AI

AI Exam Prep

More Practice / Certified Information Systems Security Professional

CISSP Practice Test

Our review divides the ISC2 curriculum into four multi-domain blocks to match official exam proportions: Threat Management and Governance represents 25% (combining Security & Risk with Asset Security), System Architecture and Comms commands 26%, Access controls and Verification forms 25%, and Software/Operations security handles the final 24%. This approach preserves the real-world mix of operational details and strategic risk calculations.

Certified Information Systems Security ProfessionalCybersecurityAI practice test
Browse all competitive exams

About this Certified Information Systems Security Professional Cybersecurity practice test

The legendary difficulty of the CISSP lies in its refusal to play the trivia game; it bypasses direct questions about encryption algorithms to evaluate your judgment as a risk-conscious business strategist. You have to put on your managerial hat to answer these situational scenarios. Whether defending an identity management system or formulating software security policies, the exam forces you to balance technical safeguards against business survival, user friction, and legal liability. These questions are constructed to train your managerial instinct, delivering justifications designed to satisfy an executive steering committee.

CISSP Practice Test sample questions

These starter questions help you launch a cybersecurity mock test quickly. Swap them with your own worksheet, notebook, or textbook questions any time.

  1. 1. A security architect is designing a system where the cost of implementing a control must be less than the expected loss from the risk it mitigates. Which principle does this represent?

    • A) Due diligence
    • B) Cost-benefit analysis in safeguard selection
    • C) Risk acceptance
    • D) Residual risk management
  2. 2. What is the correct order of the risk management process, from first to last?

    • A) Identify risks, mitigate risks, assess risks, monitor risks
    • B) Identify risks, assess/analyze risks, respond to (treat) risks, monitor and review
    • C) Assess risks, identify risks, monitor risks, respond to risks
    • D) Monitor risks, identify risks, assess risks, treat risks
  3. 3. A company decides to purchase cyber insurance to cover potential financial losses from a data breach rather than implementing additional technical controls. Which risk response strategy is this?

    • A) Risk avoidance
    • B) Risk mitigation
    • C) Risk transfer
    • D) Risk acceptance
  4. 4. What is 'due diligence' in the context of information security governance?

    • A) Taking corrective action after an incident
    • B) The ongoing research and investigation needed to understand risks before making a decision
    • C) Accepting all identified risks
    • D) Transferring risk through insurance
  5. 5. Which document formally defines an organization's overall approach to security, including management's intent and high-level direction?

    • A) A procedure
    • B) A standard
    • C) A security policy
    • D) A guideline
  6. 6. What is the purpose of data classification in an organization's asset security program?

    • A) To encrypt all data uniformly
    • B) To assign a sensitivity level to data so appropriate handling and protection controls can be applied
    • C) To determine which employees get promoted
    • D) To calculate insurance premiums
  7. 7. Who is typically responsible for determining the classification level of a specific piece of data and approving appropriate controls?

    • A) The data custodian
    • B) The data owner
    • C) The end user
    • D) The security auditor
  8. 8. What is the primary purpose of a data retention policy?

    • A) To maximize storage costs
    • B) To define how long data must be kept and when it should be securely destroyed, based on legal and business requirements
    • C) To encrypt data at rest
    • D) To classify data by sensitivity
  9. 9. In the Bell-LaPadula security model, what does the 'no read up, no write down' rule enforce?

    • A) Integrity
    • B) Confidentiality
    • C) Availability
    • D) Non-repudiation
  10. 10. Which security model uses a 'no write up, no read down' rule to protect data integrity?

    • A) Bell-LaPadula
    • B) Biba
    • C) Brewer-Nash
    • D) Clark-Wilson
  11. 11. What is the primary purpose of Trusted Platform Module (TPM) hardware?

    • A) To speed up disk I/O
    • B) To provide hardware-based cryptographic key storage and support secure boot processes
    • C) To manage network traffic
    • D) To provide backup power
  12. 12. In cryptography, what is the primary weakness of symmetric encryption compared to asymmetric encryption?

    • A) It is slower for large amounts of data
    • B) Securely distributing and managing the shared secret key among all parties is difficult
    • C) It cannot provide confidentiality
    • D) It requires a certificate authority
  13. 13. Which OSI layer does IPsec primarily operate at to secure communications between two hosts or networks?

