Skip to main content
CISSP (Certified Information Systems Security Professional)
Free practice questions12

Free CISSP (Certified Information Systems Security Professional) practice questions

Real exam-format questions from the CertBase CISSP (Certified Information Systems Security Professional) bank — pick an answer and the answer key and explanation follow. No signup needed.

510 questions in the full bank · Bank updated July 2026

Question 01

A security team plans an adversary emulation exercise modeled on a threat group known to target its industry. How does a framework such as MITRE ATT&CK BEST support this assessment?

Question 02

In a public key infrastructure, an employee submits a certificate request and presents identity documents to a registration authority. What is the RA's role in this process?

Question 03

Legal counsel is concerned that deploying a honeypot could constitute entrapment. Which response BEST addresses the concern?

Question 04

A calendar application asks a user for permission to read her cloud file storage so it can attach documents to invitations. In OAuth 2.0 terminology, which participant is the calendar application?

Question 05

On a shared system, a high-privilege process signals data to a low-privilege process by modulating its CPU utilization in a pattern the second process measures and decodes. No files or shared variables are used. How is this communication channel BEST classified?

Question 06

What is the PRIMARY security purpose of establishing configuration baselines and recording systems in a configuration management database?

Question 07

Which type of audit generally provides the HIGHEST level of independence and objectivity?

Question 08

What is the PRIMARY purpose of conducting a business impact analysis (BIA)?

Question 09

An application must encrypt multi-terabyte data sets at rest as quickly as possible, and all encryption and decryption is performed by the same backend system. Which approach is MOST appropriate?

Question 10

A failed solid-state drive containing the organization's most sensitive data cannot be reliably purged or verified because the device no longer responds to commands. What is the MOST appropriate disposition?

Question 11

A security monitoring team detects large volumes of data leaving the network encoded inside the payload fields of echo request packets. What technique is being used?

Question 12

Following NIST SP 800-63B, a security team wants to slow online password guessing without letting attackers weaponize the control. Why is request throttling generally preferred over hard account lockout after a few failed attempts?

Detailed explanations like these run throughout the full bank.

One-time payment

Want the other 498 questions?

The full CISSP (Certified Information Systems Security Professional) bank includes 510 questions with detailed explanations, progress tracking, and performance analytics. Pay once, keep it forever — no subscription.

Get the full bank — $39.99

30-day money-back guarantee · Secure payment via Paddle