dc dotCreds
ISC2 CISSP Practice Test

CISSP Practice Test

Start today’s free 10-question CISSP set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CISSP bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CISSP questions

Use this CISSP practice test to review ISC2 Certified Information Systems Security Professional. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Apply recovery strategies 7. Security Operations (13%)

A financial institution is developing its information system contingency plan. During the business impact analysis, the IT department identifies that a 72-hour outage of the core banking system would result in an estimated loss of $5 million per day due to inability to process transactions. Considering the seven steps of information system contingency planning, what is the most critical immediate action the institution should undertake to mitigate this risk?

Concept tested:
Question 2 of 10
Objective Establish handling requirements 2. Asset Security (10%)

An organization is implementing a media disposition process for sensitive data. After sanitizing storage media, the organization must ensure the data is irrecoverable. What is the PRIMARY action that should be taken to maintain data integrity and demonstrate compliance?

Concept tested:
Question 3 of 10
Objective Apply cryptographic solutions 3. Security Architecture and Engineering (13%)

An organization uses a symmetric authentication key alongside a symmetric data encryption/decryption key. The organization’s security policy mandates the use of a single key for both authentication and encryption. What key type should be utilized?

Concept tested:
Question 4 of 10
Objective Apply software security controls 8. Software Development Security (10%)

A software development organization is establishing a Secure Development Lifecycle (SDLC) program. Which foundational element, as defined by the Secure Software Development Framework (SSDF), is most critical for ensuring the organization’s preparedness to perform secure software development activities?

Concept tested:
Question 5 of 10
Objective Manage identification and authentication 5. Identity and Access Management (13%)

A financial institution is implementing a new online banking service. The service handles sensitive account information and requires user authentication. A risk assessment identifies that a compromise of authentication could lead to significant financial loss and reputational damage. According to identity assurance level guidelines, what is the appropriate initial assurance level to select for this service?

Concept tested:
Question 6 of 10
Objective Design assessment strategies 6. Security Assessment and Testing (12%)

An organization is updating its security assessment report. Previous assessments contain valuable information. What is the most critical factor when incorporating this prior data?

Concept tested:
Question 7 of 10
Objective Apply incident management 7. Security Operations (13%)

A response team has contained a suspected malware incident but lacks enough evidence to decide when recovery should begin. Investigators must support forensics and recovery by establishing what occurred and why. Which analysis should they perform next?

Concept tested:
Question 8 of 10
Objective Apply risk management 1. Security and Risk Management (16%)

An organization's risk assessment process identifies a critical system, responsible for processing payroll data, as vulnerable to a newly identified ransomware threat. The system's compromise could result in significant financial loss and reputational damage. To ensure ongoing risk mitigation, what is the most effective approach?

Concept tested:
Question 9 of 10
Objective Apply secure network architecture 4. Communication and Network Security (13%)

An organization is designing its network security architecture and needs to implement firewall policies. Which statement best describes the primary purpose of a firewall policy regarding network traffic?

Concept tested:
Question 10 of 10
Objective Apply data protection methods 2. Asset Security (10%)

An organization is assessing the data protection level for a system containing classified information. The system employs strong encryption and access controls. Considering the complementary nature of data protection and organizational controls, what is the most appropriate conclusion?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CISSP Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CISSP PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISC2 Bundle $9.99 one-time

Unlock all 4 active ISC2 Bundle practice banks in one permanent purchase.

What’s includedISC2 CC, ISC2 SSCP, ISC2 CCSP, ISC2 CISSP
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CISSP bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CISSP practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CISSP set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A financial institution is developing its information system contingency plan. During the business impact analysis, the IT department identifies that a 72-hour outage of the core banking system would result in an estimated loss of $5 million per day due to inability to process transactions. Considering the seven steps of information system contingency planning, what is the most critical immediate action the institution should undertake to mitigate this risk?

Answer choices

  1. A. Implement robust preventative controls to minimize the likelihood of system failures, within the defined security and accountability boundaries.
  2. B. Conduct a thorough risk assessment to identify potential disruptions and vulnerabilities, under the stated decision criteria.
  3. C. Develop the Information System Contingency Plan (ISCP) focusing on immediate recovery strategies, within the defined security and accountability boundaries.
  4. D. Train personnel on the ISCP and conduct initial testing exercises, for the required business outcome.

Correct answer

Develop the Information System Contingency Plan (ISCP) focusing on immediate recovery strategies, within the defined security and accountability boundaries.