    • A) Layer 2
    • B) Layer 3
    • C) Layer 5
    • D) Layer 7
  14. 14. What is the primary security benefit of network segmentation in an enterprise architecture?

    • A) It increases available bandwidth
    • B) It limits the ability of an attacker to move laterally after compromising one segment
    • C) It eliminates the need for firewalls
    • D) It encrypts all internal traffic automatically
  15. 15. Which type of firewall makes filtering decisions by tracking the state of active connections rather than evaluating each packet in isolation?

    • A) A packet-filtering firewall
    • B) A stateful inspection firewall
    • C) An application-level proxy without session tracking
    • D) A network tap
  16. 16. What is the primary purpose of using 802.1X in wired and wireless network security?

    • A) To provide encryption for stored data
    • B) To provide port-based network access control, requiring authentication before a device is granted network access
    • C) To translate private to public IP addresses
    • D) To detect malware signatures
  17. 17. Which access control model grants permissions based on sensitivity labels assigned to objects and clearance levels assigned to subjects, and is commonly enforced by the operating system rather than the data owner?

    • A) DAC
    • B) RBAC
    • C) MAC
    • D) ABAC
  18. 18. In access control terminology, what does the term 'least privilege' mean?

    • A) Users should have access to every system by default
    • B) Users and processes should be granted only the minimum access rights needed to perform their required tasks
    • C) Only administrators should have any access
    • D) Privileges should never be reviewed once granted
  19. 19. What is the primary purpose of federated identity management between organizations?

    • A) To require every user to have a separate account at each organization
    • B) To allow a user to authenticate once with a trusted identity provider and access resources across multiple organizations without a separate login
    • C) To encrypt data shared between organizations
    • D) To eliminate the need for multi-factor authentication
  20. 20. Which authentication factor category does a fingerprint scan belong to?

    • A) Something you know
    • B) Something you have
    • C) Something you are
    • D) Somewhere you are
  21. 21. What is the primary difference between a vulnerability assessment and a penetration test?

    • A) They are the same activity
    • B) A vulnerability assessment identifies and reports potential weaknesses; a penetration test actively attempts to exploit them to demonstrate real-world impact
    • C) A penetration test is always automated while a vulnerability assessment is always manual
    • D) A vulnerability assessment is illegal without a contract, while a penetration test never requires authorization
  22. 22. What is the purpose of a security audit log review as part of ongoing security assessment?

    • A) To improve network speed
    • B) To detect unauthorized or anomalous activity by examining recorded system and user events
    • C) To back up critical data
    • D) To classify data sensitivity
  23. 23. In the context of security testing, what is a 'false positive'?

    • A) A real vulnerability that testing fails to detect
    • B) An alert or finding that indicates a problem exists when, in fact, it does not
    • C) A vulnerability that has already been patched
    • D) An attack that succeeds without detection
  24. 24. What is the primary goal of the 'containment' phase in the incident response process?

    • A) To determine the root cause of the incident
    • B) To limit the scope and impact of an ongoing incident to prevent further damage
    • C) To restore normal operations
    • D) To notify regulators
  25. 25. What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

    • A) They are identical documents
    • B) A BCP focuses on keeping critical business functions running during a disruption; a DRP focuses specifically on restoring IT systems and infrastructure after a disaster
    • C) A DRP is only for natural disasters, while a BCP is only for cyberattacks
    • D) A BCP is a subset of a DRP
  26. 26. What is the primary purpose of a change management process in security operations?

    • A) To make changes faster without documentation
    • B) To ensure that changes to systems are reviewed, approved, tested, and documented before implementation, reducing the risk of unintended impact
    • C) To eliminate the need for testing
    • D) To automatically approve all emergency changes
  27. 27. What is 'chain of custody' in digital forensics?

    • A) A network topology diagram
    • B) A documented, unbroken record of who handled evidence, when, and how, from collection through presentation
    • C) A type of encryption algorithm
    • D) A backup rotation schedule
  28. 28. According to the OWASP Top 10, which category of vulnerability involves untrusted data being sent to an interpreter as part of a command or query?

