(ISC)² · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Your organization uses a 'Warm Site' for its disaster recovery strategy. During a recent audit, you find that the site lacks the necessary bandwidth to support peak production traffic. What is the most appropriate management response?
Cancel the warm site contract and build a cold site.
Require all employees to work from home during a disaster to save bandwidth.
Accept the risk formally via the Risk Register without further mitigation.
Update the DRP to include a 'throttling' policy for non-critical services during failover.
Managing capacity through service degradation is a legitimate risk mitigation strategy when infrastructure is limited.
Following a ransomware attack, the organization must decide whether to invoke the DRP or remain in a degraded state while security teams perform forensics. What is the ISSMP's primary responsibility in this decision-making process?
Choosing the restore point from the offsite immutable backup.
Ensuring the decision is documented to align with the organization's risk appetite.
The ISSMP acts as an advisor to ensure the chosen path reflects the established risk appetite.
Performing the initial forensic image of the infected servers.
Directing the IT team to disconnect the network immediately.
You are auditing a third-party disaster recovery service provider. Which metric provides the most accurate evidence that the provider can meet your organization's required recovery point for a database cluster?
Mean Time to Recovery (MTTR) reports from previous tests.
Service Level Agreement (SLA) uptime percentages.
Replication Lag monitoring logs showing synchronization latency.
Replication lag directly indicates the age of the data at the secondary site, which is the definition of RPO.
Annual penetration test results.
During a disaster recovery simulation for a hybrid cloud environment, you discover that the automated orchestration tool fails to restore dependencies in the correct order because the cloud provider's metadata tags were purged. What is the most effective administrative control to prevent this during a real event?
Enforce mandatory tagging policies using AWS Service Control Policies (SCPs) or Azure Policy.
Policy-based enforcement ensures metadata persistence required for automated recovery orchestration.
Increase the RTO buffer time in the Service Level Agreement (SLA).
Switch from automated restoration to manual snapshot-based restores.
Implement a manual verification step in the Disaster Recovery Plan (DRP) documentation.
Which document serves as the primary governing authority to define the triggers, escalation paths, and communication roles during a declared crisis event?
Business Impact Analysis (BIA)
Crisis Management Plan (CMP)
The CMP specifically addresses leadership, communication, and decision-making during crisis events.
Standard Operating Procedure (SOP)
Disaster Recovery Plan (DRP)
Which of the following is the most effective method for testing the efficacy of a Business Continuity Plan without disrupting production operations?
Parallel processing test.
Cutover test.
Full-scale simulation.
Tabletop exercise.
Tabletop exercises are designed to test decision-making and logic without requiring downtime.
Want more Contingency Management practice?
Practice this domainDuring the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?
The ISSMP personally reviewing every SQL script.
Allowing the automated CI/CD tool to deploy without human review.
Having the DBA perform the deployment in staging and production.
Requiring a separate release team to deploy changes approved by a Change Advisory Board (CAB).
This ensures that development, approval, and deployment are performed by different entities.
A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?
AWS CloudTrail
CloudTrail logs every action taken in the AWS account, providing the audit log required for change management.
AWS Shield
AWS Config
AWS Trusted Advisor
What is the primary objective of a 'Security Gate' in an SDLC?
To ensure security activities were completed before moving to the next phase.
Security gates act as validation points to prevent security defects from moving downstream.
To automate the removal of legacy hardware.
To stop all software development until the budget is approved.
To provide a location for developers to submit their resignation.
Which document is primarily responsible for documenting the security controls applicable to a system during the SDLC's requirements phase?
Acceptable Use Policy (AUP)
System Security Plan (SSP)
The SSP identifies the security controls that must be implemented for the system.
Service Level Agreement (SLA)
Business Impact Analysis (BIA)
A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?
Workflow Validators
Validators ensure that specific conditions, such as the presence of an approval comment or a specific flag, are met before a workflow transition occurs.
Automation for Jira
Issue Security Levels
Post-functions
During a waterfall-to-Agile transition, the development team wants to bypass formal Security Requirements Traceability Matrix (SRTM) documentation in favor of user stories. How should the ISSMP reconcile this?
Require all security requirements to be embedded into the definition of done (DoD) and documented as security user stories.
Integrating security into the DoD and user stories ensures traceability without hindering velocity.
Mandate that the project manager create a manual SRTM separately from the development tasks.
