CISSP (Certified Information Systems Security Professional) Practice Test

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Certified Information Systems Security Professional (CISSP) — Exam facts
Administering bodyISC2 — exam delivered by Pearson VUE

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Questions100–150 questions

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Time limit180 minutes

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Passing scoreISC2 points: 700 of 1,000 points

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Fees
  • $749 — Standard registration (Americas, Asia Pacific, Middle East, Africa) (ISC2, per attempt)

Source: ISC2 — ISC2 Exam Pricing

Languages offeredChinese · English · German · Japanese · Spanish

Source: ISC2 — CISSP Certification Exam Outline (Effective Date: April 15, 2024)

Exam facts, with a source for every line

Frequently asked questions

How many CISSP (Certified Information Systems Security Professional) practice questions are here?+

A full bank of original CISSP (Certified Information Systems Security Professional) practice questions across the official content areas, weighted like the real exam, with explanations. Free, no signup.

What is the CISSP (Certified Information Systems Security Professional) exam like?+

A multiple-choice exam, 180 minutes. Practice by topic here, then take the full timed mock exam to gauge readiness.

Are these the real exam questions?+

No. Every question is 100% original, written from public primary sources with explanations. We never copy real exam questions or paid prep material.

Can I study in Chinese or Spanish?+

PrepPass practice is in English, 中文 and Español. The official exam is in English — switch the question language to English any time to rehearse the exact terminology you'll see on test day.

Is there a study guide for the CISSP (Certified Information Systems Security Professional)?+

Yes. PrepPass sells CISSP Study Guide — 2026 Edition, a PDF + EPUB download, $24.99 one-time; the practice on this page stays free without it. See the study guide →

Sample practice questions

A few real questions from this free bank, with full explanations. Use the practice tool above for the whole set.

  1. 1. Security and Risk Management

    An ISC2-certified security manager learns that another ISC2 member at a partner firm has falsified audit evidence. Under the ISC2 Code of Ethics, what is the manager obligated to do?

    • a.Follow the ISC2 ethics complaint procedure
    • b.Warn the member privately only
    • c.Notify only the member's employer
    • d.Wait for a client to report a loss

    Answer: a

    Explanation: The ISC2 Code of Ethics page states that members are obligated to follow the ethics complaint procedure upon observing any action by an ISC2 member that breaches the Code, and that failing to do so may itself breach Canon IV. A private warning or a report only to the employer does not meet that obligation, and nothing in the Code makes the duty wait for a client loss.

  2. 2. Security and Risk Management

    A risk assessment shows that a planned network link between a classified enclave and the corporate network creates risk above tolerance, and no practical safeguard exists. Management replaces the link with a manual, air-gapped transfer process. Which response is this?

    • a.Risk avoidance
    • b.Risk sharing
    • c.Risk transfer
    • d.Risk acceptance

    Answer: a

    Explanation: NIST SP 800-39 uses this very pattern as its example of risk avoidance: eliminating the networked connection and using an air gap with a manual transfer process when the risk exceeds tolerance. Acceptance would keep the link as is, and transfer or sharing would move liability or responsibility to another organization rather than removing the risky activity.

  3. 3. Asset Security

    An organization is ending a cloud storage contract and has no access to the provider's physical disks. Which purge technique does NIST SP 800-88 Rev. 2 note may be the only viable option for such logical storage?

    • a.Shredding
    • b.Cryptographic erase
    • c.Degaussing
    • d.Single-pass overwrite

    Answer: b

    Explanation: SP 800-88 Rev. 2 states that for logical or virtual storage such as cloud storage, cryptographic erase may be the only viable purge technique, because the data owner has no direct access to the underlying physical media. Degaussing and shredding require physical possession, and an overwrite through a virtual interface is a clear technique that does not reach the abstracted physical storage.

  4. 4. Security Architecture and Engineering

    A firewall appliance suffers a software fault. The design requires it to stop forwarding traffic rather than pass everything through unfiltered. Which design principle is being applied?

    • a.Privacy by design
    • b.Keep it simple and small
    • c.Shared responsibility
    • d.Fail securely

    Answer: d

    Explanation: NIST SP 800-53 Rev. 5 control SC-24 requires components to fail to an organization-defined known state so that failures do not cause loss of confidentiality, integrity or availability, which the ISC2 outline lists as the fail-securely principle. Simplicity reduces attack surface, shared responsibility divides duties between a cloud provider and customer, and privacy by design embeds privacy protections; none of them defines behavior on failure.

