CISSP · domain
Security Operations
Practise Certified Information Systems Security Professional CISSP Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Operations exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Operations questions (51)
Click any question to see the full explanation, or start a practice session above.
A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
Medium2An organization's data loss prevention (DLP) solution is configured to block emails containing credit card numbers. This is an example of which type of DLP control?
Hard3During a digital forensics investigation, a security analyst must preserve evidence in order of volatility. Which of the following represents the correct sequence from most volatile to least volatile?
Medium4An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?
Medium5A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?
Medium6A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?
Hard7A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)
Medium8During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
Medium9An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?
Hard10A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?
Medium11Which of the following best describes the primary purpose of an incident response plan?
Easy12A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)
Hard13Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?
Easy14Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?
Easy15An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?
Easy16An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?
Medium17A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?
Easy18An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)
Medium19A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?
Medium20Which of the following is the primary purpose of a Change Advisory Board (CAB)?
Medium21An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?
Medium22A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?
Medium23An organization is recovering from a ransomware attack that encrypted critical servers. The backup strategy must ensure that the Recovery Point Objective (RPO) of 1 hour is met. Which backup method is MOST appropriate?
Hard24An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?
Easy25Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?
Easy26Which of the following is an example of a social engineering attack?
Easy27Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?
Hard28An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?
Medium29What type of DLP system monitors data in motion across the network?
Easy30During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?
Hard31During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?
Medium32Which digital forensics tool is specifically designed for memory forensics?
Easy33During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?
Medium34A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?
Hard35What is the primary purpose of a Change Advisory Board (CAB) in change management?
Medium36An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?
Medium37A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?
Medium38Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
Easy39An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?
Hard40A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?
Medium41An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)
Medium42A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?
Hard43An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?
Hard44Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
Easy45During a digital forensics investigation, which of the following data sources has the highest order of volatility?
Medium46Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?
Easy47An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?
Medium48A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?
Hard49What is the PRIMARY purpose of a chain of custody in digital forensics?
Easy50A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?
Medium51A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?
MediumOther domains
All CISSP exam domains
Frequently asked questions
- What does the Security Operations domain cover on the CISSP exam?
- Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 51 Security Operations questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.