10 free ISC2 CISSP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 484 questions. Work through them, then open each answer to check your reasoning.
Get all 484 questions (US$39) · Download these 10 as a PDF
Question 1
Physical assets defined in an organization's business impact analysis (BIA) could include which of the following?
Show answer and explanation
Correct answer: D. Supplies kept off-site a remote facility
Physical assets in a BIA are tangible items the organization owns and needs to continue operations. Supplies kept at a remote facility are physical assets that support business continuity. Personal belongings are not organizational assets, DR revenues are financial metrics not physical assets, and cloud-based applications are logical/virtual assets, not physical ones.
Why the other options are wrong
- A. Personal belongings belong to staff members, not the organization, and are not considered organizational assets in a BIA.
- B. DR line-item revenues are financial projections or accounting entries, not physical assets.
- C. Cloud-based applications are logical or virtual assets hosted remotely, not physical assets owned by the organization.
Question 2
When assessing the audit capability of an application, which of the following activities is MOST important?
Show answer and explanation
Correct answer: B. Determine if audit records contain sufficient information.
information. When assessing audit capability, the most critical activity is determining whether audit records contain sufficient information to support investigations and compliance. Sufficient information is foundational, without it, auditing is ineffective regardless of storage capacity or response procedures. While storage and procedures matter, the quality and completeness of logged data is the primary concern for audit effectiveness.
Why the other options are wrong
- A. Investigating suspicious activity is a response action that comes after audit records are deemed adequate.
- C. Storage allocation is important but secondary; inadequate storage becomes irrelevant if the records captured lack necessary detail.
- D. Security plan responses to audit failures are important for incident management but don't directly assess whether current audit capability is sufficient.
Question 3
An organization would like to implement an authorization mechanism that would simplify the assignment of various system access permissions for many users with similar job responsibilities.
Which type of authorization mechanism would be the BEST choice for the organization to implement?
Show answer and explanation
Correct answer: A. Role-based access control (RBAC)
Role-based access control (RBAC) is specifically designed to simplify permission assignment by grouping users with similar job responsibilities into roles, then assigning permissions to those roles. This reduces administrative overhead and scales well. DAC places control with individual owners, content-dependent access is based on data sensitivity, and rule-based access uses conditional logic, none directly address simplifying bulk assignment for similar job roles.
Why the other options are wrong
- B. Discretionary access control requires individual owners to manage permissions, making it less efficient for assigning permissions to many similar users.
- C. Content-dependent access control bases decisions on data content characteristics, not user job responsibilities.
- D. Rule-based access control applies conditional logic but doesn't inherently simplify group assignment by job role.
Question 4
What is the PRIMARY reason for criminal law being difficult to enforce when dealing with cybercrime?
Show answer and explanation
Correct answer: A. Jurisdiction is hard to define.
Jurisdiction is the primary challenge in cybercrime enforcement because attacks cross borders instantly, making it unclear which country's laws apply and which law enforcement agency has authority. This fundamental jurisdictional ambiguity complicates investigation, prosecution, and enforcement more than other factors. While understaffing, extradition, and language barriers exist, they are secondary issues compared to the core jurisdictional problem.
Why the other options are wrong
- B. Understaffing is a resource issue but not the primary structural reason criminal law is difficult to enforce in cybercrime.
- C. Extradition treaty enforcement is challenging but is a consequence of jurisdictional issues, not the primary reason.
- D. Language barriers exist but are manageable through translation and are not the fundamental obstacle to enforcement.
Question 5
Wi-Fi Protected Access 2 (WPA2) provides users with a higher level of assurance that their data will remain protected by using which protocol?
Show answer and explanation

Question 6
Which part of an operating system (OS) is responsible for providing security interfaces among the hardware, OS, and other parts of the computing system?
Show answer and explanation
Correct answer: D. Security kernel
The security kernel is the minimal subset of the operating system responsible for enforcing security policy and mediating all access to protected resources. It provides the security interfaces between hardware, the OS, and applications. While the reference monitor is a conceptual model for authorization decisions and the TCB includes all security-relevant components, the security kernel is the specific architectural component that implements these interfaces and protections at the OS level.
Why the other options are wrong
- A. The reference monitor is a conceptual model describing how access control should work, not the actual OS component providing the interfaces.
- B. The Trusted Computing Base is a broader concept encompassing all security- relevant components, not the specific architectural component providing interfaces.
- C. Time separation is a scheduling technique for isolating processes, not the component providing security interfaces among hardware, OS, and applications.
Question 7
What process facilitates the balance of operational and economic costs of protective measures with gains in mission capability?
Show answer and explanation
Correct answer: D. Risk management
Risk management is the process that systematically balances the costs of implementing protective security measures against the benefits and improvements to mission capability and operational resilience. It involves assessing risks, evaluating countermeasures, and making informed decisions about resource allocation for security controls. Performance testing measures capability, security audits evaluate compliance, and risk assessment is a component of risk management but not the overarching balancing process.
Why the other options are wrong
- A. Performance testing evaluates system or application capability but doesn't address the balance between security costs and mission gains.
- B. Risk assessment identifies and analyzes risks but is a component within risk management, not the overarching balancing process.
- C. Security audit evaluates compliance with policies and standards but doesn't directly balance protective costs with mission capability gains.
Question 8
Clothing retailer employees are provisioned with user accounts that provide access to resources at partner businesses. All partner businesses use common identity and access management (IAM) protocols and differing technologies. Under the Extended Identity principle, what is the process flow between partner businesses to allow this IAM action?
Show answer and explanation

Question 9
Which of the following statements BEST describes least privilege principle in a cloud environment?
Show answer and explanation
Correct answer: A. A single cloud administrator is configured to access core functions.
core functions. Least privilege grants each subject only the access needed for assigned duties. Limiting a cloud administrator account to the core functions the role requires, rather than broad or global privileges, applies that principle and limits damage from a compromised or misused account. The other choices describe traffic inspection, routing maintenance, and network design, not the permissions assigned to an identity.
Why the other options are wrong
- B. Inspecting all incoming and outgoing packets is monitoring and intrusion detection, not how permissions are assigned.
- C. Keeping routing configurations current is network maintenance and says nothing about restricting a subject's rights.
- D. Keeping segments private is network segmentation, a design control rather than a statement about permissions granted to users or accounts.
Question 10
An organization has been collecting a large amount of redundant and unusable data and filling up the storage area network (SAN). Management has requested the identification of a solution that will address ongoing storage problems.
Which is the BEST technical solution?
Show answer and explanation
Correct answer: D. Deduplication
Deduplication is the best solution for redundant and unusable data filling a SAN. It identifies and eliminates duplicate data blocks, storing only one copy and using pointers for references. This directly addresses the problem of redundant data consuming storage space while maintaining data availability and is more effective than compression for datasets with high redundancy.
Why the other options are wrong
- A. Compression reduces file size but doesn't eliminate redundant copies of the same data across the SAN.
- B. Caching improves performance for frequently accessed data but doesn't reduce overall storage consumption.
- C. Replication creates additional copies of data, which would worsen the storage problem rather than solve it.
That was 10 of 484.
The full ISC2 CISSP pack has all 484 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
