Practice for the CISSP exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: During a Business Continuity Plan (BCP) review, senior leadership asks which type of disaster recovery site should be se. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the CISSP practice test →
What you will practice
- During a Business Continuity Plan (BCP) review, senior leadership asks which type of disaster recovery site s…
- A hurricane has destroyed your company's primary data center. The disaster recovery team activates the BCP. S…
- Your SOC team detects unusual outbound connections from a sensitive R&D server. Initial triage suggests the a…
- A financial institution recently suffered an insider attack where an employee copied thousands of sensitive c…
- Your organization is building a new data center to host critical financial systems. The facility will contain…
- A multinational company is rolling out a customer-facing web portal that allows users to log in with their Go…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. During a Business Continuity Plan (BCP) review, senior leadership asks which type of disaster recovery site should be selected. The company processes financial transactions that cannot tolerate more than a few minutes of downtime, but cost…
Answer: A. Hot site
A hot site provides the fully operational and immediately available infrastructure required to meet a recovery time objective of just a few minutes. While warm sites offer better cost efficiency, they require too much time to activate, making them unsuitable for critical financial processing.
Q2. A hurricane has destroyed your company's primary data center. The disaster recovery team activates the BCP. Senior executives are pressuring you for a status update. Which action should you take FIRST as the CISO?
Answer: D. Ensure the safety and accountability of all on-site personnel before focusing on systems recovery
Human life and safety always rank above data recovery, system restoration, or executive updates. Even under immense pressure from management, a security leader must first ensure all personnel are safe and fully accounted for before activating technical recovery procedures like failovers.
Q3. Your SOC team detects unusual outbound connections from a sensitive R&D server. Initial triage suggests the attacker may be attempting to exfiltrate proprietary data. Senior management wants immediate assurance. As the CISO, what is the BE…
Answer: B. Activate the incident response plan
Activating the incident response plan is the correct next step because it orchestrates the formal containment, forensic, and communication efforts required. While disconnecting the server seems logical, a CISO must ensure the structured process governs technical actions rather than acting hastily.
Q4. A financial institution recently suffered an insider attack where an employee copied thousands of sensitive customer records to a USB drive. The board asks you what control should be implemented to PREVENT this from happening again.
Answer: A. Implement Data Loss Prevention (DLP) with endpoint blocking of removable media
Endpoint data loss prevention is correct because it acts as a preventive control capable of actively blocking unauthorized file transfers to removable media. Options like random audits and SIEM monitoring are strictly detective controls, while policies alone lack technical enforcement.
Q5. Your organization is building a new data center to host critical financial systems. The facility will contain densely packed racks of servers and storage arrays. Executives emphasize that equipment must not be damaged by suppression system…
Answer: C. FM-200 or clean-agent suppression systems
Clean agent systems like FM-200 are the best choice because they suppress fires quickly without leaving residue or destroying electronic equipment. While carbon dioxide also protects equipment, it poses a lethal threat to personnel, violating the fundamental requirement of life safety.
Q6. A multinational company is rolling out a customer-facing web portal that allows users to log in with their Google or Facebook accounts instead of creating new credentials. Security leadership wants to ensure that the company's portal only…
Answer: C. OpenID Connect
OpenID Connect is the best fit because it layers identity and authentication capabilities on top of the OAuth 2.0 framework. While OAuth 2.0 handles authorization delegation, it does not natively verify user identity, making OpenID Connect the standard for federated social logins.
Q7. During an internal fraud investigation, your incident response team collects log files and employee emails that may later be used in civil litigation and possibly a criminal trial. Executives insist that the evidence must hold up under bot…
Answer: D. Document the chain of custody with signatures, timestamps, and transfer details for every handler
Documenting the chain of custody with signatures and timestamps legally proves who handled the evidence and guarantees its integrity for court. Hashing and secure lockers preserve data physically, but they do not prove the human handling history required for admissibility.
