Chapter 7 of 813% of exam

Security Operations

Domain 7 is day-to-day security: investigations and forensics, logging and monitoring, configuration and change management, foundational operations concepts, incident management, patching, recovery strategies, DR testing and physical and personnel safety.

Investigations and evidence

Evidence must be collected in an order that preserves the most fragile data first, handled so its integrity can be shown, and analyzed on copies. Rushing to shut a system down can destroy the evidence you need.

Order of volatility
Registers and cache; routing and ARP tables, process table, kernel statistics and memory; temporary file systems; disk; remote logs; physical configuration; archival media.
RFC 3227 §2.1
Don't shut down early
Do not shut down until evidence collection is complete; evidence may be lost and attackers may alter shutdown routines.
RFC 3227 §2.2
Work on copies
Make a bit-level copy for analysis, because analysis alters access times.
RFC 3227 §2
Chain of custody
Document each person who handled evidence, when it was transferred and why.
NIST SP 800-72 / 800-101 Rev. 1 glossary

Monitoring, configuration and change

Detection relies on IDPS, logs and SIEM, tuned to balance false positives against false negatives. Configuration management sets approved baselines and detects drift; change management keeps even emergency changes under control.

Detection trade-off
Reducing false negatives usually increases false positives, and vice versa.
NIST SP 800-94 §2.2
Signature versus anomaly
Signatures catch known threats; anomaly-based detection compares activity to a baseline and can flag new attacks.
NIST SP 800-94 §2.3
Emergency changes
Unscheduled changes are still managed and go through change control after the fact, with a security impact analysis.
NIST SP 800-128 §3.3
Separation of duties
Divide process steps so no single entity can subvert the process alone.
RFC 4949; NIST SP 800-53 Rev. 5 AC-5

Patch and vulnerability management

Patching is the only response that removes a vulnerability without removing functionality, but it is not always immediately possible. When a patch is late or will never come, other responses must carry the load.

Patching removes the flaw
Installing a patch, update or upgrade is the only risk response that completely eliminates a vulnerability without removing functionality.
NIST SP 800-40 Rev. 4 §2
When patching is not viable
A patch may not exist yet or the software may be end-of-life; use other risk responses such as mitigation or isolation.
NIST SP 800-40 Rev. 4 §2
Prioritize patches
Deploy first the patches that reduce the most risk.
NIST SP 800-40 Rev. 4

Recovery strategies and DR testing

Recovery design matches backup methods and alternate sites to the RTO and RPO from the BIA, trading cost against speed. Plans are then exercised, from discussion-based tabletop sessions to functional and full-scale exercises.

Differential versus incremental
A differential holds changes since the last full backup (restore full + last differential); an incremental holds changes since the last backup of any type (restore full + every incremental).
NIST SP 800-34 Rev. 1 §5.1.2
Alternate sites
Cold sites provide space and infrastructure; warm sites add equipment; hot sites are fully operational with current software; mirrored sites add real-time mirroring at the highest cost.
NIST SP 800-34 Rev. 1 §3.4.3, §5.1.5
Tabletop versus functional
Tabletop exercises are discussion-based; functional exercises have staff perform their duties in a simulated operational environment.
NIST SP 800-34 Rev. 1 §3.5.3

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report