CredenTrek
Library / CISSP / Guide 07 of 8
CISSP · Practice questions

Ten CISSP scenario questions, and why the runner-up answer loses

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 8 min read

The short answer

Try the ten questions below in 15 minutes, counting only your first answer. They are original, not ISC2 questions, and each is mapped to a domain and objective. Several answers are true statements; the task is to find the best, first or most appropriate action for a responsible adviser to management. Then sort your misses by habit with the table at the end.

Most CISSP misses are not ignorance. The candidate picks an answer that is technically right and managerially wrong. These ten questions are written to catch that, and every explanation says why the runner-up loses.

How should you use these questions?

The real exam is adaptive and ISC2 publishes no percentage that passes, so no practice score predicts your result. A set like this one does something more useful: it shows which habits cost you marks. Answer on paper, count only your first choice and read every explanation, including those for questions you got right.

The ten questions below are original, covering all eight domains and mapped to objectives in the outline effective 15 April 2024. Allow 15 minutes. Read each question for its key word, then ask what a responsible adviser to senior management would do.

For a wider view of the domains first, read the CISSP exam map.

Risk, assets, design and networks: five questions

Question 1 · Security and Risk Management · 1.9

An asset worth $200,000 has an exposure factor of 25 per cent against a threat expected to occur twice a year. What is the annual loss expectancy?

A. $50,000
B. $100,000
C. $400,000
D. $25,000

Show answer
Answer: B. Objective 1.9 covers risk management and quantitative analysis. The single loss expectancy is $200,000 × 25% = $50,000, and multiplying by two occurrences a year gives $100,000. A is the runner-up: it is the single loss, before the annual rate.

Question 2 · Security and Risk Management · 1.1

While investigating an incident, a security manager finds evidence that a senior executive may have broken the law. What should she do first?

A. Confront the executive privately
B. Follow the organisation's escalation process, preserve the evidence and involve legal counsel
C. Report it to law enforcement at once without telling anyone
D. Delete the files to protect the company

Show answer
Answer: B. Objective 1.1 covers professional ethics. The code asks you to protect society and act honourably, and the responsible route is documented escalation with the evidence preserved. C is the runner-up: external reporting may be required in some cases, but doing it alone and unannounced bypasses legal counsel and the duty of confidentiality.

Question 3 · Asset Security · 2.5

A set of customer records is past its legal retention period, and no legal hold applies. What should happen?

A. Archive it indefinitely in case it is needed
B. Securely destroy it according to policy
C. Move it to cheaper storage and keep it
D. Anonymise a copy and keep the original

Show answer
Answer: B. Objective 2.5 covers asset retention. Data kept longer than needed adds risk and cost without a purpose, so it should be destroyed securely under the retention policy. A is the runner-up: it feels safe, but it widens the impact of any later breach.

Question 4 · Security Architecture and Engineering · 3.6

Two parties who have never met need a shared key to protect a long session over an untrusted network. Which approach is best?

A. Email the key in plain text
B. Establish a session key with a key-exchange protocol such as Diffie-Hellman, then encrypt with a symmetric cipher
C. Hash a password and send the hash as the key
D. Encrypt all session traffic with the other party's public key

Show answer
Answer: B. Objective 3.6 covers cryptographic solutions. Asymmetric methods solve the key distribution problem and symmetric ciphers do the bulk work quickly. D is the runner-up: it works, but asymmetric encryption is slow for bulk traffic, which is why sessions use it only to set up a symmetric key.

Question 5 · Communication and Network Security · 4.2

Visitors keep plugging unmanaged laptops into meeting-room ports. Which control best stops them joining the corporate network?

A. Network access control that authenticates and checks a device before admitting it
B. A longer DHCP lease time
C. Hiding the wireless network name
D. MAC address filtering alone

Show answer
Answer: A. Objective 4.2 covers secure network components, including network access control. It decides who and what may join. D is the runner-up: MAC lists are easy to spoof and say nothing about who the user is or the state of the device.

Access, testing, operations and software: five questions

Question 6 · Identity and Access Management · 5.5

An auditor finds that a contractor still has payroll access three months after her project ended. Which control would most directly have prevented this?

