SASERÁ Academy
ISC2 CISSP · April 2024 outline · free practice

Free CISSP practice questions, every option explained

Ten scenario questions, one from every domain plus a multiple-response and an exhibit item. Answer like a security manager, then read why each option is the best move, a lesser one, or the wrong one.

  • 100–150 items (CAT)
  • Up to 3 hours
  • Pass: 700 / 1,000
CISSP practice exams 2026 course cover

10 free CISSP practice questions

Taken from the course, across all eight domains. Click an option to answer; the explanation under every option appears as soon as you do.

0 of 10 answered · 0 correctEvery option is explained after you answer
Security and Risk ManagementQuestion 1 of 10

A US federal agency follows the NIST Risk Management Framework for a new benefits system. The security and privacy controls have just been assessed and the report is ready. Which step comes NEXT?

  • Implementation happened before the assessment.
  • Ongoing monitoring follows the authorization decision.
  • Selection is an earlier step, after categorization.
  • Correct. After assessment, an authorizing official reviews the results and residual risk and decides whether to authorize operation. Monitoring follows.
Why it matters: NIST RMF steps: prepare, categorize, select, implement, assess, authorize, monitor.
Asset SecurityQuestion 2 of 10

A consumer electronics company labeled its new product's specifications Restricted during development. The product was launched publicly last week. What should happen to the classification of the specifications?

  • Keeping public data at a high level wastes controls and confuses users.
  • Correct. Sensitivity changes over time. The owner downgrades data through the formal process so protection matches its current value.
  • Duplicating content creates version and integrity problems and leaves stale labels; the owner should reclassify through the declassification process.
  • Only the owner, through the process, should change a classification.
Why it matters: Classification is not permanent. Owners review and change levels through a controlled process as value and sensitivity change.
Security Architecture and EngineeringQuestion 3 of 10

A health system is designing a new outpatient campus in an area with a history of car break-ins and loitering. The architect wants to reduce crime through the layout itself before adding guards or cameras. Which approach BEST applies this principle?

  • Guards may help, but they are an operational cost added later, not a design choice that reduces crime by itself.
  • Correct. Crime Prevention Through Environmental Design uses natural surveillance, natural access control and territorial reinforcement to discourage crime by design.
  • Cameras are mainly detective. CPTED aims to deter crime through layout before relying on technology.
  • This creates hidden areas, harms the welcoming feel a clinic needs and is target hardening rather than design-based prevention.
Why it matters: CPTED uses the built environment (visibility, lighting, access paths and a sense of ownership) to deter crime, often more cheaply than guards and technology.
Communication and Network SecurityQuestion 4 of 10

A utility uses 4G modems to connect remote pumping stations to its control center over a carrier network. A consultant points out that the carrier's encryption only protects the radio segment. What should the security manager do?

  • 5G improves several protections, but it still does not provide application end-to-end encryption to the utility's site.
  • Correct. Cellular encryption protects the air interface only. End-to-end protection is needed across the carrier core and internet.
  • Public addressing exposes the stations to internet scanning and adds risk.
  • Radio encryption stops at the base station or core; traffic beyond it is not protected by the carrier's air-interface crypto.
Why it matters: Cellular air-interface encryption protects the radio link, not the full path. Critical traffic needs end-to-end encryption and private APNs or VPNs.
Identity and Access ManagementQuestion 5 of 10

New hires at an engineering firm get access by IT copying the account of a colleague in the same team. Audits show new hires inherit years of accumulated permissions. What is the BEST provisioning approach?

  • Starting with nothing delays productivity and creates many ad hoc requests.
  • Correct. Role-based provisioning from an authoritative trigger gives new hires exactly the access their role needs, not a colleague's history.
  • Managers usually hold more access than staff, so copying them overprovisions.
  • Copying any person's account still inherits their exceptions; the method is the problem.
Why it matters: Provisioning should be based on defined roles and triggered by authoritative events (HR records), not cloned from existing users.
Security Assessment and TestingQuestion 6 of 10

A DR test met the RTO for every system. However, the team used an environment it had pre-staged and synchronized the day before, and it skipped validation of the restored data. How should the security manager interpret the results?

  • Meeting RTOs under artificial conditions does not prove the same result in a real disaster.
  • Results that overstate readiness are not a reason to test less often.
  • RTOs come from the BIA and business needs, not from how easy a staged test was.
  • Correct. Pre-staging removes the hardest part of a real recovery, and unvalidated data may be incomplete or corrupt. The measured times are therefore optimistic.
Why it matters: DR and BC data must be read with its test conditions. Unrealistic setups and skipped validation make results look better than real capability.
Security OperationsQuestion 7 of 10

Which sequence BEST describes a typical change management process?

