Free CISSP practice questions, every option explained
Ten scenario questions, one from every domain plus a multiple-response and an exhibit item. Answer like a security manager, then read why each option is the best move, a lesser one, or the wrong one.
- 100–150 items (CAT)
- Up to 3 hours
- Pass: 700 / 1,000

10 free CISSP practice questions
Taken from the course, across all eight domains. Click an option to answer; the explanation under every option appears as soon as you do.
A US federal agency follows the NIST Risk Management Framework for a new benefits system. The security and privacy controls have just been assessed and the report is ready. Which step comes NEXT?
- Implementation happened before the assessment.
- Ongoing monitoring follows the authorization decision.
- Selection is an earlier step, after categorization.
- Correct. After assessment, an authorizing official reviews the results and residual risk and decides whether to authorize operation. Monitoring follows.
A consumer electronics company labeled its new product's specifications Restricted during development. The product was launched publicly last week. What should happen to the classification of the specifications?
- Keeping public data at a high level wastes controls and confuses users.
- Correct. Sensitivity changes over time. The owner downgrades data through the formal process so protection matches its current value.
- Duplicating content creates version and integrity problems and leaves stale labels; the owner should reclassify through the declassification process.
- Only the owner, through the process, should change a classification.
A health system is designing a new outpatient campus in an area with a history of car break-ins and loitering. The architect wants to reduce crime through the layout itself before adding guards or cameras. Which approach BEST applies this principle?
- Guards may help, but they are an operational cost added later, not a design choice that reduces crime by itself.
- Correct. Crime Prevention Through Environmental Design uses natural surveillance, natural access control and territorial reinforcement to discourage crime by design.
- Cameras are mainly detective. CPTED aims to deter crime through layout before relying on technology.
- This creates hidden areas, harms the welcoming feel a clinic needs and is target hardening rather than design-based prevention.
A utility uses 4G modems to connect remote pumping stations to its control center over a carrier network. A consultant points out that the carrier's encryption only protects the radio segment. What should the security manager do?
- 5G improves several protections, but it still does not provide application end-to-end encryption to the utility's site.
- Correct. Cellular encryption protects the air interface only. End-to-end protection is needed across the carrier core and internet.
- Public addressing exposes the stations to internet scanning and adds risk.
- Radio encryption stops at the base station or core; traffic beyond it is not protected by the carrier's air-interface crypto.
New hires at an engineering firm get access by IT copying the account of a colleague in the same team. Audits show new hires inherit years of accumulated permissions. What is the BEST provisioning approach?
- Starting with nothing delays productivity and creates many ad hoc requests.
- Correct. Role-based provisioning from an authoritative trigger gives new hires exactly the access their role needs, not a colleague's history.
- Managers usually hold more access than staff, so copying them overprovisions.
- Copying any person's account still inherits their exceptions; the method is the problem.
A DR test met the RTO for every system. However, the team used an environment it had pre-staged and synchronized the day before, and it skipped validation of the restored data. How should the security manager interpret the results?
- Meeting RTOs under artificial conditions does not prove the same result in a real disaster.
- Results that overstate readiness are not a reason to test less often.
- RTOs come from the BIA and business needs, not from how easy a staged test was.
- Correct. Pre-staging removes the hardest part of a real recovery, and unvalidated data may be incomplete or corrupt. The measured times are therefore optimistic.
Which sequence BEST describes a typical change management process?
- Implementing before approval and analysis defeats the purpose of change control.
- Impact analysis informs approval, and testing should precede production implementation.
- Correct. A change is requested, its impact analyzed, approved, tested, implemented and then documented, updating the baseline.
- Approval must come before implementation, not after.
Match each cloud service model to the customer's main security responsibility. 1: SaaS. 2: PaaS. 3: IaaS. Which mapping is correct?
- PaaS customers do not manage the OS, and IaaS customers manage far more than users.
- SaaS customers do not manage the OS; IaaS customers do.
- Correct. Customer responsibility grows from SaaS to PaaS to IaaS. In IaaS the customer manages the guest OS and everything above it.
- PaaS hides the OS, while IaaS exposes it to the customer.
An engineering director at a manufacturer will travel to a trade show abroad, where border officers may inspect devices. Which TWO handling measures BEST protect the company's Restricted design files? (Choose TWO.)
- Correct. Minimizing what travels limits what could be inspected, lost or copied.
- Correct. Encryption protects files if the device is lost or stolen.
- Downloading abroad still puts the files on the device over untrusted networks and during later inspections.
- Extra copies on portable media add exposure rather than reducing it.
- Port control helps against copying, but it does not protect the files if the laptop is inspected, seized or stolen.
Call detail records from a manufacturer's IP PBX show: 2:10 a.m. to 4:40 a.m. Sunday, 380 calls from voicemail extension 4100 to premium-rate international numbers; normal weekend volume, under 10 calls. What is MOST likely happening, and what should be done?
- Hundreds of premium international calls from a voicemail extension at night are not normal activity.
- Vishing targets people through calls; these records show the PBX itself being used to place calls.
- The pattern is outbound billable calls, not a flood that degrades service.
- Correct. Attackers abuse weak voicemail or PBX settings to place costly calls. Dialing restrictions, strong PINs and call monitoring stop it.
The CISSP exam at a glance
| Domain | Weight | About this many per 125-question test |
|---|---|---|
| Security and Risk Management | 16% | 20 |
| Asset Security | 10% | 12–13 |
| Security Architecture and Engineering | 13% | 16–17 |
| Communication and Network Security | 13% | 16–17 |
| Identity and Access Management | 13% | 16–17 |
| Security Assessment and Testing | 12% | 15 |
| Security Operations | 13% | 16–17 |
| Software Development Security | 10% | 12–13 |
The real exam adapts to you and stops between 100 and 150 items. The course uses fixed 125-question tests, the middle of a real sitting, timed at 150 minutes.
What the CISSP really tests
Judgment over trivia. Most items ask what the security manager should do FIRST or what is the BEST control. Several options are real security actions; one fits the moment.
The manager mindset. Human safety first, security serving the business, senior management owning risk, governance before technology, and following the process instead of heroic shortcuts.
Formats on a fixed form. ISC2 also uses ordering, matching and hotspot items. The course writes them as text versions you can practise on Udemy.
Some math. SLE, ALE, safeguard value, and RTO, RPO and MTD reasoning.
Six full tests, 750 questions, all options explained
125 questions and 150 minutes per test, weighted like the April 2024 outline, with AI security woven into scenarios.
CISSP FAQ
How many questions are on the CISSP exam?
The CISSP is a computerized adaptive test (CAT) in every language: 100 to 150 items in up to 3 hours, including 25 unscored pretest items.
What is the CISSP passing score?
700 on a scale of 1,000. Because the exam is adaptive, no percentage converts to it; the course uses 75% on unseen tests only as a practice target.
How is the CISSP weighted?
Security and Risk Management 16%, Asset Security 10%, Security Architecture and Engineering 13%, Communication and Network Security 13%, Identity and Access Management 13%, Security Assessment and Testing 12%, Security Operations 13%, Software Development Security 10% (outline effective April 15, 2024).
Can I go back and change answers on the CISSP?
No. On the adaptive exam each answer is final, so practise answering once and moving on.
What is the CISSP 'manager mindset'?
Answers that reflect a security leader: people's safety first, security serving the business, senior management owning risk, governance before technology and following the process.
Are these real ISC2 exam questions?
No. Every question is original, written from ISC2's public exam outline. Real exam content is confidential.
Keep going: CISSP study plan · think like a manager · how the CAT exam works