ISC · domain
Security Planning And Engineering
Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Security Planning And Engineering practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Planning And Engineering questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Planning And Engineering
Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Planning And Engineering exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Planning And Engineering questions (53)
Click any question to see the full explanation, or start a practice session above.
When mapping security requirements from ISO/IEC 27001 to a cloud-native architecture, you are configuring Azure Policy to ensure all newly created storage accounts have 'Secure transfer required' enabled. What is the most efficient way to achieve this enforcement?
Hard2Which THREE actions should be taken when decommissioning an information system to ensure data security?
Hard3Which THREE factors are essential when performing a threat model using the STRIDE methodology?
Hard4Which TWO security standards are most relevant for an ISSEP designing a secure payment processing system?
Medium5A system uses SAML 2.0 for SSO. To prevent SAML assertion tampering, what is the mandatory cryptographic requirement?
Hard6When applying NIST SP 800-53 controls to a new information system, which step occurs immediately after the 'Categorize' process in the RMF?
Easy7An ISSEP is conducting a gap analysis between a legacy system and ISO/IEC 27001 requirements. The system lacks automated audit logging. Which control implementation is most effective for meeting the 'Logging and Monitoring' requirements?
Medium8Which THREE of the following are recognized categories of security controls in NIST SP 800-53?
Medium9Which TWO items should be included in a system's security architecture documentation?
Medium10Which THREE items should be included in an Incident Response (IR) plan for an information system?
Medium11During a system migration, you need to ensure integrity of transferred data. What is the best cryptographic method?
Hard12When designing a secure multi-tenant cloud application, what is the best way to ensure tenant data isolation?
Hard13When architecting a system to meet ISO 27001 requirements for secure system engineering, which TWO of the following design principles should be prioritized for protecting sensitive data at rest?
Medium14An ISSEP is evaluating the security of an API gateway. To implement OAuth 2.0 effectively, which flow should be recommended for a native mobile application?
Medium15An ISSEP is configuring an AWS S3 bucket. What policy setting best prevents public access while allowing access from a specific VPC?
Medium16You are designing an incident response architecture for a cloud environment. Which TWO of the following configurations are critical for ensuring effective forensic readiness according to NIST SP 800-61?
Medium17An ISSEP architect is designing a system under NIST SP 800-53 controls and needs to implement an automated mechanism to enforce the principle of least privilege for non-privileged accounts. Which configuration in an AWS environment best aligns with the 'AC-6' control requirement?
Medium18An ISSEP is designing a secure storage solution for a database. To ensure data integrity, which mechanism is most reliable?
Medium19You are conducting a threat modeling exercise using the STRIDE methodology. A specific service-to-service communication path lacks mutual TLS. Which STRIDE category does this vulnerability primarily fall under?
Medium20Which TWO of the following are considered critical components of a Secure Software Development Life Cycle (SDLC)?
Medium21What is the correct order of operations when handling a vulnerability in a production system according to the RMF?
Easy22You are designing a secure data enclave for highly sensitive research data. What is the most robust method to enforce physical and logical separation?
Hard23During the design of a PKI hierarchy for a highly classified system, the ISSEP needs to ensure that the Root CA is kept offline. What is the most appropriate way to sign the Subordinate CA request?
Hard24Which document is used to track and manage vulnerabilities identified during the assessment phase of the RMF?
Easy25An ISSEP is designing a secure CI/CD pipeline. Which technique is most effective for preventing secrets (e.g., API keys) from being committed to the source code repository?
Hard26When configuring AWS Security Groups for a multi-tier application architecture, an engineer must ensure that the web tier only communicates with the application tier on port 8080. Which configuration best adheres to the principle of Defense in Depth?
Hard27Which TWO controls are recommended under NIST SP 800-53 for protecting data at rest in a high-impact system?
Medium28In a cloud environment, you must ensure that VM snapshots are encrypted. What is the most effective approach?
Hard29An ISSEP needs to secure inter-process communication (IPC) on a Linux host. Which feature should be configured to prevent unauthorized processes from accessing sensitive memory space?
Medium30An ISSEP is configuring a WAF to mitigate OWASP Top 10 risks. Which configuration best addresses the 'Injection' category?
Medium31When selecting controls for a system in a high-compliance environment, what is the best practice for tailoring?
Medium32Which THREE items are required to verify the integrity of a downloaded software package?
Hard33You are designing a secure microservices architecture. To meet the 'Data at Rest' security requirements, you decide to use envelope encryption. Which sequence correctly describes the flow of managing the Data Encryption Key (DEK)?
Hard34An organization is migrating to a Zero Trust architecture as defined in NIST SP 800-207. Which component is responsible for evaluating the context of a request, such as device health and location, before granting access?
Easy35A system is being designed to process PII. The requirement is to maintain data sovereignty while utilizing a hybrid cloud model. What architectural strategy best achieves this?
Hard36When designing an information system architecture, what is the primary role of a System Security Plan (SSP)?
Easy37An ISSEP must secure a server-to-server connection that currently uses plaintext LDAP. What is the recommended secure alternative?
Medium38Which TWO methods are effective for managing cryptographic keys in a cloud architecture?
Medium39An ISSEP is designing a secure architecture for a cloud environment using NIST SP 800-160. Which architectural pattern should the engineer prioritize to ensure the principle of Least Privilege is enforced at the service-to-service communication layer within a Kubernetes cluster?
Medium40An ISSEP is architecting a secure API environment. Which strategy is most effective for throttling and preventing resource exhaustion?
Medium41When designing for high availability and security, what is the best use of a Load Balancer (LB) from a security perspective?
Medium42An ISSEP is tasked with securing an internal web application. Which headers should be implemented to prevent clickjacking?
Medium43What is the primary objective of the 'Assessment' phase in the NIST RMF?
Easy44Which THREE elements are required in a high-security access control policy?
Hard45When implementing FIPS 140-2/-3 validated cryptography in a system, what is the most important factor to verify?
Medium46An ISSEP professional is reviewing an architecture for compliance with NIST SP 800-160, Systems Security Engineering. Which THREE of the following activities are core to the 'Trustworthiness' objective for an engineered system?
Hard47What is the primary goal of the 'Authorization' phase in the NIST RMF?
Easy48An organization is adopting ISO 27001. Which document is required to justify the inclusion or exclusion of specific controls?
Medium49Which THREE methods can be used to ensure high availability for a database in a secure architecture?
Hard50In a Zero Trust architecture, what is the most critical function of a Policy Decision Point (PDP)?
Hard51Which THREE of the following are necessary to successfully implement Zero Trust in an existing enterprise environment?
Hard52You are assessing a system for compliance with FIPS 140-3. You need to ensure that the cryptographic module being used for TLS termination on a load balancer meets specific physical security requirements. Where should you look for the validation status of the cryptographic module?
Medium53In the context of the NIST Risk Management Framework (RMF), which step involves the initial identification of security controls based on the system's impact level?
EasyOther domains
All ISC exam domains
Frequently asked questions
- What does the Security Planning And Engineering domain cover on the ISC exam?
- Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 53 Security Planning And Engineering questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Planning And Engineering questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.