Deny the transition until full waterfall documentation is restored.
Allow the team to omit security requirements to speed up deployment.
Want more Systems Lifecycle Management practice?
Practice this domainA security manager is conducting a third-party risk assessment using the NIST Cybersecurity Framework. Which tool in the AWS Artifact portal is most appropriate for obtaining the necessary SOC 2 Type II reports to fulfill compliance auditing requirements?
AWS Trusted Advisor
AWS Config rules
AWS Security Hub
AWS Artifact Reports
AWS Artifact is the designated portal for obtaining compliance reports.
When drafting an organizational 'Acceptable Use Policy' (AUP), which element is most critical to ensure legal enforceability in a professional environment?
Inclusion of the entire ISO 27001 standard
A list of blocked websites
Detailed technical specifications of the firewall
Mandatory user acknowledgment signature
The signature provides the evidence needed to hold users accountable.
To ensure adherence to the PCI DSS 4.0 requirement for log integrity, which configuration in a centralized SIEM like Splunk is mandatory to prevent unauthorized modification of audit logs?
Utilizing Splunk Heavy Forwarders
Implementing WORM (Write Once Read Many) storage
WORM storage prevents the modification or deletion of logs, fulfilling audit integrity requirements.
Enabling Splunk Indexer Clustering
Configuring Role-Based Access Control (RBAC)
A company is subject to HIPAA. When configuring Microsoft 365, which feature is critical to ensure that PHI (Protected Health Information) is not accidentally shared via email while meeting 'Minimum Necessary' disclosure standards?
Exchange Online Protection (EOP) malware filtering
Microsoft Defender for Endpoint
Microsoft Purview DLP policies
Purview DLP identifies and restricts the sharing of PHI content.
Retention labels in the Compliance Center
A Chief Information Security Officer (CISO) is establishing an ethics program. Which framework provides the most comprehensive international standard for establishing an Information Security Management System (ISMS) encompassing compliance and ethical conduct?
COBIT 2019
ITIL 4
ISO/IEC 27001
ISO/IEC 27001 is the standard for building and certifying an ISMS.
NIST SP 800-53
An organization must comply with CCPA/CPRA requirements regarding 'Right to Delete'. In a hybrid environment utilizing Google Cloud Platform, which mechanism is best suited for implementing automated lifecycle policies to satisfy deletion requests across Cloud Storage buckets?
Cloud IAM condition policies
VPC Service Controls
Data Loss Prevention (DLP) API scan-only mode
Cloud Storage Lifecycle Management rules
Lifecycle rules are designed to automate object deletion to meet compliance retention/deletion needs.
Want more Law Ethics And Security Compliance Management practice?
Practice this domainWhich document is the primary source for defining the 'Risk Appetite' of an enterprise?
Risk Appetite Statement
This defines the amount of risk an organization is willing to accept.
Security Policy
Business Impact Analysis
Incident Response Plan
You are performing a qualitative risk assessment. Which factor must be prioritized to ensure the assessment is aligned with the organizational risk appetite?
The vendor's recommended patch cycle
The threat actor's motivation
The business impact of asset unavailability
Aligning risk with business impact ensures the assessment reflects true organizational risk appetite.
The technical complexity of the vulnerability
You are integrating an enterprise risk register with a GRC tool (e.g., Archer). Which method provides the most accurate view of 'Residual Risk' to the board?
Asset Value multiplied by Threat Frequency
Compliance Score subtracted from 100
Total Budget divided by Number of Findings
Inherent Risk multiplied by Control Gap
This represents the remaining risk exposure after accounting for control deficiencies.
Your organization adopts the NIST CSF 2.0. Which specific function should be assessed to identify gaps in your enterprise risk management program's Governance component?
Govern
The Govern function addresses organizational context and risk management strategy.
Protect
Respond
Recover
Identify
You are managing third-party risk. Which tool or method is most appropriate for a continuous assessment of a cloud service provider (CSP)?
Review of the CSP's website
Real-time CSPM monitoring
CSPM tools offer the continuous visibility required for modern cloud risk management.
One-time penetration test
Annual SOC 2 Type II review
A Chief Risk Officer is utilizing the FAIR framework to quantify cyber risk. Which input is required to calculate the Loss Event Frequency?