  5. 5. Communication and Network Security

    A router forwards packets between subnets by examining destination IP addresses. At which OSI layer does this forwarding decision take place?

    • a.Session layer (Layer 5)
    • b.Data link layer (Layer 2)
    • c.Network layer (Layer 3)
    • d.Transport layer (Layer 4)

    Answer: c

    Explanation: In the OSI reference model (ISO/IEC 7498-1) routing and logical addressing belong to the network layer, which is where IP operates. The data link layer handles frames and local hardware addressing within one link, the transport layer handles end-to-end delivery using ports, and the session layer manages dialogues between applications.

  6. 6. Communication and Network Security

    Users of a VoIP service report choppy audio even though average latency is low and no packets are lost. Which performance metric most likely explains this?

    • a.Bandwidth
    • b.Throughput
    • c.Jitter
    • d.Signal-to-noise ratio

    Answer: c

    Explanation: RFC 3393 defines IP packet delay variation, commonly called jitter, as the variation in delay between packets; real-time voice is sensitive to uneven arrival even when average delay is fine. Throughput and bandwidth describe how much data can move, and signal-to-noise ratio describes physical link quality that would normally show up as loss or errors.

  7. 7. Identity and Access Management (IAM)

    On a classified system, a document's owner tries to grant a colleague access, but the system refuses because the colleague's clearance does not match the document's label. Which access control model is in force?

    • a.Mandatory access control (MAC)
    • b.Risk-based access control
    • c.Rule-based access control
    • d.Discretionary access control (DAC)

    Answer: a

    Explanation: RFC 4949 defines mandatory access control as comparing security labels with clearances, and explains it is 'mandatory' because an entity cannot, by its own volition, enable another entity to access the resource. Under discretionary access control the owner could grant access at will, and rule-based and risk-based controls evaluate rules or risk signals rather than labels versus clearances.

  8. 8. Security Assessment and Testing

    A customer asks for assurance that a SaaS provider's security controls actually operated effectively over the past year, not just that they were well designed. Which report addresses this?

    • a.A SOC 2 Type 2 report
    • b.A penetration test summary from one week
    • c.A SOC 2 Type 1 report
    • d.The provider's own security policy

    Answer: a

    Explanation: Under the AICPA SOC framework, a Type 1 report covers the description of the system and the suitability of control design as of a point in time, while a Type 2 report also covers the operating effectiveness of the controls over a period. A policy document is a self-statement, and a one-week penetration test examines exploitable weaknesses rather than whether controls operated over a year.

  9. 9. Security Operations

    A junior administrator wants to power off a compromised server immediately so the attacker cannot do more damage, before any evidence is collected. What does RFC 3227 warn about this?

    • a.Volatile evidence can be lost
    • b.Shutting down resets the server's audit logs to empty
    • c.Shutting down automatically notifies law enforcement
    • d.Shutting down permanently encrypts the disk contents

    Answer: a

    Explanation: RFC 3227 advises not shutting down until evidence collection is complete, because volatile evidence may be lost and an attacker may have altered startup or shutdown scripts to destroy evidence; network isolation can contain the host while memory is preserved. Powering off does not notify authorities, encrypt disks by itself, or clear persistent logs.

  10. 10. Security Operations

    A trading firm cannot tolerate any meaningful downtime or data loss and has budget for the most capable recovery option. Which site type described in NIST SP 800-34 Rev. 1 fits?

    • a.A warm site with hardware but no current data
    • b.A mobile site delivered within 24 hours
    • c.A cold site with power and cooling ready
    • d.A mirrored site with real-time data mirroring

    Answer: d

    Explanation: SP 800-34 Rev. 1 describes mirrored sites as fully redundant facilities with automated real-time information mirroring, identical to the primary site, and notes they are the most expensive choice but ensure virtually 100 percent availability. Cold, mobile and warm sites all need time to acquire equipment, deliver the unit or load current data.

Own the complete CISSP — Certified Information Systems Security Professional guide — PDF + EPUB, $24.99 →

Report