Sample questions
(ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) practice questions
Which TWO of the following are key inputs for a quantitative risk analysis?
Which of the following is the most appropriate action when an ISSEP identifies a high-risk vulnerability in a system that is currently in production?
You are assessing an Engineered System that utilizes a Trusted Platform Module (TPM) for secure boot. A scan reveals that the firmware version is outdated and susceptible to a know…
Which of the following is a primary objective of a 'System-Level Risk Assessment'?
An ISSEP is evaluating the security of an OT/ICS environment. Which THREE of the following are considered high-priority mitigation strategies to protect against common ICS cyber th…
What is the primary purpose of a 'Sanitization' process in the context of system decommissioning?
During a system engineering project, an ISSEP discovers that a vendor-provided API lacks robust authentication. Which risk management strategy is best suited for this vulnerability…
Which THREE of the following are essential for protecting against 'Man-in-the-Middle' (MitM) attacks in a service-oriented architecture?
You are assessing an Engineered System for cloud-native vulnerabilities. Which THREE of the following are common misconfigurations in containerized environments that an ISSEP shoul…
What is the primary goal of the 'Authorization' phase in the NIST RMF?
An ISSEP is reviewing a cloud-based application that uses a multi-factor authentication (MFA) provider. The provider experiences an outage, and the system is configured to 'fail-op…
When managing decommissioning of a cloud-native application, which document must be updated to reflect the removal of security controls?
Secure Operations Change Management And DisposalmediumSee the answer and why each option is right or wrong →An ISSEP is performing a system-level risk assessment on a cloud-native architecture using the NIST SP 800-37 RMF. During the 'Assess' step, the engineer identifies that an automat…
During the design of a PKI hierarchy for a highly classified system, the ISSEP needs to ensure that the Root CA is kept offline. What is the most appropriate way to sign the Subord…
An ISSEP is designing a secure CI/CD pipeline. Which technique is most effective for preventing secrets (e.g., API keys) from being committed to the source code repository?
In the systems engineering V-model, how does 'Verification' differ from 'Validation'?
An ISSEP is evaluating the risk of an API that uses basic authentication over HTTP. What is the most significant risk, and how should it be mitigated?
An ISSEP is assessing the security of a CI/CD pipeline. Which THREE of the following practices are crucial to ensure the security of the software supply chain?
During a risk assessment of an industrial control system (ICS), the engineer identifies that an administrative workstation shares the same VLAN as the PLC network. Which remediatio…
Which THREE technologies are acceptable for the secure disposal of solid-state drives (SSDs)?
Secure Operations Change Management And DisposalhardSee the answer and why each option is right or wrong →An ISSEP is performing a supply chain risk assessment for an IOT-based sensor array. Which finding poses the highest systemic risk to the overall system integrity?
An ISSEP must secure a server-to-server connection that currently uses plaintext LDAP. What is the recommended secure alternative?
Which THREE items should be included in a Post-Implementation Review (PIR) for a security change?
Secure Operations Change Management And DisposalhardSee the answer and why each option is right or wrong →When designing an information system architecture, what is the primary role of a System Security Plan (SSP)?