Courseiva

ISC · topic practice

Security Planning And Engineering practice questions

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Security Planning And Engineering practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security Planning And Engineering

What the exam tests

What to know about Security Planning And Engineering

Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Planning And Engineering exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security Planning And Engineering questions

20 questions · select your answer, then reveal the explanation

During the design of a PKI hierarchy for a highly classified system, the ISSEP needs to ensure that the Root CA is kept offline. What is the most appropriate way to sign the Subordinate CA request?

An ISSEP is evaluating the security of an API gateway. To implement OAuth 2.0 effectively, which flow should be recommended for a native mobile application?

A system is being designed to process PII. The requirement is to maintain data sovereignty while utilizing a hybrid cloud model. What architectural strategy best achieves this?

An ISSEP is designing a secure architecture for a cloud environment using NIST SP 800-160. Which architectural pattern should the engineer prioritize to ensure the principle of Least Privilege is enforced at the service-to-service communication layer within a Kubernetes cluster?

When applying NIST SP 800-53 controls to a new information system, which step occurs immediately after the 'Categorize' process in the RMF?

When configuring AWS Security Groups for a multi-tier application architecture, an engineer must ensure that the web tier only communicates with the application tier on port 8080. Which configuration best adheres to the principle of Defense in Depth?

An ISSEP is configuring a WAF to mitigate OWASP Top 10 risks. Which configuration best addresses the 'Injection' category?

An ISSEP is conducting a gap analysis between a legacy system and ISO/IEC 27001 requirements. The system lacks automated audit logging. Which control implementation is most effective for meeting the 'Logging and Monitoring' requirements?

An ISSEP must secure a server-to-server connection that currently uses plaintext LDAP. What is the recommended secure alternative?

In a Zero Trust architecture, what is the most critical function of a Policy Decision Point (PDP)?

When designing an information system architecture, what is the primary role of a System Security Plan (SSP)?

An ISSEP is designing a secure CI/CD pipeline. Which technique is most effective for preventing secrets (e.g., API keys) from being committed to the source code repository?

When implementing FIPS 140-2/-3 validated cryptography in a system, what is the most important factor to verify?

An organization is adopting ISO 27001. Which document is required to justify the inclusion or exclusion of specific controls?

You are designing a secure data enclave for highly sensitive research data. What is the most robust method to enforce physical and logical separation?

What is the primary objective of the 'Assessment' phase in the NIST RMF?

A system uses SAML 2.0 for SSO. To prevent SAML assertion tampering, what is the mandatory cryptographic requirement?

An ISSEP needs to secure inter-process communication (IPC) on a Linux host. Which feature should be configured to prevent unauthorized processes from accessing sensitive memory space?

Which document is used to track and manage vulnerabilities identified during the assessment phase of the RMF?

An ISSEP is designing a secure storage solution for a database. To ensure data integrity, which mechanism is most reliable?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Planning And Engineering sessions

Start a Security Planning And Engineering only practice session

Every question in these sessions is drawn from the Security Planning And Engineering domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Security Planning And Engineering?
Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Planning And Engineering questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Planning And Engineering domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.