Ultimate Comprehensive Study Guide for the
Certified Information Systems Security Professional
Practice Questions Covering All 8 CISSP Domains
with Detailed Explanations Aligned with the Latest
(ISC)² CISSP Exam Blueprint (2026–2027)
SECTION 1: SECURITY & RISK MANAGEMENT (50 Questions)
1. Which of the following is the PRIMARY purpose of a security policy?
• A) Guide the implementation of security controls and define acceptable
behavior
• B) Provide technical instructions for firewall configuration
• C) Define the company's marketing strategy
• D) Establish a baseline for performance metrics
• E) Document employee benefits
2. A risk assessment has identified a high-probability, high-impact
vulnerability. What is the MOST appropriate management response?
• A) Implement additional security controls to mitigate the risk
• B) Accept the risk and monitor it
• C) Transfer the risk through insurance
• D) Ignore the risk due to budget constraints
• E) Terminate the business process
3. The three pillars of information security are:
• A) Confidentiality, Integrity, Availability
• B) Confidentiality, Integrity, Accountability
• C) Privacy, Integrity, Availability
, • D) Confidentiality, Assurance, Availability
• E) Privacy, Assurance, Accountability
4. Which of the following is a key characteristic of quantitative risk analysis?
• A) It assigns monetary values to assets and calculates Annualized Loss
Expectancy (ALE)
• B) It uses subjective rankings for risk assessment
• C) It relies on expert opinions and is non-mathematical
• D) It identifies risks but does not prioritize them
• E) It only applies to IT security
5. The formula for Single Loss Expectancy (SLE) is:
• A) Asset Value × Exposure Factor
• B) SLE × Annualized Rate of Occurrence (ARO)
• C) Asset Value × ARO
• D) Exposure Factor × ARO
• E) Asset Value ÷ Exposure Factor
6. Which of the following is an example of a "preventive" control?
• A) Access control list (ACL) on a firewall
• B) Security awareness training
• C) Audit log review
• D) Intrusion detection system (IDS)
• E) Regular backup testing
7. In the context of security governance, which of the following is the
PRIMARY responsibility of senior management?
• A) Establish the security strategy and allocate resources
• B) Implement security controls
• C) Monitor compliance on a daily basis
, • D) Perform vulnerability assessments
• E) Develop secure code
8. A company is developing a new software application. Which security
approach should be integrated from the beginning to minimize risk?
• A) Security by Design
• B) Firewall implementation after development
• C) Penetration testing during the final phase
• D) Vulnerability scanning after deployment
• E) Manual code review once a year
9. Which of the following best describes "Risk Appetite"?
• A) The amount of risk an organization is willing to accept to achieve its
objectives
• B) The total risk present in the environment
• C) A specific control used to mitigate risk
• D) The process of identifying risks
• E) The method of transferring risk to a third party
10. A security manager needs to classify a new asset. Which of the following is
the MOST important factor to consider?
• A) The asset's value to the organization and the impact of its loss
• B) The age of the asset
• C) The color of the asset
• D) The location of the asset
• E) The asset's manufacturer
11. Which of the following security roles is responsible for implementing and
operating the security controls?
• A) Security Administrator
• B) Chief Information Security Officer (CISO)
, • C) Data Owner
• D) Auditor
• E) Security Policy Developer
12. What is the PRIMARY goal of a Business Continuity Plan (BCP)?
• A) Ensure that critical business functions can continue during and after
a disaster
• B) Protect data from cyber-attacks
• C) Ensure that employees are paid on time
• D) Reduce the cost of insurance
• E) Improve the company's reputation
13. Which of the following is a key legal principle that requires organizations
to protect personal information they collect?
• A) Privacy
• B) Integrity
• C) Confidentiality
• D) Availability
• E) Non-repudiation
14. In the context of risk management, a 'vulnerability' is defined as:
• A) A weakness that could be exploited by a threat
• B) The potential for a loss
• C) An entity that can cause harm
• D) A measure of the likelihood of an attack
• E) A control that prevents attacks
15. The 'need-to-know' principle is a fundamental component of which
security objective?
• A) Confidentiality