dc dotCreds
ISC2 CISSP Practice Test

CISSP Practice Test

Start today’s free 10-question CISSP set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 15, 2026, 12:15 AM CDT

Go Pro - One Time Unlock

Unlock the full CISSP bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CISSP questions

Use this CISSP practice test to review ISC2 Certified Information Systems Security Professional. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Select application security testing 8. Software Development Security (10%)

A cloud provider is implementing a new containerization strategy for its applications. The security team needs to determine the most appropriate security controls to ensure the containers are isolated and secure. Which approach best minimizes resource contention and ensures application isolation?

Concept tested:
Question 2 of 10
Objective Apply secure network architecture 4. Communication and Network Security (13%)

A company is implementing a secure network architecture to connect two geographically dispersed offices. They require a secure, encrypted connection for all data transmitted between the offices. Which solution best meets this requirement?

Concept tested:
Question 3 of 10
Objective Identify and classify information and assets 2. Asset Security (10%)

A system administrator discovers that a newly implemented data aggregation process is generating security impact levels higher than initially anticipated. Review of the individual information types reveals no significant changes in sensitivity. Considering the potential impact of compromised systems and dependent systems, what action should the administrator take to align the system security objective impact levels with the aggregated data’s risk profile?

Concept tested:
Question 4 of 10
Objective Manage identification and authentication 5. Identity and Access Management (13%)

A financial institution is implementing a new online banking service. The service handles sensitive account information and requires user authentication. A risk assessment identifies that a compromise of authentication could lead to significant financial loss and reputational damage. According to identity assurance level guidelines, what is the appropriate initial assurance level to select for this service?

Concept tested:
Question 5 of 10
Objective Apply cryptographic solutions 3. Security Architecture and Engineering (13%)

A company is implementing a key management system. They utilize a key-encrypting key to protect other cryptographic keys. The key inventory shows this key-encrypting key has an expiration date approaching. What is the most appropriate action to ensure continued confidentiality protection of the protected keys?

Concept tested:
Question 6 of 10
Objective Design assessment strategies 6. Security Assessment and Testing (12%)

A system owner presents an assessment report to the authorizing official, referencing findings from a previous assessment of a common control. The system owner claims the previous assessment is still valid. Before approving the current assessment, what is the authorizing official's PRIMARY responsibility?

Concept tested:
Question 7 of 10
Objective Manage logging and monitoring 7. Security Operations (13%)

During a security assessment, an analyst discovers that a log source offers limited configuration options, only allowing for simple enable/disable functionality. What is the most prudent approach for the administrator to take when configuring this log source for an environment where granular logging is required?

Concept tested:
Question 8 of 10
Objective Develop security policy and awareness 1. Security and Risk Management (16%)

A system owner is receiving an authorization package. According to organizational policy, what is the correct procedure for handling the authorization decision document?

Concept tested:
Question 9 of 10
Objective Control physical and logical access 5. Identity and Access Management (13%)

During enrollment for an authenticator application, the identity team must ensure that future codes are accepted only for the employee who registered that authenticator. Which control most directly creates this trusted relationship?

Concept tested:
Question 10 of 10
Objective Apply key decisions 3. Security Architecture and Engineering (13%)

A system utilizes a symmetric key-wrapping key to protect keying material transmitted between two systems. The key-wrapping key is lost. Given the scenario, what is the recommended approach to ensure continued secure transmission of the keying material?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CISSP Pro $4.99 one-time

Unlock all 200 CISSP questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CISSP PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CISSP bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CISSP practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CISSP set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A cloud provider is implementing a new containerization strategy for its applications. The security team needs to determine the most appropriate security controls to ensure the containers are isolated and secure. Which approach best minimizes resource contention and ensures application isolation?

Answer choices

  1. A. Implement network segmentation to isolate container networks.
  2. B. Utilize a container runtime with robust resource limits.
  3. C. Employ a container-specific operating system with minimal components.
  4. D. Conduct regular vulnerability scans of the host operating system.