  • Implementing before approval and analysis defeats the purpose of change control.
  • Impact analysis informs approval, and testing should precede production implementation.
  • Correct. A change is requested, its impact analyzed, approved, tested, implemented and then documented, updating the baseline.
  • Approval must come before implementation, not after.
Why it matters: Change management moves from request through analysis, approval and testing to controlled implementation and documentation.
Software Development SecurityQuestion 8 of 10

Match each cloud service model to the customer's main security responsibility. 1: SaaS. 2: PaaS. 3: IaaS. Which mapping is correct?

  • PaaS customers do not manage the OS, and IaaS customers manage far more than users.
  • SaaS customers do not manage the OS; IaaS customers do.
  • Correct. Customer responsibility grows from SaaS to PaaS to IaaS. In IaaS the customer manages the guest OS and everything above it.
  • PaaS hides the OS, while IaaS exposes it to the customer.
Why it matters: Shared responsibility shifts with the model: the customer owns more layers in IaaS and fewer in SaaS, but always its data and access.
Asset SecurityQuestion 9 of 10 · choose two

An engineering director at a manufacturer will travel to a trade show abroad, where border officers may inspect devices. Which TWO handling measures BEST protect the company's Restricted design files? (Choose TWO.)

  • Correct. Minimizing what travels limits what could be inspected, lost or copied.
  • Correct. Encryption protects files if the device is lost or stolen.
  • Downloading abroad still puts the files on the device over untrusted networks and during later inspections.
  • Extra copies on portable media add exposure rather than reducing it.
  • Port control helps against copying, but it does not protect the files if the laptop is inspected, seized or stolen.
Why it matters: Travel handling focuses on carrying the minimum, encrypting what must travel and keeping devices under control.
Communication and Network SecurityQuestion 10 of 10

Call detail records from a manufacturer's IP PBX show: 2:10 a.m. to 4:40 a.m. Sunday, 380 calls from voicemail extension 4100 to premium-rate international numbers; normal weekend volume, under 10 calls. What is MOST likely happening, and what should be done?

  • Hundreds of premium international calls from a voicemail extension at night are not normal activity.
  • Vishing targets people through calls; these records show the PBX itself being used to place calls.
  • The pattern is outbound billable calls, not a flood that degrades service.
  • Correct. Attackers abuse weak voicemail or PBX settings to place costly calls. Dialing restrictions, strong PINs and call monitoring stop it.
Why it matters: Toll fraud exploits PBX and voicemail weaknesses to place expensive calls. Defenses include strong PINs, disabling unneeded features, restricting destinations and monitoring call records.

The CISSP exam at a glance

DomainWeightAbout this many per 125-question test
Security and Risk Management16%20
Asset Security10%12–13
Security Architecture and Engineering13%16–17
Communication and Network Security13%16–17
Identity and Access Management13%16–17
Security Assessment and Testing12%15
Security Operations13%16–17
Software Development Security10%12–13

The real exam adapts to you and stops between 100 and 150 items. The course uses fixed 125-question tests, the middle of a real sitting, timed at 150 minutes.

What the CISSP really tests

Judgment over trivia. Most items ask what the security manager should do FIRST or what is the BEST control. Several options are real security actions; one fits the moment.

The manager mindset. Human safety first, security serving the business, senior management owning risk, governance before technology, and following the process instead of heroic shortcuts.

Formats on a fixed form. ISC2 also uses ordering, matching and hotspot items. The course writes them as text versions you can practise on Udemy.

Some math. SLE, ALE, safeguard value, and RTO, RPO and MTD reasoning.

Six full tests, 750 questions, all options explained

125 questions and 150 minutes per test, weighted like the April 2024 outline, with AI security woven into scenarios.

See the CISSP course →

CISSP FAQ

How many questions are on the CISSP exam?

The CISSP is a computerized adaptive test (CAT) in every language: 100 to 150 items in up to 3 hours, including 25 unscored pretest items.

What is the CISSP passing score?

700 on a scale of 1,000. Because the exam is adaptive, no percentage converts to it; the course uses 75% on unseen tests only as a practice target.

How is the CISSP weighted?

Security and Risk Management 16%, Asset Security 10%, Security Architecture and Engineering 13%, Communication and Network Security 13%, Identity and Access Management 13%, Security Assessment and Testing 12%, Security Operations 13%, Software Development Security 10% (outline effective April 15, 2024).

Can I go back and change answers on the CISSP?

No. On the adaptive exam each answer is final, so practise answering once and moving on.

What is the CISSP 'manager mindset'?

Answers that reflect a security leader: people's safety first, security serving the business, senior management owning risk, governance before technology and following the process.

Are these real ISC2 exam questions?

No. Every question is original, written from ISC2's public exam outline. Real exam content is confidential.

Keep going: CISSP study plan · think like a manager · how the CAT exam works