    • A) Broken access control
    • B) Injection
    • C) Security misconfiguration
    • D) Cryptographic failures
  29. 29. What is the primary purpose of secure code review in the Software Development Life Cycle (SDLC)?

    • A) To speed up the build pipeline
    • B) To identify security flaws in source code before the application is deployed to production
    • C) To replace unit testing
    • D) To manage user access requests
  30. 30. What does 'DevSecOps' primarily emphasize?

    • A) Removing security testing to speed up releases
    • B) Integrating security practices and testing throughout the development and operations pipeline rather than only at the end
    • C) Outsourcing all security responsibilities to a third party
    • D) Using only manual security reviews

Syllabus & Core Topics

information security risk managementsecurity architecture and modelsidentity and access control modelssecurity operations and incident response

A seasoned security leader knows that an access control policy is only as effective as the physical security and hardware architecture supporting it. Analyzing the intersections between domains—like how a risk tolerance policy governs software development standards—makes your CISSP studies far more cohesive.

Why this practice page is useful

  • ISC2 questions frequently present multiple valid security strategies — like due care versus due diligence — and ask which one is most appropriate; these quizzes train your eye to spot the best answer among several reasonable ones.

  • Access models like MAC, DAC, and RBAC are simple in isolation but easily blur together under stress — contrasting them side by side here makes the distinctions stick.

  • Rather than testing simple definitions, these explanations focus on why a specific procedural control fits a particular corporate risk strategy — the managerial reasoning CISSP actually rewards.

Answer key & quick explanations

Short answers for the sample questions above. Use this to self-check before generating a fresh AI-built mock test.

  1. 1. A security architect is designing a system where the cost of implementing a control must be less than the expected loss from the risk it mitigates. Which principle does this represent?

    B) Cost-benefit analysis in safeguard selection

    Cost-benefit analysis in safeguard selection means a control should only be implemented if its cost is justified by the reduction in risk it provides — spending more on a safeguard than the loss it prevents doesn't make economic sense. Due diligence is the research done before a decision, risk acceptance means doing nothing about the risk, and residual risk is what's left over after controls are applied, not a selection principle itself.

  2. 2. What is the correct order of the risk management process, from first to last?

    B) Identify risks, assess/analyze risks, respond to (treat) risks, monitor and review

    The standard risk management process starts with identifying risks, then assessing or analyzing their likelihood and impact, then responding to (treating) them through mitigation, transfer, avoidance, or acceptance, and finally monitoring and reviewing on an ongoing basis. The other orderings skip steps or put monitoring before the risk has even been identified.

  3. 3. A company decides to purchase cyber insurance to cover potential financial losses from a data breach rather than implementing additional technical controls. Which risk response strategy is this?

    C) Risk transfer

    Purchasing insurance shifts the financial impact of a risk to a third party (the insurer) rather than reducing the likelihood or impact directly — that's the definition of risk transfer. Risk avoidance means eliminating the activity that creates the risk, risk mitigation means reducing the risk with controls, and risk acceptance means taking no action and absorbing the loss yourself.

  4. 4. What is 'due diligence' in the context of information security governance?

    B) The ongoing research and investigation needed to understand risks before making a decision

    Due diligence refers to the reasonable investigation and research an organization performs to understand its risks before acting — essentially 'doing your homework.' Due care is the follow-through of actually acting on what due diligence uncovered. Corrective action after an incident, blanket risk acceptance, and insurance are all separate concepts.

  5. 5. Which document formally defines an organization's overall approach to security, including management's intent and high-level direction?

    C) A security policy

    A security policy is the high-level document that states management's intent, goals, and overall direction for security, from which more detailed standards, procedures, and guidelines are derived. A procedure gives step-by-step instructions, a standard sets specific mandatory requirements, and a guideline offers recommended (not mandatory) practices.

  6. 6. What is the purpose of data classification in an organization's asset security program?

    B) To assign a sensitivity level to data so appropriate handling and protection controls can be applied

    Data classification assigns a sensitivity level — such as public, internal, confidential, or restricted — to data, so the organization can apply handling, access, and protection controls appropriate to how sensitive that data actually is. It has nothing to do with encryption uniformity, promotions, or insurance.

  7. 7. Who is typically responsible for determining the classification level of a specific piece of data and approving appropriate controls?

