Sample questions
(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) practice questions
An ISSMP is revising the BCP to account for 'Supply Chain Resiliency'. Which approach is best for verifying that critical third-party vendors can meet the organization's recovery r…
During a BCP planning session, the executive team is debating the 'Maximum Tolerable Downtime' (MTD) for a legacy internal application. What is the correct way to define this metri…
When classifying business processes for BCP, what is the 'Recovery Time Objective' (RTO) most effectively used for?
Which TWO of the following are effective ways to improve 'Crisis Management Leadership' effectiveness during an incident?
Which TWO aspects of the NIST Cybersecurity Framework (CSF) are most relevant when establishing a 'Compliance Program Management' function?
Law Ethics And Security Compliance ManagementmediumSee the answer and why each option is right or wrong →A security manager is drafting a security policy. Which element is essential for ensuring executive support and establishing the policy's organizational authority?
Which TWO actions should a security manager take to ensure an organization remains compliant with the Sarbanes-Oxley (SOX) Act regarding IT controls?
Law Ethics And Security Compliance ManagementmediumSee the answer and why each option is right or wrong →When conducting a compliance audit, what is the purpose of a 'Gap Analysis'?
Law Ethics And Security Compliance ManagementeasySee the answer and why each option is right or wrong →What is the primary objective of a Business Impact Analysis (BIA)?
In Okta, to restrict administrative access to a specific geographic region during an active session, which policy should be modified?
When reporting to the board of directors, which presentation method is most effective for communicating security performance?
Leadership And Organizational ManagementmediumSee the answer and why each option is right or wrong →In Tenable.io, when prioritizing vulnerability remediation, which metric provides the best insight into the likelihood of a vulnerability being exploited in the wild?
When managing cross-functional security projects, which stakeholder communication strategy is most effective for securing project resources?
Leadership And Organizational ManagementmediumSee the answer and why each option is right or wrong →Which THREE of the following are important considerations for an ISSMP when outsourcing security functions?
A CISO is aligning the organizational information security strategy with the NIST Cybersecurity Framework (CSF) 2.0. Which specific function should the CISO prioritize to ensure th…
Leadership And Organizational ManagementmediumSee the answer and why each option is right or wrong →An organization is conducting a risk assessment and identifies a critical vulnerability in a legacy system that cannot be patched. Which of the following is the most appropriate ri…
Leadership And Organizational ManagementmediumSee the answer and why each option is right or wrong →When designing the Crisis Communication Plan, why is it essential to establish pre-approved communication templates?
When designing a Disaster Recovery Program, which THREE of the following represent common 'single points of failure' that must be addressed?
A company is subject to HIPAA. When configuring Microsoft 365, which feature is critical to ensure that PHI (Protected Health Information) is not accidentally shared via email whil…
Law Ethics And Security Compliance ManagementhardSee the answer and why each option is right or wrong →Which principle of 'Ethics in Security Leadership' dictates that a manager should prioritize the safety and privacy of the user over organizational convenience?
Law Ethics And Security Compliance ManagementeasySee the answer and why each option is right or wrong →Which TWO factors must a security officer consider when performing a 'Privacy Impact Assessment' (PIA) for a new cloud application?
Law Ethics And Security Compliance ManagementmediumSee the answer and why each option is right or wrong →A CISO is presenting a security program roadmap. Which approach is best for managing expectations regarding security maturity?
Leadership And Organizational ManagementmediumSee the answer and why each option is right or wrong →What is the primary objective of a 'lessons learned' meeting conducted after a disaster recovery exercise?
Which THREE of the following strategies should be included in a 'Disaster Recovery Program Oversight' function to ensure long-term viability?