Ten CISSP scenario questions, and why the runner-up answer loses
Try the ten questions below in 15 minutes, counting only your first answer. They are original, not ISC2 questions, and each is mapped to a domain and objective. Several answers are true statements; the task is to find the best, first or most appropriate action for a responsible adviser to management. Then sort your misses by habit with the table at the end.
Most CISSP misses are not ignorance. The candidate picks an answer that is technically right and managerially wrong. These ten questions are written to catch that, and every explanation says why the runner-up loses.
How should you use these questions?
The real exam is adaptive and ISC2 publishes no percentage that passes, so no practice score predicts your result. A set like this one does something more useful: it shows which habits cost you marks. Answer on paper, count only your first choice and read every explanation, including those for questions you got right.
The ten questions below are original, covering all eight domains and mapped to objectives in the outline effective 15 April 2024. Allow 15 minutes. Read each question for its key word, then ask what a responsible adviser to senior management would do.
For a wider view of the domains first, read the CISSP exam map.
Risk, assets, design and networks: five questions
Question 1 · Security and Risk Management · 1.9
An asset worth $200,000 has an exposure factor of 25 per cent against a threat expected to occur twice a year. What is the annual loss expectancy?
A. $50,000
B. $100,000
C. $400,000
D. $25,000
Show answer
Question 2 · Security and Risk Management · 1.1
While investigating an incident, a security manager finds evidence that a senior executive may have broken the law. What should she do first?
A. Confront the executive privately
B. Follow the organisation's escalation process, preserve the evidence and involve legal counsel
C. Report it to law enforcement at once without telling anyone
D. Delete the files to protect the company
Show answer
Question 3 · Asset Security · 2.5
A set of customer records is past its legal retention period, and no legal hold applies. What should happen?
A. Archive it indefinitely in case it is needed
B. Securely destroy it according to policy
C. Move it to cheaper storage and keep it
D. Anonymise a copy and keep the original
Show answer
Question 4 · Security Architecture and Engineering · 3.6
Two parties who have never met need a shared key to protect a long session over an untrusted network. Which approach is best?
A. Email the key in plain text
B. Establish a session key with a key-exchange protocol such as Diffie-Hellman, then encrypt with a symmetric cipher
C. Hash a password and send the hash as the key
D. Encrypt all session traffic with the other party's public key
Show answer
Question 5 · Communication and Network Security · 4.2
Visitors keep plugging unmanaged laptops into meeting-room ports. Which control best stops them joining the corporate network?
A. Network access control that authenticates and checks a device before admitting it
B. A longer DHCP lease time
C. Hiding the wireless network name
D. MAC address filtering alone
Show answer
Access, testing, operations and software: five questions
Question 6 · Identity and Access Management · 5.5
An auditor finds that a contractor still has payroll access three months after her project ended. Which control would most directly have prevented this?
A. Encrypting the payroll database
B. Periodic access reviews and timely deprovisioning
C. Stronger password complexity
D. Network segmentation
Show answer
Question 7 · Security Assessment and Testing · 6.4
A vulnerability scan reports 2,000 findings and the team can fix 100 this quarter. What is the best way to choose?
A. Fix the first 100 in the report
B. Prioritise by risk to the business, considering asset value, exposure and exploitability
C. Fix every finding with the highest severity score, whatever the system
D. Rerun the scan until the count falls
Show answer
Question 8 · Security Operations · 7.1
An analyst must collect evidence from a running, compromised server. Which order best follows the order of volatility?
A. Disk image, then memory, then network connections
B. Memory and network connections, then the disk image
C. Backup tapes, then memory
D. Shut the server down, then image the disk
Show answer
Question 9 · Security Operations · 7.10
Management says the order system may lose no more than 15 minutes of data. Which metric is this?
A. Recovery time objective
B. Recovery point objective
C. Maximum tolerable downtime
D. Mean time to repair
Show answer
Question 10 · Software Development Security · 8.4
A team wants to use a popular open-source library in a payment application. What should happen before adoption?
A. Assume popularity means it is safe
B. Assess its provenance, licence and known vulnerabilities and record it in a software inventory such as an SBOM
C. Copy the code and remove the licence file
D. Ban all open-source components
Show answer
What does your score tell you?
Count first answers only, then sort your misses by habit, which repeats across domains.
| If you missed | The habit to fix |
|---|---|
| 1 or 9 | Mixing up two neighbouring metrics, such as single and annual loss, or recovery point and recovery time |
| 2 or 8 | Acting alone, or before preserving evidence and following the proper order |
| 3 or 10 | Choosing an extreme, such as keep everything, trust everything or ban everything, over a managed middle |
| 4 or 5 | Picking a control that sounds strong but does not address the problem asked |
| 6 or 7 | Fixing the symptom or the score instead of the cause or the business risk |
If you missed three or more, find the objectives behind them in the exam map and give them extra hours in your plan.
Chapter 5 of CredenTrek For CISSP has you rate yourself on all 62 objectives, and Appendix G adds 16 more timed questions mapped to them.
- Answer all ten questions in 15 minutes, counting only your first choice.
- Write down the objective behind each miss and rate yourself from 1 to 5 on it.
- For each miss, write one sentence on why the runner-up fails.
- Check that your question bank names the outline effective 15 April 2024 and includes explained scenarios.
Questions readers ask
Are these real CISSP exam questions?
Why do two answers often look right?
What practice results show I am ready?
How do I choose a question bank?
- ISC2 CISSP certification page
- ISC2 CISSP exam outline, effective 15 April 2024
This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.