ISC2 · CISSP-ISSEP

ISC2 CISSP-ISSEP Exam Practice Questions

214 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 214 questions in this pack

Question 1

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems.

Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed

  1. Level 4
  2. Level 5
  3. Level 1
  4. Level 2
  5. Level 3
Show answer and explanation

Correct answer: A. Level 4

FITSAF Level 4 is the stage at which procedures and controls are tested and reviewed, confirming that what was implemented actually works as intended. The five FITSAF levels progress from documented policy, to documented procedures, to implemented procedures and controls, to tested and reviewed procedures and controls, and finally to fully integrated procedures and controls. Testing and formal review are the defining activities of Level 4.

Why the other options are wrong

  • B. Level 5 is where procedures and controls are fully integrated into a comprehensive program, which comes after testing and review.
  • C. Level 1 means only that a security policy is documented.
  • D. Level 2 means that procedures supporting the policy are documented, with no implementation or testing yet.
  • E. Level 3 means the documented procedures and controls have been implemented, but not yet tested and reviewed.

Question 2

Which of the following is a type of security management for computers and networks in order to identify security breaches

  1. IPS
  2. IDS
  3. ASA
  4. EAP
Show answer and explanation

Correct answer: B. IDS

IDS (Intrusion Detection System) is a security management tool designed to identify and alert on security breaches by monitoring network traffic and system activity for suspicious patterns and signatures that indicate unauthorized access or attacks.

Why the other options are wrong

  • A. IPS (Intrusion Prevention System) goes beyond detection to actively block threats, but the question specifically asks for identification of breaches.
  • C. ASA (Adaptive Security Appliance) is a firewall and VPN device that provides perimeter security but is not primarily designed for breach detection.
  • D. EAP (Extensible Authentication Protocol) is an authentication framework for network access control, not for identifying security breaches.

Question 3

Which of the following types of firewalls increases the security of data packets by remembering the state of connection at the network and the session layers as they pass through the filter

  1. Stateless packet filter firewall
  2. PIX firewall
  3. Stateful packet filter firewall
  4. Virtual firewall
Show answer and explanation

Correct answer: C. Stateful packet filter firewall

A stateful packet filter firewall maintains awareness of the state of network connections and remembers the context of data flows passing through it at both the network and session layers. This allows it to make intelligent decisions about whether packets belong to legitimate established connections, providing enhanced security over simple packet filtering.

Why the other options are wrong

  • A. Stateless packet filter firewalls do not track connection state; they examine each packet independently.
  • B. PIX firewall is a specific Cisco appliance that can be stateful, but it is not the general category describing state-tracking firewalls.
  • D. Virtual firewalls are deployed in virtualized environments but are not specifically defined by their ability to track connection state.

See all 10 free questions Get the full pack, US$39

214 practice questions for ISC2 Information Systems Security Engineering Professional (CISSP-ISSEP), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 214 questions mapped to the ISSEP exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

An ISSEP attempt costs US$599. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 214 questions

What makes the ISSEP hard

ISSEP is the systems engineering concentration: CISSP knowledge poured into the NIST flavoured mould of formal security engineering, and it reads unlike any other ISC2 exam.

It covers security engineering across the full system lifecycle, requirements decomposition and trade studies, risk management framed the RMF and 800-160 way, verification and validation of controls, and secure operations through change management and disposal. Practitioners from agile shops often struggle with the formal process framing, since the exam wants the engineering discipline answer, artefacts included.

The weighting is deliberately front loaded: engineering foundations is the single largest domain at 24%, with planning and engineering at 22% and risk management and implementation, verification at 20% each. Only disposal and change management is light at 14%. This pack has 214 practice questions for the ISSEP.

About the exam

CISSP-ISSEP certifies security systems engineering as a CISSP concentration: engineering principles across the lifecycle, risk management, security planning and engineering, implementation, verification and validation, and secure operations and disposal. It requires a CISSP in good standing plus 2 years of engineering experience. The current exam outline is effective from 1 August 2025, and it is maintained under the CISSP CPE cycle.

Exam domains

  • Systems security engineering foundations: 24%
  • Risk management: 20%
  • Security planning and engineering: 22%
  • Systems security implementation, verification, and validation: 20%
  • Secure operations, change management, and disposal: 14%

125 questions, 3 hours, multiple choice and advanced item types, pass mark 700 out of 1000, US$599 per attempt, Pearson VUE test centres.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISC2 CISSP-ISSEP pack?

214 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.