Courseiva
← Back to Certified Information Systems Security Professional CISSP questions

Scenario-based practice

Hard Difficulty Questions

Practise Certified Information Systems Security Professional CISSP practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISSP
exam code
ISC2
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISSP topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A financial services company with 5000 employees uses a hybrid identity model with on-premises Active Directory (AD) synchronized to Azure AD via Azure AD Connect. The company has recently deployed Microsoft 365 and uses it for email and file sharing. Users authenticate to Azure AD using password hash synchronization (PHS) with Seamless Single Sign-On (SSO). The security team has implemented Conditional Access policies to require multi-factor authentication (MFA) for all external access and for access to sensitive financial applications. Recently, the help desk has received numerous complaints from users working remotely that they are frequently prompted for MFA, even multiple times during a single work session, causing frustration and productivity loss. Additionally, some users report that they are unable to access certain financial applications despite being in the correct group membership. An investigation reveals that Azure AD Connect synchronization is occurring successfully and that MFA configurations appear correct. The security team suspects that the issue may be related to the Conditional Access session settings or token lifetimes. What is the BEST course of action to diagnose and resolve the primary issue of excessive MFA prompts while maintaining security?

Question 2hardmultiple choice
Full question →

A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?

Question 3hardmulti select
Full question →

Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)

Question 4hardmultiple choice
Study the full ACL explanation →

Refer to the exhibit. A security analyst is reviewing the network ACL inbound rules. Which statement is true?

Exhibit

{
  "InboundRules": [
    {
      "RuleNumber": 100,
      "Protocol": "6",
      "PortRange": {
        "From": 80,
        "To": 80
      },
      "Source": "0.0.0.0/0",
      "Action": "allow"
    },
    {
      "RuleNumber": 200,
      "Protocol": "6",
      "PortRange": {
        "From": 22,
        "To": 22
      },
      "Source": "10.0.0.0/8",
      "Action": "allow"
    }
  ]
}
Question 5hardmulti select
Full question →

Which THREE of the following are primary objectives of a risk management program?

Question 6hardmultiple choice
Full question →

A multinational company must comply with the EU General Data Protection Regulation (GDPR) for processing personal data of EU citizens. The company's data protection officer (DPO) has been appointed but reports to the Chief Marketing Officer (CMO). Which compliance issue is most critical?

Question 7hardmulti select
Full question →

An organization is acquiring a third-party software product. Which THREE of the following should be included in the security assessment of the vendor?

Question 8hardmultiple choice
Full question →

A security analyst discovers that an employee shared confidential customer data with an unauthorized third party. The analyst reports this to the CISO, who decides to terminate the employee. Which ethical principle from the (ISC)² Code of Ethics is most directly violated by the employee?

Question 9hardmultiple choice
Full question →

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

Question 10hardmultiple choice
Study the full virtualization explanation →

A large financial institution is migrating its core banking system to a private cloud. The architecture must protect against data leakage between different business units sharing the same physical infrastructure. The system uses a hypervisor and virtual machines. Each business unit has its own security classification. The security requirement is that no VM belonging to a lower classification should be able to read data from a higher classification VM, even if the hypervisor is compromised. The architect proposes using mandatory access control at the hypervisor level. However, the IT team notes that a hypervisor compromise could bypass MAC. Additionally, they need to ensure that data at rest is encrypted and keys are stored securely. Which of the following would BEST meet the requirement?

Question 11hardmultiple choice
Study the full ACL explanation →

Refer to the exhibit. A security auditor is reviewing the network ACLs for a cloud VPC. Which of the following is the most significant security concern?

Exhibit

{
  "network": "vpc-12345",
  "inbound_rules": [
    {"protocol": "tcp", "port": 22, "source": "10.0.0.0/8"},
    {"protocol": "tcp", "port": 3389, "source": "192.168.1.0/24"}
  ],
  "outbound_rules": [
    {"protocol": "all", "destination": "0.0.0.0/0"}
  ]
}
Question 12hardmultiple choice
Full question →

A security architect is designing a network for a high-security data center. The requirement is to ensure that even if an attacker compromises one server, they cannot easily move laterally to other servers in the same data center. Which network design principle should be applied?

Question 13hardmultiple choice
Read the full DNS explanation →

A company deploys DNSSEC to protect its DNS infrastructure. Which cryptographic operation does DNSSEC primarily use to ensure the authenticity and integrity of DNS data?

Question 14hardmultiple choice
Open the full BGP breakdown →

A company uses BGP to exchange routes with its ISP. To prevent prefix hijacking, which mechanism should be implemented?

Question 15hardmultiple choice
Read the full wireless explanation →

A company is migrating from WPA2 to WPA3 to enhance wireless security. Which of the following cryptographic changes does WPA3 introduce compared to WPA2?

Question 16hardmultiple choice
Read the full VPN explanation →

During a security assessment, a consultant discovers that a legacy VPN solution uses MS-CHAPv2 for authentication and does not support IKE. The protocol is known to be vulnerable to dictionary attacks. Which VPN protocol is most likely being used?

Question 17hardmultiple choice
Full question →

An organization is adopting a microservices architecture. Which security control is most effective for ensuring that inter-service communication is authenticated and authorized?

Question 18hardmultiple choice
Full question →

Refer to the exhibit. Which attack is this OAuth authorization server policy vulnerable to?

Exhibit

{
  "scopes": [
    {"name": "read", "permissions": ["file:read"]},
    {"name": "write", "permissions": ["file:write"]}
  ],
  "default_permissions": ["file:read"]
}
Question 19hardmultiple choice
Full question →

During a penetration test, an ethical hacker sets up a rogue access point with the same SSID as the corporate network and broadcasts a stronger signal. Users inadvertently connect to the rogue AP, allowing the hacker to capture credentials. What is this attack called?

Question 20hardmultiple choice
Full question →

A company's security team discovers that an employee inadvertently shared sensitive customer data via a public cloud storage link. The incident response team contains the breach and notifies affected customers. Which of the following risk management strategies would BEST prevent recurrence?

These CISSP practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CISSP questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.