CISSP Certified Information Systems Security Professional Free Practice Test — 30 Questions
This practice set of 30 questions exercises your decision-making in high-pressure security incidents. You'll confront zero-day exploits, ransomware, data exfiltration, and regulatory conflicts (GDPR, CCPA, GLBA, PCI DSS). The questions test your ability to prioritize containment vs. investigation, apply risk management under ambiguity, and demonstrate behavioral competencies like adaptability and communication when leading teams through crises. Key domains include Security Operations, Asset Security, and Security and Risk Management. Use this set to sharpen your incident response sequencing, regulatory compliance thinking, and leadership under pressure—not as a proxy for the live exam blueprint.
What this CISSP Certified Information Systems Security Professional practice set measures
This is an analysis of the practice bank, not a claim about the vendor's live exam blueprint. Use it to identify the knowledge, judgment, and recall patterns exercised here, then verify your coverage against the current official exam guide.
Incident Response Prioritization & Containment
A recurring theme is the correct sequencing of incident response actions. The practice bank emphasizes that containment—isolating affected systems—is the immediate priority when facing an active exploit or data exfiltration. This must be balanced with preserving forensic evidence for later analysis. Questions test your ability to resist rushing to recovery or notification without understanding the breach's scope. The correct approach aligns with NIST SP 800-61 phases: preparation, detection, containment, eradication, recovery, and lessons learned.
- Isolate affected network segments to prevent lateral movement and further exfiltration.
- Preserve forensic evidence before initiating eradication or recovery.
- Activate the incident response plan and convene the designated team.
Behavioral Competencies in Crisis Management
Several questions focus on soft skills needed when leading security teams under uncertainty. Organizational mergers, ambiguous directives, and novel threats require adaptability, flexibility, and strong communication. The practice bank repeatedly selects these competencies over purely technical options when the scenario involves shifting priorities or team morale. The ability to guide teams through change, manage expectations, and maintain effectiveness during transitions is as critical as technical knowledge for a CISSP.
- Adaptability and flexibility are crucial when pivoting strategies with incomplete information.
- Strong communication skills help manage expectations and convey changes to diverse audiences.
- Leadership potential is demonstrated by guiding teams through ambiguity and maintaining morale.
Regulatory Compliance & Data Protection Conflicts
Questions present conflicts between new data residency laws (or cloud provider policies) and existing international privacy obligations like GDPR. The correct response prioritizes initiating a cross-functional impact assessment and revising policies—not unilaterally adopting the cloud provider's mandate. The practice bank underscores that compliance must be proactive, involving legal and business stakeholders, and that technical solutions (e.g., data segregation) should be explored before accepting non-compliance. Data retention policies must justify necessity and minimize collection.
- Initiate a cross-functional task force to conduct impact assessments of new regulations.
- Implement tiered data retention policies based on sensitivity and regulatory necessity.
- Engage cloud providers to explore technical solutions that satisfy both provider and legal obligations.
Zero-Day & Legacy System Risk Mitigation
When facing zero-day vulnerabilities in legacy or unsupported systems, the practice bank advises implementing compensating controls like network segmentation, enhanced monitoring, and custom IDPS signatures—not rushing to modify code or replace systems without planning. The emphasis is on risk-based decision-making: balance operational continuity with security until a patch is available. For supply chain attacks, proactive supplier risk management integrated with threat intelligence is favored over reactive internal containment.
- Implement network segmentation and access controls to isolate vulnerable systems.
- Deploy intrusion detection/prevention systems with custom signatures tailored to the vulnerability.
- Establish a comprehensive supplier risk management program integrated with threat intelligence.
Practice CISSP Certified Information Systems Security Professional with real flashcards
Read the prompt, commit to an answer, then flip the card. Move through the deck at your own pace and repeat any topic that does not come back quickly.
Card 1 of 20
1 reviewed this session
Static practice bank
Start the 30-question diagnostic
The complete question bank is embedded in this pre-rendered page. There is no database request or second content download when you begin.
During a late-night alert, a security analyst at a financial institution discovers that a zero-day exploit has successfully infiltrated the core customer data repository, leading to unauthorized access. The system logs indicate anomalous outbound traffic patterns suggesting potential data exfiltration. The organization\'s incident response plan mandates a structured approach to such events. Which of the following actions should the incident response team prioritize as the *immediate* first step to mitigate further damage?
Study workflow
Turn one CISSP Certified Information Systems Security Professional attempt into a study plan
- 1
Apply the Incident Response Lifecycle
Memorize the NIST SP 800-61 phases: Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident. In scenarios, always first contain to stop bleeding (isolate, block), then preserve forensics, then eradicate. Delay notification until scope is known unless legally required.
- 2
Evaluate Behavioral Competencies First
When a question describes ambiguity, shifting priorities, or team resistance, look for answers that emphasize adaptability, communication, and leadership. Technical fixes are secondary. Practice identifying the human element that drives successful incident management.
- 3
Resolve Regulatory Conflicts with Impact Assessment
When a new law or policy conflicts with existing obligations, do not unilaterally adopt the new requirement. Initiate a cross-functional task force to assess impact on all data processing. Revise policies and governance frameworks based on that assessment, involving legal and compliance teams.
- 4
Use Compensating Controls for Unpatchable Systems
For legacy or zero-day vulnerabilities without patches, do not modify code or wait. Immediately isolate affected systems via network segmentation. Deploy host-based detection rules, monitor logs aggressively, and restrict access to essential users only. Plan replacement in parallel.
- 5
Measure Security Awareness Program Effectiveness
Establish pre-deployment baseline metrics (e.g., phishing click rates, report rates). Continuously track these indicators against program updates. Use control groups to measure behavioral shifts. Avoid relying solely on completion rates or post-training quizzes.
FAQ
Questions about this exam practice page
Clear boundaries on what the bank covers, how to use it, and where official vendor information still matters.
When should you notify regulators under GDPR after a breach?+
Under GDPR Article 33, notify the supervisory authority without undue delay and no later than 72 hours after awareness. You may provide initial information as a preliminary notification and supplement later. Delay only if you can demonstrate justification.
What is the first step in responding to a zero-day exploit?+
Immediate containment to prevent lateral movement. Isolate affected network segments, disable compromised accounts, and block outbound traffic. Then begin forensic analysis to understand the exploit's mechanism and scope.
How should you handle conflicting data residency and retention requirements?+
Implement a tiered data retention policy categorizing logs by sensitivity and legal necessity. For logs needed for security, explore pseudonymization or anonymization. Engage cloud providers for technical solutions like data segregation or trusted execution environments.
What behavioral competency is most critical when leading a team through an organizational merger?+
Adaptability and flexibility. Mergers introduce ambiguity, shifting priorities, and potential role changes. The leader must guide the team through uncertainty, communicate effectively, and maintain operational effectiveness despite incomplete information.
Which approach best tests the effectiveness of an adaptive security awareness program?+
Establish pre-deployment baseline metrics for key behaviors (e.g., phishing susceptibility, incident reporting). Continuously track these indicators after program updates. Use control groups to measure behavioral shifts and risk reduction over time.
Build the next review session
Browse another free bank or use the study strategy guide to turn your misses into spaced review.