    B) The data owner

    The data owner is the business role accountable for a piece of data, including deciding its classification level and approving who can access it and under what controls. The data custodian implements and maintains the technical controls the owner requires, the end user simply uses the data, and an auditor independently verifies controls rather than setting them.

  8. 8. What is the primary purpose of a data retention policy?

    B) To define how long data must be kept and when it should be securely destroyed, based on legal and business requirements

    A data retention policy specifies how long different types of data must be kept, based on legal, regulatory, and business needs, and when it should be securely destroyed once that period ends. It isn't about maximizing storage spend, encryption, or classification — those are related but separate controls.

  9. 9. In the Bell-LaPadula security model, what does the 'no read up, no write down' rule enforce?

    B) Confidentiality

    Bell-LaPadula's 'no read up, no write down' rules (simple security property and *-property) are designed specifically to prevent information from flowing to a lower clearance level or from a higher classification down to a lower one, which protects confidentiality. It doesn't address data integrity, availability, or non-repudiation — those are handled by other models or mechanisms.

  10. 10. Which security model uses a 'no write up, no read down' rule to protect data integrity?

    B) Biba

    The Biba model uses 'no write up, no read down' rules to prevent lower-integrity data or subjects from corrupting higher-integrity data, making it the classic model built specifically around integrity rather than confidentiality. Bell-LaPadula addresses confidentiality, and while Clark-Wilson also protects integrity, it does so through well-formed transactions and separation of duties rather than the read/write rule this question describes.

  11. 11. What is the primary purpose of Trusted Platform Module (TPM) hardware?

    B) To provide hardware-based cryptographic key storage and support secure boot processes

    A TPM is a dedicated hardware chip that securely generates and stores cryptographic keys and supports functions like secure boot, which verifies that a system starts up using only trusted software. It isn't related to disk speed, network traffic management, or backup power.

  12. 12. In cryptography, what is the primary weakness of symmetric encryption compared to asymmetric encryption?

    B) Securely distributing and managing the shared secret key among all parties is difficult

    Symmetric encryption is fast and efficient, but every party who needs to communicate securely has to share the same secret key, and distributing and protecting that key without it being intercepted or leaked is a significant practical challenge — that's the weakness asymmetric encryption (using public/private key pairs) solves. Symmetric encryption is actually faster than asymmetric for bulk data, it does provide confidentiality, and it doesn't inherently require a CA.

  13. 13. Which OSI layer does IPsec primarily operate at to secure communications between two hosts or networks?

    B) Layer 3

    IPsec operates at the Network layer (Layer 3), which is why it can transparently secure all traffic between two hosts or networks regardless of the application generating it. Layer 2 protocols work within a single local segment, and TLS/SSL (often confused with IPsec) typically operates higher up, around the Session/Presentation layers, not IPsec.

  14. 14. What is the primary security benefit of network segmentation in an enterprise architecture?

    B) It limits the ability of an attacker to move laterally after compromising one segment

    Segmenting a network into smaller zones means that if an attacker compromises one segment, firewalls or access controls between segments make it harder for them to move laterally to reach other, more sensitive parts of the network. Segmentation isn't primarily about bandwidth, it doesn't remove the need for firewalls (it often relies on them), and it doesn't automatically encrypt traffic.

  15. 15. Which type of firewall makes filtering decisions by tracking the state of active connections rather than evaluating each packet in isolation?

    B) A stateful inspection firewall

    A stateful inspection firewall keeps track of the state of active connections (like whether a TCP packet belongs to an already-established session) and uses that context to make smarter filtering decisions than looking at each packet in isolation. A static packet-filtering firewall evaluates each packet independently against rules with no awareness of connection state, and an application-level proxy without session tracking and a network tap don't perform this kind of connection-state-based filtering.

  16. 16. What is the primary purpose of using 802.1X in wired and wireless network security?

    B) To provide port-based network access control, requiring authentication before a device is granted network access

    802.1X provides port-based network access control, requiring a device or user to authenticate — often against a RADIUS server — before being granted access to the network through a switch port or wireless access point. It doesn't encrypt stored data, translate addresses, or detect malware signatures.

