ISC2 · CISSP-ISSMP

ISC2 CISSP-ISSMP Exam Practice Questions

218 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 218 questions in this pack

Question 1

Which of the following fields of management focuses on establishing and maintaining consistency of a system's or product's performance and its functional and physical attributes with its requirements, design, and operational information throughout its life?

  1. Configuration management
  2. Risk management
  3. Procurement management
  4. Change management
Show answer and explanation

Correct answer: A. Configuration management

Configuration management is the discipline that establishes and maintains consistency of a system's or product's performance, functional attributes, and physical attributes with its requirements, design, and operational information throughout its lifecycle. This involves tracking, documenting, and controlling all changes to the system's configuration items.

Why the other options are wrong

  • B. Risk management focuses on identifying, analyzing, and mitigating risks, not maintaining system consistency.
  • C. Procurement management deals with acquiring goods and services from external sources.
  • D. Change management controls the implementation of changes to systems but does not establish the baseline consistency.

Question 2

Which of the following are the ways of sending secure e-mail messages over the Internet? Each correct answer represents a complete solution. Choose two.

  1. TLS
  2. PGP
  3. S/MIME
  4. IPSec
Show answer and explanation

Correct answer: B, C

B. PGP C. S/MIME PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose Internet Mail Extensions) are complete end-to-end solutions for securing email messages. Both provide encryption and digital signature capabilities for email. TLS secures the transport channel between mail servers but not the message itself, and IPSec operates at the network layer rather than providing email-specific security.

Why the other options are wrong

  • A. TLS secures the connection between mail servers during transmission but does not provide end-to-end message encryption.
  • D. IPSec is a network-layer security protocol used for VPNs and network communication, not specifically for email security.

Question 3

You work as a Senior Marketing Manger for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote desktop session. You suspected that some malicious attack was performed on the network of the company. You immediately called the incident response team to handle the situation who enquired the Network Administrator to acquire all relevant information regarding the malfunctioning. The Network Administrator informed the incident response team that he was reviewing the security of the network which caused all these problems. Incident response team announced that this was a controlled event not an incident. Which of the following steps of an incident handling process was performed by the incident response team?

  1. Containment
  2. Eradication
  3. Preparation
  4. Identification
Show answer and explanation

Correct answer: D. Identification

The Identification phase is where the incident response team determines whether an event is actually a security incident or a controlled, legitimate activity. In this scenario, the incident response team identified that the Network Administrator's security review was a controlled event, not a malicious incident. This classification decision is the core function of the Identification step.

Why the other options are wrong

  • A. Containment involves stopping the attack and limiting its impact, which was not performed here.
  • B. Eradication involves removing malware or unauthorized access, which was not needed since this was a controlled event.
  • C. Preparation involves establishing tools, processes, and readiness before an incident occurs.

See all 10 free questions Get the full pack, US$39

218 practice questions for ISC2 Information Systems Security Management Professional (CISSP-ISSMP), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 218 questions mapped to the ISSMP exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

An ISSMP attempt costs US$599. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 218 questions

What makes the ISSMP hard

ISSMP is the CISSP concentration for people running the security programme rather than the firewall, and it leans even further into management judgement than the CISSP already does.

The exam lives at the leadership layer: aligning the security programme to business strategy, lifecycle and vendor management, risk decisions framed as trade-offs, security operations and incident management from the coordinator’s chair, and contingency planning including BIA, RTO and RPO and exercise types. The classic ISC2 trap intensifies here, where every option is defensible and the scored one is whatever the accountable manager does first.

Leadership and risk carry the exam: leadership and organisational management is 21% and risk management 20%, with security operations at 18%, roughly 60% of the paper before reaching lifecycle, contingency or compliance. This pack has 218 practice questions for the ISSMP.

About the exam

CISSP-ISSMP certifies security leadership and programme management as a CISSP concentration: leadership and organisational management, systems lifecycle management, risk, security operations, contingency management, and law, ethics and compliance. It requires a CISSP in good standing plus 2 years of management experience, and is maintained under the CISSP CPE cycle.

Exam domains

  • Leadership and organizational management: 21%
  • Systems lifecycle management: 15%
  • Risk management: 20%
  • Security operations: 18%
  • Contingency management: 12%
  • Law, ethics, and security compliance management: 14%

125 questions, 3 hours, multiple choice and advanced item types, pass mark 700 out of 1000, US$599 per attempt, Pearson VUE test centres.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISC2 CISSP-ISSMP pack?

218 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.