Correct answer

Employ a container-specific operating system with minimal components.

Containerization offers application isolation and resource efficiency, and a container-specific operating system minimizes the attack surface. This approach reduces the risk of vulnerabilities and resource contention by limiting the components present.

Wrong-answer review

  • A. Implement network segmentation to isolate container networks.: Network segmentation primarily addresses network-level security, not the isolation of container resources.
  • B. Utilize a container runtime with robust resource limits.: Container runtimes manage resource limits but don't inherently provide the isolation of a specialized OS.
  • D. Conduct regular vulnerability scans of the host operating system.: Host OS scans don't directly address container isolation; they focus on the underlying infrastructure.

Extra learning features

Why candidates miss this

The choice of 'Implement network segmentation to isolate container networks' is tempting because it's a common networking security practice. However, network segmentation primarily addresses network-level security, not the isolation of container resources. Likely wrong answer: Implement network segmentation to isolate container networks. Review focus: Application Container Security Guide (NIST SP 800-190)

Interview question

Q: How do container design choices affect isolation, resource contention, and attack surface, and what controls would you prioritize? Strong answer: Containerization offers application isolation and resource efficiency, and a container-specific operating system minimizes the attack surface. This approach reduces the risk of vulnerabilities and resource contention by limiting the components present.

  • containerization
  • application isolation
  • resource efficiency
  • attack surface
  • container-specific operating system

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: 8. Software Development Security (10%)

Source: Application Container Security Guide (NIST SP 800-190)

Question 2 A company is implementing a secure network architecture to connect two geographically dispersed offices. They require a secure, encrypted connection for all data transmitted between the offices. Which solution best meets this requirement?

Answer choices

  1. A. Establish a gateway-to-gateway IPsec-based VPN.
  2. B. Deploy a host-based firewall on each server.
  3. C. Implement a wireless network with WPA2-Enterprise encryption.
  4. D. Utilize a cloud-based file sharing service with strong access controls.

Correct answer

Establish a gateway-to-gateway IPsec-based VPN.

Objective/domain: 4. Communication and Network Security (13%)

Source: Guide to IPsec VPNs (NIST SP 800-77 Rev. 1)

Question 3 A system administrator discovers that a newly implemented data aggregation process is generating security impact levels higher than initially anticipated. Review of the individual information types reveals no significant changes in sensitivity. Considering the potential impact of compromised systems and dependent systems, what action should the administrator take to align the system security objective impact levels with the aggregated data’s risk profile?

Answer choices

  1. A. Adjust the system security objective impact levels to a higher level, documenting the aggregation and its potential security impact.
  2. B. Implement a new security policy mandating immediate isolation of the aggregated data.
  3. C. Conduct a full vulnerability scan of all systems connected to the aggregated data.
  4. D. Revert to the original data classification scheme and discontinue the aggregation process.

Correct answer

Adjust the system security objective impact levels to a higher level, documenting the aggregation and its potential security impact.

Question 4 A financial institution is implementing a new online banking service. The service handles sensitive account information and requires user authentication. A risk assessment identifies that a compromise of authentication could lead to significant financial loss and reputational damage. According to identity assurance level guidelines, what is the appropriate initial assurance level to select for this service?

Answer choices

  1. A. AAL2
  2. B. AAL1
  3. C. AAL3
  4. D. AAL4

Correct answer

AAL2

Objective/domain: 5. Identity and Access Management (13%)

Source: Digital Identity Guidelines (NIST SP 800-63-4)

Question 5 A company is implementing a key management system. They utilize a key-encrypting key to protect other cryptographic keys. The key inventory shows this key-encrypting key has an expiration date approaching. What is the most appropriate action to ensure continued confidentiality protection of the protected keys?

Answer choices

  1. A. Terminate the key-encrypting key and generate a new one.
  2. B. Extend the expiration date of the key-encrypting key.
  3. C. Ignore the expiration date and continue using the key-encrypting key.
  4. D. Implement a key transport mechanism to securely replace the key-encrypting key.