  17. 17. Which access control model grants permissions based on sensitivity labels assigned to objects and clearance levels assigned to subjects, and is commonly enforced by the operating system rather than the data owner?

    C) MAC

    Mandatory Access Control (MAC) assigns sensitivity labels to objects and clearance levels to subjects, and the operating system — not the data owner — enforces access based on comparing the two, which is why it's used in high-security environments. DAC lets the resource owner decide who gets access, RBAC assigns permissions based on job role, and ABAC evaluates a broader set of attributes rather than fixed labels and clearances.

  18. 18. In access control terminology, what does the term 'least privilege' mean?

    B) Users and processes should be granted only the minimum access rights needed to perform their required tasks

    Least privilege means every user, account, and process should be granted only the access rights necessary to do its specific job — nothing more — which limits the damage possible if that account is compromised or misused. It's the opposite of giving broad default access, it applies to more than just administrators, and privileges should be reviewed periodically, not left unchecked.

  19. 19. What is the primary purpose of federated identity management between organizations?

    B) To allow a user to authenticate once with a trusted identity provider and access resources across multiple organizations without a separate login

    Federated identity management lets a user authenticate once with a trusted identity provider and then access resources at other, federated organizations without creating and managing a separate set of credentials at each one. It doesn't require separate accounts everywhere (that's the problem it solves), it isn't primarily an encryption mechanism, and it doesn't eliminate the value of MFA — it can actually be combined with it.

  20. 20. Which authentication factor category does a fingerprint scan belong to?

    C) Something you are

    A fingerprint is a physical biometric characteristic, which places it in the 'something you are' authentication factor category. 'Something you know' covers passwords and PINs, 'something you have' covers tokens and smart cards, and 'somewhere you are' refers to location-based authentication, a different (and less standard) factor category.

  21. 21. What is the primary difference between a vulnerability assessment and a penetration test?

    B) A vulnerability assessment identifies and reports potential weaknesses; a penetration test actively attempts to exploit them to demonstrate real-world impact

    A vulnerability assessment scans and reports on potential weaknesses without necessarily attempting to exploit them, while a penetration test goes further and actively tries to exploit those weaknesses to prove real-world impact and how far an attacker could actually get. They're related but distinct activities, and neither is defined purely by being automated or manual, nor by a blanket rule about authorization.

  22. 22. What is the purpose of a security audit log review as part of ongoing security assessment?

    B) To detect unauthorized or anomalous activity by examining recorded system and user events

    Reviewing audit logs lets security teams spot unauthorized access attempts, unusual behavior, or policy violations by examining what users and systems actually did, which is a core ongoing assessment activity. It has no direct role in network speed, backups, or data classification.

  23. 23. In the context of security testing, what is a 'false positive'?

    B) An alert or finding that indicates a problem exists when, in fact, it does not

    A false positive is when a security tool or test reports a problem — such as a vulnerability or an intrusion — that doesn't actually exist, which wastes investigation time if not properly triaged. A real vulnerability that goes undetected is a false negative, a patched vulnerability appearing in a scan report is a separate configuration/scan-timing issue, and an undetected successful attack isn't what 'false positive' refers to at all.

  24. 24. What is the primary goal of the 'containment' phase in the incident response process?

    B) To limit the scope and impact of an ongoing incident to prevent further damage

    Containment is specifically about stopping an incident from spreading further or causing more damage — for example, isolating an infected host from the network — before moving on to eradication and recovery. Determining root cause is part of the identification/analysis phase, restoring operations is recovery, and regulatory notification is a separate compliance step, not containment itself.

  25. 25. What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

    B) A BCP focuses on keeping critical business functions running during a disruption; a DRP focuses specifically on restoring IT systems and infrastructure after a disaster

    A BCP focuses broadly on keeping essential business functions running during and after a disruption, while a DRP is the more technical, IT-focused plan for restoring systems, applications, and data after a disaster — the DRP is typically considered a component that supports the broader BCP. Neither plan is limited to only natural disasters or only cyberattacks, and a BCP is the broader plan, not a subset of the DRP.

  26. 26. What is the primary purpose of a change management process in security operations?

