CISSP® Certification Exam 2026 Latest Comprehensive
Study Guide Practice Questions, Cybersecurity Domains
Review, Verified Answers, Detailed Explanations & Success
Preparation Workbook
The CISSP Mindset: Manager, Not Technician
The CISSP exam is fundamentally different from other security certifications. It
assumes you already know how firewalls, encryption, and access controls
work. The exam tests judgment: How would a senior information security
manager think about this problem?
Key heuristics for success:
• Prefer least privilege, defense in depth, and secure-by-default answers
• Choose preventive and auditable controls that scale with policy and risk
appetite
• In incident response, respect order and evidence handling before jumping
to cleanup
• In cloud or IAM scenarios, think identity-first and shared-responsibility-
first
• Governance and policy often precede technical controls
DOMAIN 1: SECURITY AND RISK MANAGEMENT (16%)
Questions 1–16
Question 1
A security manager is reviewing the risk register and identifies a vulnerability in a
legacy system that would cost $500,000 to remediate. The annual loss expectancy
(ALE) for an exploit is calculated at $50,000. What is the most
appropriate response?
,A) Immediately remediate the vulnerability regardless of cost
B) Transfer the risk by purchasing cyber insurance
C) Accept the risk and document the decision with management approval
D) Avoid the risk by decommissioning the legacy system
Answer: C) Accept the risk and document the decision with management
approval
Rationale: The safeguard value ($500K) exceeds the ALE ($50K), meaning the
control costs more than the risk it mitigates. Risk acceptance is appropriate when
the cost to remediate exceeds the potential loss. This must be formally documented
with management approval — not just left unaddressed. CISSP thinks in business
terms: security spending must be justified by risk reduction value.
Question 2
A CISO is developing the organization's security policy framework. Which
document should be created FIRST to ensure all subsequent security documents
are properly aligned?
A) Security procedures and work instructions
B) Information security policy
C) Security standards and baselines
D) Security awareness training materials
Answer: B) Information security policy
Rationale: The policy hierarchy starts with the Information Security Policy at
the top — it establishes management's intent, direction, and principles. Everything
else (standards, baselines, guidelines, procedures) flows from and supports the
policy. You cannot write a standard without knowing what the policy requires.
Question 3
A company wants to improve disaster recovery for several business services.
Budgets are limited, and leadership asks which services should receive the
strongest recovery targets first. What should be completed before setting detailed
technical recovery designs?
,A) A business impact analysis that identifies critical processes, impacts,
dependencies, and recovery priorities
B) A purchase order for the largest backup appliance available
C) A firewall rule review for every internal subnet
D) A password reset for all employees
Answer: A) A business impact analysis that identifies critical processes,
impacts, dependencies, and recovery priorities
Rationale: A BIA connects recovery targets to business impact and service
criticality. CISSP questions often test whether the candidate starts with business
priorities before choosing technology.
Question 4
A security team documents a moderate residual risk after implementing agreed
controls. The team proposes that the risk be formally accepted by the business
owner. Why is formal risk acceptance important?
A) It transfers liability to the insurance provider
B) It ensures the risk is fully eliminated
C) It creates an audit trail and ensures accountability for the decision
D) It allows the security team to avoid responsibility
Answer: C) It creates an audit trail and ensures accountability for the
decision
Rationale: Formal risk acceptance documents that the business owner is aware of
and accepts the residual risk. This creates accountability and an audit trail. Risk
acceptance does not transfer liability (A) or eliminate the risk (B), and the security
team remains responsible for ongoing monitoring.
Question 5
Which of the following is the correct order of the (ISC)² Code of Ethics Canons?
A) Protect society, the common good, necessary public trust and confidence, and
the infrastructure → Act honorably, honestly, justly, responsibly, and legally →
Provide diligent and competent service to principals → Advance and protect the
, profession
B) Advance and protect the profession → Act honorably, honestly, justly,
responsibly, and legally → Provide diligent and competent service to principals →
Protect society, the common good, necessary public trust and confidence, and the
infrastructure
C) Protect society, the common good, necessary public trust and confidence, and
the infrastructure → Provide diligent and competent service to principals → Act
honorably, honestly, justly, responsibly, and legally → Advance and protect the
profession
D) Provide diligent and competent service to principals → Protect society, the
common good, necessary public trust and confidence, and the infrastructure → Act
honorably, honestly, justly, responsibly, and legally → Advance and protect the
profession
Answer: A) Protect society, the common good, necessary public trust and
confidence, and the infrastructure → Act honorably, honestly, justly,
responsibly, and legally → Provide diligent and competent service to
principals → Advance and protect the profession
Rationale: The (ISC)² Code of Ethics canons are ordered by priority. Canon I
(Protect society) is the highest priority. Canon II (Act honorably) comes second.
Canon III (Provide diligent service to principals) comes third. Canon IV (Advance
the profession) comes fourth. When an ethics scenario is presented, the order of the
canons matters.
Question 6
A security analyst calculates the Single Loss Expectancy (SLE) for a server as
$10,000 and the Annualized Rate of Occurrence (ARO) as 0.5. What is the Annual
Loss Expectancy (ALE)?
