Courseiva

CISSP · domain

Security Operations

Practise Certified Information Systems Security Professional CISSP Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

51 questions14 easy25 medium12 hard

Focused practice

Practice Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Operations

Security Operations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Operations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Operations questions (51)

Click any question to see the full explanation, or start a practice session above.

1

A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:

Medium
2

An organization's data loss prevention (DLP) solution is configured to block emails containing credit card numbers. This is an example of which type of DLP control?

Hard
3

During a digital forensics investigation, a security analyst must preserve evidence in order of volatility. Which of the following represents the correct sequence from most volatile to least volatile?

Medium
4

An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?

Medium
5

A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?

Medium
6

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

Hard
7

A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)

Medium
8

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

Medium
9

An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?

Hard
10

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

Medium
11

Which of the following best describes the primary purpose of an incident response plan?

Easy
12

A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)

Hard
13

Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?

Easy
14

Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?

Easy
15

An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?

Easy
16

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

Medium
17

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

Easy
18

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

Medium
19

A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?

Medium
20

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

Medium
21

An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?

Medium
22

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Medium
23

An organization is recovering from a ransomware attack that encrypted critical servers. The backup strategy must ensure that the Recovery Point Objective (RPO) of 1 hour is met. Which backup method is MOST appropriate?

Hard
24

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

Easy
25

Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?

Easy
26

Which of the following is an example of a social engineering attack?

Easy
27

Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?

Hard
28

An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?

Medium
29

What type of DLP system monitors data in motion across the network?

Easy
30

During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?

Hard
31

During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?

Medium
32

Which digital forensics tool is specifically designed for memory forensics?

Easy
33

During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?

Medium
34

A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?

Hard
35

What is the primary purpose of a Change Advisory Board (CAB) in change management?

Medium
36

An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?

Medium
37

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

Medium
38

Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
39

An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?

Hard
40

A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?

Medium
41

An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)

Medium
42

A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?

Hard
43

An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?

Hard
44

Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
45

During a digital forensics investigation, which of the following data sources has the highest order of volatility?

Medium
46

Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?

Easy
47

An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?

Medium
48

A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?

Hard
49

What is the PRIMARY purpose of a chain of custody in digital forensics?

Easy
50

A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?

Medium
51

A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?

Medium

Frequently asked questions

What does the Security Operations domain cover on the CISSP exam?
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 51 Security Operations questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp security ops Practice Questions