Courseiva

ISC · domain

Security Planning And Engineering

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Security Planning And Engineering practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

53 questions8 easy26 medium19 hard

Focused practice

Practice Security Planning And Engineering questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Planning And Engineering

Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Planning And Engineering exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Planning And Engineering questions (53)

Click any question to see the full explanation, or start a practice session above.

1

When mapping security requirements from ISO/IEC 27001 to a cloud-native architecture, you are configuring Azure Policy to ensure all newly created storage accounts have 'Secure transfer required' enabled. What is the most efficient way to achieve this enforcement?

Hard
2

Which THREE actions should be taken when decommissioning an information system to ensure data security?

Hard
3

Which THREE factors are essential when performing a threat model using the STRIDE methodology?

Hard
4

Which TWO security standards are most relevant for an ISSEP designing a secure payment processing system?

Medium
5

A system uses SAML 2.0 for SSO. To prevent SAML assertion tampering, what is the mandatory cryptographic requirement?

Hard
6

When applying NIST SP 800-53 controls to a new information system, which step occurs immediately after the 'Categorize' process in the RMF?

Easy
7

An ISSEP is conducting a gap analysis between a legacy system and ISO/IEC 27001 requirements. The system lacks automated audit logging. Which control implementation is most effective for meeting the 'Logging and Monitoring' requirements?

Medium
8

Which THREE of the following are recognized categories of security controls in NIST SP 800-53?

Medium
9

Which TWO items should be included in a system's security architecture documentation?

Medium
10

Which THREE items should be included in an Incident Response (IR) plan for an information system?

Medium
11

During a system migration, you need to ensure integrity of transferred data. What is the best cryptographic method?

Hard
12

When designing a secure multi-tenant cloud application, what is the best way to ensure tenant data isolation?

Hard
13

When architecting a system to meet ISO 27001 requirements for secure system engineering, which TWO of the following design principles should be prioritized for protecting sensitive data at rest?

Medium
14

An ISSEP is evaluating the security of an API gateway. To implement OAuth 2.0 effectively, which flow should be recommended for a native mobile application?

Medium
15

An ISSEP is configuring an AWS S3 bucket. What policy setting best prevents public access while allowing access from a specific VPC?

Medium
16

You are designing an incident response architecture for a cloud environment. Which TWO of the following configurations are critical for ensuring effective forensic readiness according to NIST SP 800-61?

Medium
17

An ISSEP architect is designing a system under NIST SP 800-53 controls and needs to implement an automated mechanism to enforce the principle of least privilege for non-privileged accounts. Which configuration in an AWS environment best aligns with the 'AC-6' control requirement?

Medium
18

An ISSEP is designing a secure storage solution for a database. To ensure data integrity, which mechanism is most reliable?

Medium
19

You are conducting a threat modeling exercise using the STRIDE methodology. A specific service-to-service communication path lacks mutual TLS. Which STRIDE category does this vulnerability primarily fall under?

Medium
20

Which TWO of the following are considered critical components of a Secure Software Development Life Cycle (SDLC)?

Medium
21

What is the correct order of operations when handling a vulnerability in a production system according to the RMF?

Easy
22

You are designing a secure data enclave for highly sensitive research data. What is the most robust method to enforce physical and logical separation?

Hard
23

During the design of a PKI hierarchy for a highly classified system, the ISSEP needs to ensure that the Root CA is kept offline. What is the most appropriate way to sign the Subordinate CA request?

Hard
24

Which document is used to track and manage vulnerabilities identified during the assessment phase of the RMF?

Easy
25

An ISSEP is designing a secure CI/CD pipeline. Which technique is most effective for preventing secrets (e.g., API keys) from being committed to the source code repository?

Hard
26

When configuring AWS Security Groups for a multi-tier application architecture, an engineer must ensure that the web tier only communicates with the application tier on port 8080. Which configuration best adheres to the principle of Defense in Depth?

Hard
27

Which TWO controls are recommended under NIST SP 800-53 for protecting data at rest in a high-impact system?

Medium
28

In a cloud environment, you must ensure that VM snapshots are encrypted. What is the most effective approach?

Hard
29

An ISSEP needs to secure inter-process communication (IPC) on a Linux host. Which feature should be configured to prevent unauthorized processes from accessing sensitive memory space?

Medium
30

An ISSEP is configuring a WAF to mitigate OWASP Top 10 risks. Which configuration best addresses the 'Injection' category?

Medium
31

When selecting controls for a system in a high-compliance environment, what is the best practice for tailoring?

Medium
32

Which THREE items are required to verify the integrity of a downloaded software package?

Hard
33

You are designing a secure microservices architecture. To meet the 'Data at Rest' security requirements, you decide to use envelope encryption. Which sequence correctly describes the flow of managing the Data Encryption Key (DEK)?

Hard
34

An organization is migrating to a Zero Trust architecture as defined in NIST SP 800-207. Which component is responsible for evaluating the context of a request, such as device health and location, before granting access?

Easy
35

A system is being designed to process PII. The requirement is to maintain data sovereignty while utilizing a hybrid cloud model. What architectural strategy best achieves this?

Hard
36

When designing an information system architecture, what is the primary role of a System Security Plan (SSP)?

Easy
37

An ISSEP must secure a server-to-server connection that currently uses plaintext LDAP. What is the recommended secure alternative?

Medium
38

Which TWO methods are effective for managing cryptographic keys in a cloud architecture?

Medium
39

An ISSEP is designing a secure architecture for a cloud environment using NIST SP 800-160. Which architectural pattern should the engineer prioritize to ensure the principle of Least Privilege is enforced at the service-to-service communication layer within a Kubernetes cluster?

Medium
40

An ISSEP is architecting a secure API environment. Which strategy is most effective for throttling and preventing resource exhaustion?

Medium
41

When designing for high availability and security, what is the best use of a Load Balancer (LB) from a security perspective?

Medium
42

An ISSEP is tasked with securing an internal web application. Which headers should be implemented to prevent clickjacking?

Medium
43

What is the primary objective of the 'Assessment' phase in the NIST RMF?

Easy
44

Which THREE elements are required in a high-security access control policy?

Hard
45

When implementing FIPS 140-2/-3 validated cryptography in a system, what is the most important factor to verify?

Medium
46

An ISSEP professional is reviewing an architecture for compliance with NIST SP 800-160, Systems Security Engineering. Which THREE of the following activities are core to the 'Trustworthiness' objective for an engineered system?

Hard
47

What is the primary goal of the 'Authorization' phase in the NIST RMF?

Easy
48

An organization is adopting ISO 27001. Which document is required to justify the inclusion or exclusion of specific controls?

Medium
49

Which THREE methods can be used to ensure high availability for a database in a secure architecture?

Hard
50

In a Zero Trust architecture, what is the most critical function of a Policy Decision Point (PDP)?

Hard
51

Which THREE of the following are necessary to successfully implement Zero Trust in an existing enterprise environment?

Hard
52

You are assessing a system for compliance with FIPS 140-3. You need to ensure that the cryptographic module being used for TLS termination on a load balancer meets specific physical security requirements. Where should you look for the validation status of the cryptographic module?

Medium
53

In the context of the NIST Risk Management Framework (RMF), which step involves the initial identification of security controls based on the system's impact level?

Easy

Frequently asked questions

What does the Security Planning And Engineering domain cover on the ISC exam?
Security Planning And Engineering questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 53 Security Planning And Engineering questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Planning And Engineering questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issep ISC2-ISSEP security planning and engineering Practice Questions