Skip to content

CISSP Practice Questions

Prepare for CISSP with more than an answer.

627 questions in the full set21 sample questionsUpdated Jan 26, 2026
Exam fee
$749 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 8
  1. Security and Risk Management16%
  2. Asset Security10%
  3. Security Architecture and Engineering13%
  4. Communication and Network Security13%
  5. Identity and Access Management (IAM)13%
  6. Security Assessment and Testing12%
  7. Security Operations13%
  8. Software Development Security10%
  1. 1

    When determining who can accept the risk associated with a vulnerability, which of the following is MOST important?

    Show answer details

    Correct answer: C

    This is the CORRECT answer. When determining who can accept risk associated with a vulnerability, incident likelihood is the MOST important factor. This relates to the CISSP Security and Risk Management domain. Risk acceptance authority must be assigned based on the probability that the vulnerability will be exploited and cause an incident. Higher likelihood scenarios require higher levels of management approval and authority. While type of potential loss and countermeasure effectiveness are important considerations, and information ownership determines who has stewardship, the probability of occurrence is the primary factor that determines the appropriate level of authority needed to accept the risk. Low-likelihood risks can often be accepted at lower organizational levels, while high-likelihood risks require senior management or board-level approval.

  2. 2

    A security professional determines that a number of outsourcing contracts inherited from a previous merger do not adhere to the current security requirements.

    Which of the following BEST minimizes the risk of this happening again?

    Show answer details

    Correct answer: D

    This is the CORRECT answer. When outsourcing contracts inherited from a merger do not adhere to current security requirements, assigning a compliance officer to review the merger conditions is the most appropriate response. This falls under the CISSP Security and Risk Management domain, specifically addressing third-party risk management and regulatory compliance. A compliance officer can systematically review existing contracts, identify gaps against current requirements, negotiate amendments or renewals, and establish remediation timelines. The other options are either reactive (defining controls after issues are identified) or preventive for future mergers but do not address the current situation of inherited non-compliant contracts. The compliance officer ensures legal and regulatory requirements are met while balancing business continuity needs.

  3. 3

    Which of the following is a direct monetary cost of a security incident?

    Show answer details

    Correct answer: C

    This is the CORRECT answer. Equipment represents a direct monetary cost of a security incident. This relates to the CISSP Security and Risk Management domain, specifically incident response and business impact analysis. Direct costs are immediate, quantifiable expenses directly attributable to the incident, such as replacing damaged or compromised hardware, purchasing new security tools, or buying additional equipment to restore operations. These costs can be easily measured and directly linked to the incident. Indirect costs like lost productivity, reputation damage, customer churn, or regulatory fines are harder to quantify immediately but may be larger in total impact. Understanding direct vs. indirect costs is essential for incident response planning and business case development for security investments.

  4. 4

    Which of the following would MINIMIZE the ability of an attacker to exploit a buffer overflow?

    Show answer details

    Correct answer: B

    This is the CORRECT answer. Code review would MINIMIZE the ability of an attacker to exploit a buffer overflow vulnerability. This falls under the CISSP Software Development Security domain. Static code review can identify buffer overflow vulnerabilities before deployment by examining memory allocation, boundary checking, and input validation routines. Code review catches common programming errors like unchecked string functions, improper array bounds checking, and unsafe memory operations that lead to buffer overflows. While input validation and access controls provide runtime protection, and penetration testing identifies existing vulnerabilities, code review prevents the vulnerabilities from reaching production in the first place. Secure coding practices combined with thorough code review are the most effective preventive controls against buffer overflow attacks.

  5. 5

    Which of the following mechanisms will BEST prevent a Cross-Site Request Forgery (CSRF) attack?

    Show answer details

    Correct answer: C

    This is the CORRECT answer. Synchronized session tokens will BEST prevent Cross-Site Request Forgery (CSRF) attacks. This is part of the CISSP Software Development Security domain. CSRF attacks trick users into performing unwanted actions on web applications where they are authenticated. Synchronized session tokens (also called CSRF tokens) are unique, unpredictable values tied to the user session that must be included with state-changing requests. The server validates these tokens to ensure requests originate from legitimate application pages, not malicious third-party sites. This token synchronization pattern effectively prevents CSRF because attackers cannot predict or access the valid tokens needed for their forged requests. Other controls like input validation and session management help with different attack vectors but synchronized tokens specifically address the CSRF vulnerability.

