORRECT answer. When determining who can accept risk associated with a vulnerability, incident likelihood is the MOST important factor. This relates to the CISSP Security and Risk Management domain. Risk acceptance authority must be assigned based on the probability that the vulnerability will be exploited and cause an incident. Higher likelihood scenarios require higher levels of management approval and authority. While type of potential loss and countermeasure effectiveness are important considerations, and information ownership determines who has stewardship, the probability of occurrence is the primary factor that determines the appropriate level of authority needed to accept the risk. Low-likelihood risks can often be accepted at lower organizational levels, while high-likelihood risks require senior management or board-level approval.

Ready for the real thing?

The full CISSP simulator has every exam-style question, timed mode, and instant scoring.

Go to the CISSP simulator →