Primary Loss Magnitude and Secondary Loss Magnitude
Inherent Risk and Residual Risk
Control Strength and Asset Valuation
Threat Event Frequency and Vulnerability
Correct, these are the two components of Loss Event Frequency.
Want more Risk Management practice?
Practice this domainA CISO is aligning security objectives with the enterprise's Balanced Scorecard. Which perspective should the CISO focus on to demonstrate the value of security investments in achieving organizational mission readiness?
Customer Perspective
Learning and Growth Perspective
Internal Process Perspective
This aligns security controls with the key internal operations needed to achieve mission objectives.
Financial Perspective
Which organizational structure is most effective for a CISO to influence security behavior across geographically dispersed and independent business units?
Centralized Command and Control
Outsourced Security Operations
Matrix Management
Provides the balance of authority and influence needed in large, complex organizations.
Decentralized/Siloed Management
When transitioning to an Agile development methodology, which security management approach best supports the 'Shift Left' security strategy?
Performing security audits only after deployment
Requiring manual sign-off for every code commit
Limiting access to the development environment
Integrating automated security testing in the CI/CD pipeline
Automation early in the pipeline is the cornerstone of the shift left strategy.
The board of directors requests a quantitative risk assessment for a new cloud-based initiative. Which metric provides the best representation of potential financial exposure to the organization for a single, significant security event?
Single Loss Expectancy (SLE)
SLE is the direct product of the asset value and the exposure factor.
Residual Risk
Annualized Loss Expectancy (ALE)
Annualized Rate of Occurrence (ARO)
A security manager is evaluating organizational security culture. Which indicator provides the most reliable evidence of a 'security-first' culture?
Volume of self-reported security near-misses
This indicates an empowered and vigilant workforce.
Budget allocated to security
Percentage of employees who completed training
Number of security policies written
An ISSMP is managing a merger where two organizations use different identity providers. Which strategy best mitigates identity-related risk during the integration phase?
Granting domain administrative rights to both IT teams
Implementing a federated identity solution
Federation provides a secure, scalable way to manage cross-organizational identities.
Migrating all users to a new identity provider immediately
Creating duplicate user accounts for all employees
Want more Leadership And Organizational Management practice?
Practice this domainAn organization uses Microsoft Sentinel. To ensure that an automated incident response playbook only triggers when a high-severity alert originates from a specific production subnet, where should the condition be defined?
In the Azure Policy definitions
In the Sentinel Data Connector configuration
Inside the KQL query of the analytic rule
In the Automation Rule trigger condition
Automation rules allow filtering by alert severity and entity values before triggering the playbook.
In an incident response plan, which metric is most useful for measuring the 'dwell time' of a threat actor?
Mean Time to Acknowledge (MTTA)
Mean Time to Recovery (MTTR)
Mean Time to Detect (MTTD)
MTTD directly relates to how long a threat remains active before it is discovered.
Mean Time to Contain (MTTC)
Which document is considered the primary 'source of truth' for defining the SOC's roles, responsibilities, and communication paths during a major security incident?
Vulnerability Assessment Report
Standard Operating Procedure (SOP)
Incident Response Plan (IRP)
The IRP outlines the management, roles, and escalation procedures for incidents.
Asset Inventory
When using Palo Alto Networks Cortex XSOAR, which component is responsible for orchestrating the execution of scripts across multiple third-party integrations?
Classifier
Integration Instance
Playbook
Playbooks are the workflows that define the automated steps and cross-tool actions.
Indicator Field
An organization is investigating a potential lateral movement incident in AWS. Which CloudTrail event field provides the most reliable indicator of the source IP address for an API call performed by an IAM role?
recipientAccountId
sourceIPAddress
This field records the IP address from which the API request originated.
requestParameters
userIdentity.arn
When configuring CrowdStrike Falcon to isolate a host during an active incident, what is the prerequisite requirement for the agent's communication state?
The agent must be in 'Aggressive' sensor mode
The agent must maintain an active connection to the Falcon Cloud
Host isolation relies on the agent receiving the command from the cloud; if the host is offline, it cannot receive the instruction.
The host must have full disk encryption disabled
The host must be in a 'Managed' group with full administrative rights
Want more Security Operations practice?
Practice this domainThe ISC exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Contingency Management, Systems Lifecycle Management, Law Ethics And Security Compliance Management, Risk Management, Leadership And Organizational Management, Security Operations. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official (ISC)² ISC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.