Information system contingency planning focuses on recovering systems and data after a disruption, following a structured seven-step process. Prioritizing the ISCP development ensures immediate recovery strategies are in place to mitigate potential financial losses.

Wrong-answer review

  • A. Implement robust preventative controls to minimize the likelihood of system failures, within the defined security and accountability boundaries.: Implementing preventative controls is a long-term strategy and doesn't address the immediate need for recovery planning.
  • B. Conduct a thorough risk assessment to identify potential disruptions and vulnerabilities, under the stated decision criteria.: A risk assessment is a necessary step, but it doesn't provide the immediate recovery actions required.
  • D. Train personnel on the ISCP and conduct initial testing exercises, for the required business outcome.: Training and testing are important, but they come after the plan itself is developed and in place.

Extra learning features

Why candidates miss this

The distractor ‘Implement robust preventative controls to minimize the likelihood of system failures’ is tempting because it addresses a general security concern. However, it doesn’t directly tackle the immediate, time-sensitive issue of recovering from a known outage. The decisive clue is the specific timeframe (72 hours) and the associated financial loss, which necessitates a focused recovery plan. Likely wrong answer: Implement robust preventative controls to minimize the likelihood of system failures Review focus: Contingency Planning Guide for Federal Information Systems (NIST SP 800-34 Rev. 1)

Why this matters

Understanding the immediate financial impact of a 72-hour outage—$5 million per day—highlights the critical need for rapid recovery strategies. Implementing a robust ISCP, as the question requires, directly addresses this risk by establishing a framework for minimizing downtime and financial losses, ensuring business continuity and protecting the institution's reputation. This causal chain emphasizes the importance of proactive planning in mitigating potential disasters.

Objective/domain: 7. Security Operations (13%)

Source: Contingency Planning Guide for Federal Information Systems (NIST SP 800-34 Rev. 1)

Question 2 An organization is implementing a media disposition process for sensitive data. After sanitizing storage media, the organization must ensure the data is irrecoverable. What is the PRIMARY action that should be taken to maintain data integrity and demonstrate compliance?

Answer choices

  1. A. Immediately shred the media and dispose of it in a secure landfill, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.
  2. B. Apply a new marking indicating the updated confidentiality level, unless the device is leaving the organization and is stored in a location where access is carefully controlled until the device leaves the organization to prevent reintroduction of sensitive data, under the organization’s defined implementation and exception-management process.
  3. C. Maintain detailed records of the sanitization process, including the method used, personnel involved, and verification results, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, for the stated requirement.
  4. D. Return the media to the original vendor for refurbishment and reuse, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, as the recommended response to this scenario.

Correct answer

Maintain detailed records of the sanitization process, including the method used, personnel involved, and verification results, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements, for the stated requirement.

Objective/domain: 2. Asset Security (10%)

Source: Guidelines for Media Sanitization (NIST SP 800-88 Rev. 1)

Question 3 An organization uses a symmetric authentication key alongside a symmetric data encryption/decryption key. The organization’s security policy mandates the use of a single key for both authentication and encryption. What key type should be utilized?

Answer choices

  1. A. A public signature-verification key, as configured.
  2. B. A symmetric authentication key, for the affected environment.
  3. C. A public ephemeral key-agreement key, for the specified implementation requirement.
  4. D. A symmetric data encryption/decryption key, for the stated requirement.

Correct answer

A symmetric data encryption/decryption key, for the stated requirement.

Objective/domain: 3. Security Architecture and Engineering (13%)

Source: Recommendation for Key Management: Part 1 (NIST SP 800-57 Part 1 Rev. 5)

Question 4 A software development organization is establishing a Secure Development Lifecycle (SDLC) program. Which foundational element, as defined by the Secure Software Development Framework (SSDF), is most critical for ensuring the organization’s preparedness to perform secure software development activities?

Answer choices

  1. A. Conducting regular security awareness training for all software developers, for the described technical objective and its associated operational control requirements, in the described situation.
  2. B. Establishing a formal vulnerability disclosure program for external researchers, as the selected approach for the stated technical and business outcome, for this task.
  3. C. Implementing a strict change management process for all software releases, as the selected approach for the stated technical and business outcome.
  4. D. Ensuring that the organization’s people, processes, and technology are prepared to perform secure software development at the organization level, under the documented operational and governance requirements.

Correct answer

Ensuring that the organization’s people, processes, and technology are prepared to perform secure software development at the organization level, under the documented operational and governance requirements.

