CredenTrek
Blog / CISSP / Article 05 of 10
CISSP · Prepare

Think like a manager: how to answer CISSP scenario questions

By Mustafa K. Al-Dori · Checked against official documents on 11 October 2026 · 8 min read

The short answer

CISSP scenario questions reward judgement, not engineering. Read for the key word, identify who is asking, protect people first, follow policy and law, and choose the answer that fixes risk at its source. If two answers are both correct, pick the one that comes first in the lifecycle. Practise this routine until it is automatic.

Experienced engineers often score worse than they expect on practice questions. They are answering as engineers, and the exam is written for advisers to the business.

Why a technically correct answer can still be wrong

CISSP presents a short situation and asks for the best, first or most appropriate action. Several options may be true statements. The task is to find the action a responsible adviser to management would take at that moment.

The CredenTrek CISSP book describes a candidate who had led firewall projects for eight years. When he started studying, he answered practice questions as an engineer and scored poorly. Once he began asking "what would the business need first?", his scores rose and he passed four months later.

That change is the whole skill.

A five-step reading routine

  1. Find the key word. Best, first, most or least. It decides which kind of answer you want.
  2. Identify the role. Who is asking, and what authority do they have? A security officer cannot decide what only senior management can.
  3. Name the domain. Is this risk, asset handling, architecture, identity, testing, operations or software? Naming it brings the right principles forward.
  4. Remove the extremes. Wiping, firing and ignoring are rarely best.
  5. Compare what remains. Ask which is earlier in the lifecycle, and which one deals with the cause rather than the symptom.

Cues that point towards the best answer

  • An answer that protects people ranks above one that protects equipment.
  • An answer that follows policy and law ranks above a clever workaround.
  • An answer that involves the right owner or approver ranks above a unilateral technical fix.
  • An answer that addresses the cause ranks above one that treats the symptom.
  • When in doubt, ask who is accountable and who should decide.

None of these is an official ISC2 rule. They are study habits distilled from how the exam's tasks are written, and you should always check them against your question's wording.

Worked example 1: the sequence

A risk assessment finds a high risk that would cost more to fix than the asset is worth. Senior management decides to live with it. Which response is this?

The key word is the response, and the decision belongs to senior management. Living with a known risk, with management's approval, is risk acceptance. Mitigation would reduce it. Transference would pass it to a third party. Avoidance would stop the activity. The role tells you who decides, and the definition does the rest.

Worked example 2: who is accountable

Who holds final accountability for protecting an organisation's information assets?

Security staff implement controls and advise. Administrators run systems. Auditors assess. Accountability stays with senior management. When a question asks about accountability, the answer is rarely the person closest to the keyboard.

Worked example 3: what comes first

What should be completed first when developing a business continuity plan?

A recovery test and a backup purchase both come later. A business impact analysis identifies critical functions and recovery priorities, which everything else depends on. When two answers are both good actions, the earlier one in the lifecycle usually wins.

These three examples are drawn from the book's sample questions, written for the book in the style of the exam. They are not ISC2 questions.

Train the habit, not the answer

After each practice set, write one sentence on why the runner-up fails. Do it for every question, including those you got right. In an adaptive exam the difference between a good answer and the best one is what moves your result.

Mark questions you answered by instinct, and ask what instinct you used. Within a few sessions you will see your pattern. Most candidates have one favourite wrong move: jumping to a technical fix, skipping the approver or doing things in the wrong order.

Practice material

Use a block of ten, count only your first answers, and sort the misses by habit.

Questions readers ask

Are the five cues official ISC2 guidance?
No. They are study heuristics. ISC2 publishes the exam outline, and your final authority is always the wording of the question and the outline.
I work in technical security. Why do I score poorly on practice questions?
Technical roles train you to fix. CISSP asks what to do first, who decides and how to manage the risk. Practise reading each question as an adviser to the business.
How many practice questions should I do?
Enough to see a stable pattern in your misses. The count matters less than reviewing why each wrong answer was wrong.
Sources

This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.