A) $5,000
B) $10,000
C) $15,000
D) $20,000
Answer: A) $5,000
Study Guide Practice Questions, Cybersecurity Domains
Review, Verified Answers, Detailed Explanations & Success
Preparation Workbook
The CISSP Mindset: Manager, Not Technician
The CISSP exam is fundamentally different from other security certifications. It
assumes you already know how firewalls, encryption, and access controls
work. The exam tests judgment: How would a senior information security
manager think about this problem?
Key heuristics for success:
• Prefer least privilege, defense in depth, and secure-by-default answers
• Choose preventive and auditable controls that scale with policy and risk
appetite
• In incident response, respect order and evidence handling before jumping
to cleanup
• In cloud or IAM scenarios, think identity-first and shared-responsibility-
first
• Governance and policy often precede technical controls
DOMAIN 1: SECURITY AND RISK MANAGEMENT (16%)
Questions 1–16
Question 1
A security manager is reviewing the risk register and identifies a vulnerability in a
legacy system that would cost $500,000 to remediate. The annual loss expectancy
(ALE) for an exploit is calculated at $50,000. What is the most
appropriate response?
,A) Immediately remediate the vulnerability regardless of cost
B) Transfer the risk by purchasing cyber insurance
C) Accept the risk and document the decision with management approval
D) Avoid the risk by decommissioning the legacy system
Answer: C) Accept the risk and document the decision with management
approval
Rationale: The safeguard value ($500K) exceeds the ALE ($50K), meaning the
control costs more than the risk it mitigates. Risk acceptance is appropriate when
the cost to remediate exceeds the potential loss. This must be formally documented
with management approval — not just left unaddressed. CISSP thinks in business
terms: security spending must be justified by risk reduction value.
Question 2
A CISO is developing the organization's security policy framework. Which
document should be created FIRST to ensure all subsequent security documents
are properly aligned?
A) Security procedures and work instructions
B) Information security policy
C) Security standards and baselines
D) Security awareness training materials
Answer: B) Information security policy
Rationale: The policy hierarchy starts with the Information Security Policy at
the top — it establishes management's intent, direction, and principles. Everything
else (standards, baselines, guidelines, procedures) flows from and supports the
policy. You cannot write a standard without knowing what the policy requires.
Question 3
A company wants to improve disaster recovery for several business services.
Budgets are limited, and leadership asks which services should receive the
strongest recovery targets first. What should be completed before setting detailed
technical recovery designs?
,A) A business impact analysis that identifies critical processes, impacts,
dependencies, and recovery priorities
B) A purchase order for the largest backup appliance available
C) A firewall rule review for every internal subnet
D) A password reset for all employees
Answer: A) A business impact analysis that identifies critical processes,
impacts, dependencies, and recovery priorities
Rationale: A BIA connects recovery targets to business impact and service
criticality. CISSP questions often test whether the candidate starts with business
priorities before choosing technology.
Question 4
A security team documents a moderate residual risk after implementing agreed
controls. The team proposes that the risk be formally accepted by the business
owner. Why is formal risk acceptance important?
A) It transfers liability to the insurance provider
B) It ensures the risk is fully eliminated
C) It creates an audit trail and ensures accountability for the decision
D) It allows the security team to avoid responsibility
Answer: C) It creates an audit trail and ensures accountability for the
decision
Rationale: Formal risk acceptance documents that the business owner is aware of
and accepts the residual risk. This creates accountability and an audit trail. Risk
acceptance does not transfer liability (A) or eliminate the risk (B), and the security
team remains responsible for ongoing monitoring.
Question 5
Which of the following is the correct order of the (ISC)² Code of Ethics Canons?
A) Protect society, the common good, necessary public trust and confidence, and
the infrastructure → Act honorably, honestly, justly, responsibly, and legally →
Provide diligent and competent service to principals → Advance and protect the
, profession
B) Advance and protect the profession → Act honorably, honestly, justly,
responsibly, and legally → Provide diligent and competent service to principals →
Protect society, the common good, necessary public trust and confidence, and the
infrastructure
C) Protect society, the common good, necessary public trust and confidence, and
the infrastructure → Provide diligent and competent service to principals → Act
honorably, honestly, justly, responsibly, and legally → Advance and protect the
profession
D) Provide diligent and competent service to principals → Protect society, the
common good, necessary public trust and confidence, and the infrastructure → Act
honorably, honestly, justly, responsibly, and legally → Advance and protect the
profession
Answer: A) Protect society, the common good, necessary public trust and
confidence, and the infrastructure → Act honorably, honestly, justly,
responsibly, and legally → Provide diligent and competent service to
principals → Advance and protect the profession
Rationale: The (ISC)² Code of Ethics canons are ordered by priority. Canon I
(Protect society) is the highest priority. Canon II (Act honorably) comes second.
Canon III (Provide diligent service to principals) comes third. Canon IV (Advance
the profession) comes fourth. When an ethics scenario is presented, the order of the
canons matters.
Question 6
A security analyst calculates the Single Loss Expectancy (SLE) for a server as
$10,000 and the Annualized Rate of Occurrence (ARO) as 0.5. What is the Annual
Loss Expectancy (ALE)?
A) $5,000
B) $10,000
C) $15,000
D) $20,000
Answer: A) $5,000