Objective/domain: 8. Software Development Security (10%)

Source: Secure Software Development Framework (NIST SP 800-218)

Question 5 A financial institution is implementing a new online banking service. The service handles sensitive account information and requires user authentication. A risk assessment identifies that a compromise of authentication could lead to significant financial loss and reputational damage. According to identity assurance level guidelines, what is the appropriate initial assurance level to select for this service?

Answer choices

  1. A. AAL2, under this approach.
  2. B. AAL1
  3. C. AAL3, in practice.
  4. D. AAL4, for the affected environment.

Correct answer

AAL2, under this approach.

Objective/domain: 5. Identity and Access Management (13%)

Source: Digital Identity Guidelines (NIST SP 800-63-4)

Question 6 An organization is updating its security assessment report. Previous assessments contain valuable information. What is the most critical factor when incorporating this prior data?

Answer choices

  1. A. Ensuring the information remains relevant to the current system environment and risk profile.
  2. B. Prioritizing assessments based on the assessor's personal preference, as the selected response to the described condition.
  3. C. Including all previous assessment data regardless of its applicability, as the primary proposed approach.
  4. D. Focusing solely on the most recent assessment to ensure accuracy, for the specified implementation requirement.

Correct answer

Ensuring the information remains relevant to the current system environment and risk profile.

Question 7 A response team has contained a suspected malware incident but lacks enough evidence to decide when recovery should begin. Investigators must support forensics and recovery by establishing what occurred and why. Which analysis should they perform next?

Answer choices

  1. A. Restore all systems immediately without considering operational disruption, under this approach.
  2. B. Calculate financial loss before preserving the incident timeline, for evaluation.
  3. C. Determine the event sequence, involved assets, and root cause, for the specified implementation requirement.
  4. D. Close the investigation once containment has succeeded, for the specified implementation requirement.

Correct answer

Determine the event sequence, involved assets, and root cause, for the specified implementation requirement.

Question 8 An organization's risk assessment process identifies a critical system, responsible for processing payroll data, as vulnerable to a newly identified ransomware threat. The system's compromise could result in significant financial loss and reputational damage. To ensure ongoing risk mitigation, what is the most effective approach?

Answer choices

  1. A. Immediately implement a compensating control without further analysis, as the primary proposed approach.
  2. B. Conduct a full system rebuild to eliminate the potential threat, for review.
  3. C. Document the vulnerability and accept the associated risk, within the documented operational, security, ownership, and validation requirements.
  4. D. Update the system's security baseline and schedule a follow-up assessment, under organization-wide implementation-governance requirements.

Correct answer

Update the system's security baseline and schedule a follow-up assessment, under organization-wide implementation-governance requirements.

Objective/domain: 1. Security and Risk Management (16%)

Source: Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1)

Question 9 An organization is designing its network security architecture and needs to implement firewall policies. Which statement best describes the primary purpose of a firewall policy regarding network traffic?

Answer choices

  1. A. To allow all network traffic to pass through the firewall without any restrictions, within the defined security and accountability boundaries.
  2. B. To automatically detect and block all malicious network traffic, for the described technical objective and its associated operational control requirements, for this task.
  3. C. To define how the firewall should handle inbound and outbound network traffic based on security requirements, for consideration.
  4. D. To prioritize network traffic based on user-defined policies, as the selected response to the described condition.

Correct answer

To define how the firewall should handle inbound and outbound network traffic based on security requirements, for consideration.

Objective/domain: 4. Communication and Network Security (13%)

Source: Guidelines on Firewalls and Firewall Policy (NIST SP 800-41 Rev. 1)

Question 10 An organization is assessing the data protection level for a system containing classified information. The system employs strong encryption and access controls. Considering the complementary nature of data protection and organizational controls, what is the most appropriate conclusion?

Answer choices

  1. A. The data protection level should be assessed based on the potential impact of a compromise, under this approach.
  2. B. The data protection level should remain at the base level due to the existing controls, as described.
  3. C. The data protection level should be increased to reflect the enhanced controls, as the recommended response to this scenario.
  4. D. The data protection level should be determined solely by the organizational control measures, under the documented operational and governance requirements.

Correct answer

The data protection level should be assessed based on the potential impact of a compromise, under this approach.

Objective/domain: 2. Asset Security (10%)

Source: Guidelines for Media Sanitization (NIST SP 800-88 Rev. 1)

Where to go after the daily web set

How are CISSP questions generated?

dotCreds builds CISSP practice questions from public exam objectives and ISC2 exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CISSP practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.