A. Encrypting the payroll database
B. Periodic access reviews and timely deprovisioning
C. Stronger password complexity
D. Network segmentation

Show answer
Answer: B. Objective 5.5 covers the access provisioning lifecycle, including review and removal. The fault is an entitlement that outlived its purpose. C is the runner-up: strong passwords do nothing about access that should not exist.

Question 7 · Security Assessment and Testing · 6.4

A vulnerability scan reports 2,000 findings and the team can fix 100 this quarter. What is the best way to choose?

A. Fix the first 100 in the report
B. Prioritise by risk to the business, considering asset value, exposure and exploitability
C. Fix every finding with the highest severity score, whatever the system
D. Rerun the scan until the count falls

Show answer
Answer: B. Objective 6.4 covers analysing test output and reporting. Limited effort goes where it reduces the most business risk. C is the runner-up: a severity score alone ignores whether the system matters or is reachable.

Question 8 · Security Operations · 7.1

An analyst must collect evidence from a running, compromised server. Which order best follows the order of volatility?

A. Disk image, then memory, then network connections
B. Memory and network connections, then the disk image
C. Backup tapes, then memory
D. Shut the server down, then image the disk

Show answer
Answer: B. Objective 7.1 covers evidence handling and forensics. The most volatile data disappears first, so memory and live connections come before disk. D is the runner-up: powering off is tempting to stop the damage, but it destroys volatile evidence.

Question 9 · Security Operations · 7.10

Management says the order system may lose no more than 15 minutes of data. Which metric is this?

A. Recovery time objective
B. Recovery point objective
C. Maximum tolerable downtime
D. Mean time to repair

Show answer
Answer: B. Objective 7.10 covers recovery strategies. The recovery point objective is the acceptable amount of data loss, measured in time. A is the runner-up: the recovery time objective measures how long restoration may take, not how much data may be lost.

Question 10 · Software Development Security · 8.4

A team wants to use a popular open-source library in a payment application. What should happen before adoption?

A. Assume popularity means it is safe
B. Assess its provenance, licence and known vulnerabilities and record it in a software inventory such as an SBOM
C. Copy the code and remove the licence file
D. Ban all open-source components

Show answer
Answer: B. Objective 8.4 covers the security of acquired software, including open-source components. Managed adoption keeps the benefit and controls the risk. D is the runner-up: blanket bans are rarely the best answer because they ignore business need.

What does your score tell you?

Count first answers only, then sort your misses by habit, which repeats across domains.

If you missed The habit to fix
1 or 9 Mixing up two neighbouring metrics, such as single and annual loss, or recovery point and recovery time
2 or 8 Acting alone, or before preserving evidence and following the proper order
3 or 10 Choosing an extreme, such as keep everything, trust everything or ban everything, over a managed middle
4 or 5 Picking a control that sounds strong but does not address the problem asked
6 or 7 Fixing the symptom or the score instead of the cause or the business risk

If you missed three or more, find the objectives behind them in the exam map and give them extra hours in your plan.

Chapter 5 of CredenTrek For CISSP has you rate yourself on all 62 objectives, and Appendix G adds 16 more timed questions mapped to them.

Your next step
  1. Answer all ten questions in 15 minutes, counting only your first choice.
  2. Write down the objective behind each miss and rate yourself from 1 to 5 on it.
  3. For each miss, write one sentence on why the runner-up fails.
  4. Check that your question bank names the outline effective 15 April 2024 and includes explained scenarios.

Questions readers ask

Are these real CISSP exam questions?
No. They were written for this page and are not ISC2 questions. Each is mapped to an objective in the outline effective 15 April 2024. Use them to find weak objectives, not to predict the wording you will see.
Why do two answers often look right?
Because the exam asks for the best, first or most appropriate action. Both answers may be true statements. Ask who is accountable, what comes first in the lifecycle and what addresses the risk at its source.
What practice results show I am ready?
No single score does. Look for consistent results across two or three full practice exams, no domain far behind the others and the ability to explain why the best answer beats the second best.
How do I choose a question bank?
Choose one and use it thoroughly. Check that it follows the current outline, covers all 62 objectives, explains every answer and states its refund policy in writing.
Sources

This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.