ISC2 · CISSP

ISC2 CISSP Exam Practice Questions

484 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 484 questions in this pack

Question 1

Physical assets defined in an organization's business impact analysis (BIA) could include which of the following?

  1. Personal belongings of organizational staff members
  2. Disaster recovery (DR) line-item revenues
  3. Cloud-based applications
  4. Supplies kept off-site a remote facility
Show answer and explanation

Correct answer: D. Supplies kept off-site a remote facility

Physical assets in a BIA are tangible items the organization owns and needs to continue operations. Supplies kept at a remote facility are physical assets that support business continuity. Personal belongings are not organizational assets, DR revenues are financial metrics not physical assets, and cloud-based applications are logical/virtual assets, not physical ones.

Why the other options are wrong

  • A. Personal belongings belong to staff members, not the organization, and are not considered organizational assets in a BIA.
  • B. DR line-item revenues are financial projections or accounting entries, not physical assets.
  • C. Cloud-based applications are logical or virtual assets hosted remotely, not physical assets owned by the organization.

Question 2

When assessing the audit capability of an application, which of the following activities is MOST important?

  1. Identify procedures to investigate suspicious activity.
  2. Determine if audit records contain sufficient information.
  3. Verify if sufficient storage is allocated for audit records.
  4. Review security plan for actions to be taken in the event of audit failure.
Show answer and explanation

Correct answer: B. Determine if audit records contain sufficient information.

information. When assessing audit capability, the most critical activity is determining whether audit records contain sufficient information to support investigations and compliance. Sufficient information is foundational, without it, auditing is ineffective regardless of storage capacity or response procedures. While storage and procedures matter, the quality and completeness of logged data is the primary concern for audit effectiveness.

Why the other options are wrong

  • A. Investigating suspicious activity is a response action that comes after audit records are deemed adequate.
  • C. Storage allocation is important but secondary; inadequate storage becomes irrelevant if the records captured lack necessary detail.
  • D. Security plan responses to audit failures are important for incident management but don't directly assess whether current audit capability is sufficient.

Question 3

An organization would like to implement an authorization mechanism that would simplify the assignment of various system access permissions for many users with similar job responsibilities. Which type of authorization mechanism would be the BEST choice for the organization to implement?

  1. Role-based access control (RBAC)
  2. Discretionary access control (DAC)
  3. Content-dependent Access Control
  4. Rule-based Access Control
Show answer and explanation

Correct answer: A. Role-based access control (RBAC)

Role-based access control (RBAC) is specifically designed to simplify permission assignment by grouping users with similar job responsibilities into roles, then assigning permissions to those roles. This reduces administrative overhead and scales well. DAC places control with individual owners, content-dependent access is based on data sensitivity, and rule-based access uses conditional logic, none directly address simplifying bulk assignment for similar job roles.

Why the other options are wrong

  • B. Discretionary access control requires individual owners to manage permissions, making it less efficient for assigning permissions to many similar users.
  • C. Content-dependent access control bases decisions on data content characteristics, not user job responsibilities.
  • D. Rule-based access control applies conditional logic but doesn't inherently simplify group assignment by job role.

See all 10 free questions Get the full pack, US$39

484 practice questions for ISC2 Certified Information Systems Security Professional (CISSP), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 484 questions across all eight CISSP domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed CISSP attempt costs the full US$749 again, plus a 30-day wait before your next attempt. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 484 questions

What makes the CISSP hard

The CISSP uses Computerized Adaptive Testing: the exam adjusts to your performance in real time and ends anywhere between 100 and 150 questions, so you never know where you stand until it is over. You also need five years of paid security experience just to be eligible, which makes a failed attempt more than an expensive afternoon.

484 practice questions for the CISSP, in one place, so the question style is familiar before test day.

About the exam

The CISSP is the most widely recognised cybersecurity credential in the world. With over 165,000 holders globally, it validates expertise across eight domains of information security, from cryptography and network architecture to governance, risk management, and software security. It is required at DoD 8140 IAT Level III and IAM Levels II and III, and is the benchmark credential for security architects, CISOs and senior security management roles. Five years of paid security experience across at least two domains is required; candidates who pass before meeting the experience requirement become an Associate of ISC2 with up to six years to qualify.

Exam domains

  • Security and risk management: 16%
  • Asset security: 10%
  • Security architecture and engineering: 13%
  • Communication and network security: 13%
  • Identity and access management: 13%
  • Security assessment and testing: 12%
  • Security operations: 13%
  • Software development security: 10%

100 to 150 questions (CAT format), 3 hours, pass mark 700 out of 1000, US$749 per attempt, Pearson VUE testing centres or online proctored, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISC2 CISSP pack?

484 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.