Correct answer

Implement a key transport mechanism to securely replace the key-encrypting key.

Objective/domain: 3. Security Architecture and Engineering (13%)

Source: Recommendation for Key Management: Part 1 (NIST SP 800-57 Part 1 Rev. 5)

Question 6 A system owner presents an assessment report to the authorizing official, referencing findings from a previous assessment of a common control. The system owner claims the previous assessment is still valid. Before approving the current assessment, what is the authorizing official's PRIMARY responsibility?

Answer choices

  1. A. Rejecting the assessment report due to the reliance on prior findings.
  2. B. Automatically accepting the findings as valid, given the previous assessment.
  3. C. Requiring a completely new assessment, disregarding any prior assessment data.
  4. D. Verifying the applicability and credibility of the previous assessment with relevant stakeholders.

Correct answer

Verifying the applicability and credibility of the previous assessment with relevant stakeholders.

Question 7 During a security assessment, an analyst discovers that a log source offers limited configuration options, only allowing for simple enable/disable functionality. What is the most prudent approach for the administrator to take when configuring this log source for an environment where granular logging is required?

Answer choices

  1. A. Immediately disable the log source to prevent potential data leakage.
  2. B. Configure the log source to log all events, regardless of the level of detail, to ensure comprehensive coverage.
  3. C. Implement a secondary log source with more granular configuration options to supplement the existing log source.
  4. D. Accept the limitations of the log source and focus on configuring other log sources to provide the desired level of detail.

Correct answer

Configure the log source to log all events, regardless of the level of detail, to ensure comprehensive coverage.

Objective/domain: 7. Security Operations (13%)

Source: Guide to Computer Security Log Management (NIST SP 800-92)

Question 8 A system owner is receiving an authorization package. According to organizational policy, what is the correct procedure for handling the authorization decision document?

Answer choices

  1. A. Immediately distribute the document to all system users for review.
  2. B. Transmit the authorization decision and authorization package to the system owner or common control provider.
  3. C. Store the document in a central repository for easy access.
  4. D. Archive the document after a brief period of review by the system owner.

Correct answer

Transmit the authorization decision and authorization package to the system owner or common control provider.

Objective/domain: 1. Security and Risk Management (16%)

Source: Risk Management Framework for Information Systems and Organizations (NIST SP 800-37 Rev. 2)

Question 9 During enrollment for an authenticator application, the identity team must ensure that future codes are accepted only for the employee who registered that authenticator. Which control most directly creates this trusted relationship?

Answer choices

  1. A. Associate the registered authenticator with the verified employee account during enrollment.
  2. B. Store the employee's ordinary password inside the authenticator application.
  3. C. Treat any valid-looking code as sufficient without checking its registered owner.
  4. D. Use the generated code as a permanent replacement for the employee identity record.

Correct answer

Associate the registered authenticator with the verified employee account during enrollment.

Objective/domain: 5. Identity and Access Management (13%)

Source: Digital Identity Guidelines (NIST SP 800-63-4)

Question 10 A system utilizes a symmetric key-wrapping key to protect keying material transmitted between two systems. The key-wrapping key is lost. Given the scenario, what is the recommended approach to ensure continued secure transmission of the keying material?

Answer choices

  1. A. C. Generate a new key-wrapping key and instruct both systems to use the new keying material to re-encrypt the keying material.
  2. B. B. Resend the key-wrapping key to both systems and re-encrypt the keying material.
  3. C. A. Immediately archive the original key-wrapping key for future reference.
  4. D. D. Ignore the loss and continue using the previously transmitted keying material.

Correct answer

C. Generate a new key-wrapping key and instruct both systems to use the new keying material to re-encrypt the keying material.

Objective/domain: 3. Security Architecture and Engineering (13%)

Source: Recommendation for Key Management: Part 1 (NIST SP 800-57 Part 1 Rev. 5)

Where to go after the daily web set

How are CISSP questions generated?

dotCreds builds CISSP practice questions from public exam objectives and ISC2 exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CISSP practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.