Q8. Your organization is adopting the NIST Risk Management Framework (RMF) for a new healthcare application that processes PHI. During a meeting, a project manager asks what must be done immediately after categorizing the information system.
Answer: A. Select baseline
In the NIST Risk Management Framework, selecting baseline controls is the immediate next step after categorizing the system. You must select the appropriate security controls based on impact level before you can implement or document them.
Q9. Your company recently suffered a data breach caused by an employee reusing weak passwords. To address the issue, management mandates security awareness training focused on password hygiene for all employees. Which type of control does this…
Answer: A. Administrative / Preventive
Security awareness training is an administrative control, and its goal here is to prevent future incidents by changing user behavior. Whenever the exam mentions training or policies, immediately categorize it as an administrative and preventive control.
Q10. Your executives want to adopt a framework that focuses on governance and aligning IT goals with business objectives, not just security. They specifically want something that helps with auditability, accountability, and enterprise risk mana…
Answer: C. COBIT
The correct choice is COBIT because it is a framework focused specifically on IT governance and aligning business objectives. Expect NIST or ISO 27001 as strong distractors here, but those focus strictly on security operations and risk management rather than broad governance.
Q11. During a financial audit, regulators demand proof that your online banking platform can immediately detect and respond if a user's digital certificate is revoked due to compromise. Your PKI team explains options for handling certificate st…
Answer: C. Implement Online Certificate Status Protocol (OCSP) for real-time revocation validation
The correct choice is OCSP because it provides real-time certificate revocation validation directly from the certificate authority. CRLs are a tempting distractor, but remember they are published periodically and cannot guarantee the immediate status checks regulators require.
Q12. A retail company suffers a breach that exposes thousands of customer credit cards. During litigation, the court asks whether the company's executives took reasonable steps to protect customer data. Which example BEST demonstrates due dilig…
Answer: C. Management commissioning a third-party risk assessment before deploying a new payment system
The correct choice is commissioning a third-party risk assessment because due diligence is the proactive investigation of risks before taking action. Approving policies and implementing encryption demonstrate due care, which represents the ongoing operational actions taken to maintain security.
Q13. You are the CISO of a government contractor managing classified data. During an internal audit, you discover that a senior engineer has bypassed security controls to finish a project ahead of schedule, saving the company millions in penalt…
Answer: C. Report the violation to appropriate authorities or internal compliance even if it could harm the company's reputation
The ISC squared code of ethics mandates protecting society and the public before employer interests. Reporting serious violations through proper channels is required, regardless of financial justifications. For the exam, always eliminate options that prioritize reputation, cost, or convenience over legal and ethical duties.
Q14. During a penetration test, the tester successfully gains access to a domain controller using a service account with excessive privileges. The CISO wants to prevent similar findings in the future. What should the security manager do first t…
Answer: B. Conduct a root cause analysis to determine why privilege escalation was possible
Conducting a root cause analysis is the correct first step because a security manager must strategically understand why a vulnerability was exploited before deploying fixes. Implementing privileged access management tools immediately is a tactical reaction that might miss broader systemic issues.
Q15. A global financial institution detects abnormal outbound traffic from a workstation that belongs to the CFO's executive assistant. Initial logs show large encrypted data transfers to an external IP at 2:00 a.m. The SOC suspects a data exfi…
Answer: A. Disconnect the affected workstation from the network immediately
Disconnecting the affected workstation is correct because incident response priorities dictate stopping an active data exfiltration immediately to prevent further loss. While capturing a forensic image is important, it happens after containment to prevent ongoing unauthorized data leakage.
Q16. A software development company recently transitioned to DevOps and Continuous Integration/Continuous Deployment (CI/CD). During a review, the security manager discovers that developers have direct administrative access to production server…
Answer: B. Implement separation of duties and restrict production access via a controlled change management process
Implementing separation of duties and enforcing a change management process is correct because it addresses the underlying process gap rather than just punishing users. Revoking access immediately is a reactive technical fix that fails to establish the necessary governance for production environments.
More CISSP drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.