  6. 6

    An organization has doubled in size due to a rapid market share increase. The size of the Information Technology (IT) staff has maintained pace with this growth. The organization hires several contractors whose onsite time is limited. The IT department has pushed its limits building servers and rolling out workstations and has a backlog of account management requests.

    Which contract is BEST in offloading the task from the IT staff?

    Show answer details

    Correct answer: B

    This is the CORRECT answer. Identity as a Service (IDaaS) is the best solution for an organization that has doubled in size due to rapid market share increase. This relates to the CISSP Identity and Access Management domain. IDaaS provides cloud-based identity management that can scale quickly to accommodate rapid user growth without requiring significant infrastructure investment or lengthy deployment cycles. IDaaS solutions offer rapid user provisioning, automated onboarding/offboarding, single sign-on capabilities, and can integrate with multiple applications quickly. For organizations experiencing rapid growth, IDaaS eliminates the need to build internal identity infrastructure, provides immediate scalability, reduces administrative overhead, and can be implemented much faster than traditional on-premises identity management systems. This allows the organization to focus on business growth while maintaining security and compliance.

  7. 7

    A security architect is designing a network for a new data center. The design must prevent a single point of failure for internet connectivity and routing. The following diagram shows a proposed high-availability router setup. Which protocol is MOST likely being used to manage the failover between Router A and Router B?

    graph TD subgraph Data Center VR[Virtual Router IP: 192.168.1.1] R1[Router A - Active] R2[Router B - Standby] SW[Core Switch] end Internet((Internet)) SW --> R1 SW --> R2 R1 --> Internet R2 --> Internet style R1 fill:#9f9,stroke:#333,stroke-width:2px style R2 fill:#f99,stroke:#333,stroke-width:2px

    Show answer details

    Correct answer: D

    The diagram depicts a classic high-availability setup using a First Hop Redundancy Protocol (FHRP). Protocols like VRRP (or the Cisco-proprietary HSRP) allow two or more routers to share a single virtual IP address. One router is elected as the 'active' or 'master' router, handling all traffic, while the other(s) remain in standby. If the active router fails, a standby router takes over the virtual IP address and begins forwarding traffic, providing seamless failover. BGP is an exterior gateway protocol for routing between autonomous systems. OSPF is an interior gateway routing protocol. STP is a Layer 2 protocol that prevents loops in switched networks.

  8. 8

    All of the following items should be included in a Business Impact Analysis (BIA) questionnaire EXCEPT questions that

    Show answer details

    Correct answer: A

    This is the CORRECT answer. A Business Impact Analysis (BIA) questionnaire should NOT include questions about determining the risk of a business interruption occurring. The BIA focuses on identifying and quantifying the impacts of business disruptions, not on assessing the likelihood or risk of those disruptions occurring. Risk assessment is a separate process that typically precedes or runs parallel to the BIA. The BIA should focus on impact identification, quantification of financial and operational losses, and recovery time objectives.

  9. 9

    Which of the following actions will reduce risk to a laptop before traveling to a high risk area?

    Show answer details

    Correct answer: C

    This is the CORRECT answer. Purging or re-imaging the hard disk drive before traveling to a high-risk area is the most effective way to reduce risk. This ensures that if the laptop is stolen, compromised, or subjected to border inspection, no sensitive organizational data can be accessed. Only essential software and data needed for the trip should be loaded onto the device.

  10. 10

    Which of the following represents the GREATEST risk to data confidentiality?

    Show answer details

    Correct answer: C

    This is the CORRECT answer. Backup tapes generated unencrypted represent the GREATEST risk to data confidentiality. If these tapes are lost, stolen, or improperly disposed of, all the sensitive data they contain becomes immediately accessible to unauthorized parties. Backup tapes often contain complete copies of critical databases and systems, making their compromise catastrophic for confidentiality. Other options may pose risks but none as severe and direct as unencrypted data at rest.

Create an account to continue.