    B) To ensure that changes to systems are reviewed, approved, tested, and documented before implementation, reducing the risk of unintended impact

    Change management ensures that proposed changes to systems or configurations go through review, approval, testing, and documentation before being implemented, which reduces the risk of an unplanned outage or security gap caused by an unvetted change. It's meant to slow down risky changes appropriately, not eliminate testing, skip documentation, or auto-approve emergency changes without any review.

  27. 27. What is 'chain of custody' in digital forensics?

    B) A documented, unbroken record of who handled evidence, when, and how, from collection through presentation

    Chain of custody is the documented, unbroken trail showing exactly who collected, handled, transferred, and stored a piece of evidence and when, which is essential for that evidence to remain legally admissible. It isn't a network diagram, an encryption algorithm, or a backup schedule.

  28. 28. According to the OWASP Top 10, which category of vulnerability involves untrusted data being sent to an interpreter as part of a command or query?

    B) Injection

    Injection vulnerabilities occur when untrusted input is passed to an interpreter — such as a SQL, OS command, or LDAP interpreter — without proper validation or parameterization, letting an attacker alter the intended command or query. Broken access control involves improper enforcement of permissions, security misconfiguration involves insecure default or incomplete settings, and cryptographic failures involve weak or missing protection of sensitive data — all distinct OWASP Top 10 categories from injection.

  29. 29. What is the primary purpose of secure code review in the Software Development Life Cycle (SDLC)?

    B) To identify security flaws in source code before the application is deployed to production

    Secure code review examines source code before deployment specifically to catch security flaws — like injection risks or improper input validation — that automated scanning or functional testing alone might miss. It isn't primarily about build speed, it complements rather than replaces unit testing, and it has nothing to do with managing user access requests.

  30. 30. What does 'DevSecOps' primarily emphasize?

    B) Integrating security practices and testing throughout the development and operations pipeline rather than only at the end

    DevSecOps embeds security practices and automated testing throughout the entire development and operations pipeline, so vulnerabilities are caught early and continuously rather than only at a final gate before release. It's the opposite of removing security checks, it doesn't mean outsourcing security entirely, and it specifically favors automated testing integrated into the pipeline over relying solely on manual review.

Curriculum Mapping & Learning Guide

Use this breakdown to identify which skills each question tests and guide post-test review.

Risk Management & Asset Security

Calculating business risk exposure, structuring security policies, classifying asset datasets, and assigning data custody roles.

Security Architecture & Network Security

Evaluating formal math security models, planning encryption schemes, segmenting subnets, and selecting firewall types.

Identity, Access & Assessment

Structuring identity directories, configuring federated access links, managing MFA properties, and reviewing security audits.

Operations & Software Development Security

Formulating disaster recovery plans, performing forensic collections, securing software build lifecycles, and embedding DevSecOps.

Certified Information Systems Security Professional Cybersecurity units covered

  1. Chapter 1: Security & Risk Management: Creating risk frameworks, evaluating regulatory mandates, establishing security policies, and drafting business continuity plans.
  2. Chapter 2: Asset Security: Classifying digital assets properly, assigning information owners, and implementing retention rules.
  3. Chapter 3: Security Architecture & Engineering: Designing models like Bell-LaPadula and Biba, selecting hardware modules, and utilizing cryptography.
  4. Chapter 4: Communication & Network Security: Segmenting virtual subnets, configuring VPN gateways, and managing wireless WPA3 parameters.
  5. Chapter 5: Identity & Access Management: Administering authentication factors, designing authorization matrices, and configuring identity federations.
  6. Chapter 6: Security Assessment & Testing: Managing continuous audits, coordinating internal assessments, and conducting penetration tests.
  7. Chapter 7: Security Operations: Coordinating disaster recovery routines, gathering digital forensics, and managing patches.
  8. Chapter 8: Software Development Security: Applying secure SDLC practices, auditing codebase risks, and remediating high-risk alerts.

How to use this cissp practice test page

1. Click the Start CISSP Practice Test button to launch the setup.

2. Use the slider to choose your number of questions (from 5 to 30, default is 10).

3. Take your test, submit your answers, and let our AI analyze your performance.

4. Select Practice Weak Areas or Generate More Like This to have the AI create custom, targeted questions just for you.

Explore more for Certified Information Systems Security Professional

Move between subjects in the same exam to build a balanced Certified Information Systems Security Professional revision routine.