Practice CISSP Security Operations questions with full explanations on every answer.
Start practicing
Security Operations — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?
2A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?
3Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
4A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?
5An organization's data loss prevention (DLP) solution is configured to block emails containing credit card numbers. This is an example of which type of DLP control?
6During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
7Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?
8An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?
9What is the PRIMARY purpose of a chain of custody in digital forensics?
10A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?
11An organization is recovering from a ransomware attack that encrypted critical servers. The backup strategy must ensure that the Recovery Point Objective (RPO) of 1 hour is met. Which backup method is MOST appropriate?
12An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?
13A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?
14An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?
15During a digital forensics investigation, a security analyst must preserve evidence in order of volatility. Which of the following represents the correct sequence from most volatile to least volatile?
16A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?
17A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?
18Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?
19A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?
20Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?
21A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
22An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?
23Which digital forensics tool is specifically designed for memory forensics?
24What is the primary purpose of a Change Advisory Board (CAB) in change management?
25An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)
26A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)
27Which of the following best describes the primary purpose of an incident response plan?
28During a digital forensics investigation, which of the following data sources has the highest order of volatility?
29An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?
30Which of the following is the primary purpose of a Change Advisory Board (CAB)?
31What type of DLP system monitors data in motion across the network?
32An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?
33During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?
34An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?
35Which of the following is an example of a social engineering attack?
36An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?
37Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?
38A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?
39A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)
40An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)
41An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?
42During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?
43An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?
44A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?
45Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?
46A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?
47Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
48A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?
49During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?
50A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?
51A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?
The Security Operations domain covers the key concepts tested in this area of the CISSP exam blueprint published by ISC2. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CISSP domains — no account required.
The Courseiva CISSP question bank contains 51 questions in the Security Operations domain, covering the 13% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Operations domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included