Free CISSP-ISSAP Practice Test Questions and Answers (2026)

Last Update Check
View Mode
Q: 1
The network you administer allows owners of objects to manage the access to those objects via access control lists. This is an example of what type of access control?
Options
13 comments in the community discussion
1
Option A here. RBAC can use ACLs too and I've seen setups where role owners control access. The question says 'owners', so maybe it's not the best fit, but I think it still works in some systems. Not totally sure, open to another view.
I’d say D since "owners" managing ACLs is textbook DAC. A is tempting because RBAC can use ACLs, but roles aren't owners here.
Q: 2
You work as a Network Administrator for Blue Bell Inc. The company has a TCP-based network. The company has two offices in different cities. The company wants to connect the two offices by using a public network. You decide to configure a virtual private network (VPN) between the offices. Which of the following protocols is used by VPN for tunneling?
Options
16 comments in the community discussion
7
A. but not totally sure if it should be L2TP or IPSec here. L2TP is for tunneling right? Can someone confirm?
1
A
Q: 3
John works as a security manager for SoftTech Inc. He is working with his team on the disaster recovery management plan. One of his team members has a doubt related to the most cost effective DRP testing plan. According to you, which of the following disaster recovery testing plans is the most cost-effective and efficient way to identify areas of overlap in the plan before conducting more demanding training exercises?
Options
15 comments in the community discussion
1
Option B here. Walk-through drill feels the least resource intensive and more efficient than doing a full-scale exercise. Maybe it's a trap but I'm pretty sure this is what most would pick before anything big.
Probably C
Q: 4
In which of the following SDLC phases are the software and other components of the system faithfully incorporated into the design specifications?
Options
18 comments in the community discussion
5
A . Some might get tripped up by B but that's more about verifying, not actually building to specs.
1
A
Q: 5
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of the disaster. In which of the following disaster recovery tests can this task be performed?
Options
15 comments in the community discussion
6
C . Simulation tests are where you talk through the scenario step by step, not just review docs like D. I see why D could look tempting but it's really focused on procedures, not disaster handling specifics.
1
C imo
Q: 6
Which of the following heights of fence deters only casual trespassers?
Options
17 comments in the community discussion
5
B . 3 to 4 feet isn't much of a barrier and fits what the exam usually wants for 'casual deterrence'-just enough to signal property lines but easy to climb. D is tempting but that's more for physical security against determined intruders. Let me know if you see it differently.
4
Option B, nice clear-cut question, matches what I've seen on similar prep exams.
Q: 7
In which of the following types of tests are the disaster recovery checklists distributed to the members of disaster recovery team and asked to review the assigned checklist?
Options
17 comments in the community discussion
6
Option D makes the most sense. Checklist test is just reviewing individual assignments, no team scenario or system disruption like in B or C. The word "simulation" can trip you up here but it's not about simply distributing checklists. If I missed something let me know, but pretty confident!
2
D tbh. Checklist test is just about handing out the docs for review, no group discussions or actual sim work involved. That lines up with NIST and CISSP study guides. Pretty sure on this one, but open if I missed a nuance.
Q: 8
Which of the following encryption modes has the property to allow many error correcting codes to function normally even when applied before encryption?
Options
20 comments in the community discussion
1
A, seen similar on a practice exam. If you want more on this, the official guide gives diagrams for each mode and it really helps nail these details down.
Why would you use CBC or CFB for this when OFB is designed to avoid error propagation in the output stream?
Q: 9
Which of the following is an electrical event shows that there is enough power on the grid to prevent from a total power loss but there is no enough power to meet the current electrical demand?
Options
15 comments in the community discussion
1
C/D? I know blackout means total loss so D looks more accurate, but sometimes people say blackout when parts of the grid go down. Not totally sure which way the exam wants, anyone else pick C?
Maybe C since blackout sometimes gets used when most power is lost but not always 100%, especially in certain regional grid failures. I think it depends how strict the definition is on this exam. Open to counterpoints.
Q: 10
Which of the following processes is used by remote users to make a secure connection to internal resources after establishing an Internet connection?
Options
18 comments in the community discussion
1
Had something like this in a mock, it's C. Tunneling lets remote users create secure VPN connections back to the network after connecting to the Internet. Packet filtering and the others don't provide that direct secure tunnel. Agree?
1
C , tunneling is what's behind VPNs for remote access. It lets users reach internal resources securely after connecting to the Internet. Official study guide covers this well, worth reviewing VPN concepts for CISSP.
Q: 11
Which of the following backup types backs up files that have been added and all data that have been modified since the most recent backup was performed?
Options
2 comments in the community discussion
1
Its B, since incremental backup grabs only new or changed files since the last backup. Confident here.
Q: 12
Which of the following methods will allow data to be sent on the Internet in a secure format?
Options
8 comments in the community discussion
1
B , PPP can do encrypted sessions so I think it fits for secure data online.
1
I actually think B (Point-to-Point Protocol) fits here. PPP can do encrypted sessions using options like ECP, so it should allow secure data over the Internet too. Maybe I'm missing something obvious?
Q: 13
Which of the following plans is designed to protect critical business processes from natural or man- made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes?
Options
5 comments in the community discussion
8
Makes sense to pick C. Business continuity plan is all about keeping key operations running when disaster strikes, not just recovering IT systems like a DRP would. Pretty sure that's what they're asking for here, but open to other takes.
C tbh, BCP is broader and focuses on keeping the whole business functioning, not just recovering specific systems. Disaster recovery plans like A are mostly about IT and data. CISSP usually likes the most comprehensive process answer. Anyone disagree?
Q: 14
In which of the following phases of the SDLC does the software and other components of the system faithfully incorporate the design specifications and provide proper documentation and training?
Options
10 comments in the community discussion
1
Option D-I thought evaluation and acceptance mattered most for making sure requirements are met. That's when you review the system and hand it over, so docs and training feel like they'd fit there. Not totally sure, but seems logical.
B , that's the phase where the system gets built out from design specs and actual docs and training materials are produced. Evaluation is more about reviewing if things meet needs, not creating stuff. That's what I've seen in most SDLC breakdowns, but open to correction if anyone's got a counterpoint.
Q: 15
You are the Network Administrator for a bank. In addition to the usual security issues, you are concerned that your customers could be the victim of phishing attacks that use fake bank Web sites. Which of the following would protect against this?
Options
5 comments in the community discussion
2
Its C, but if the question asked for the best practical protection for average users then maybe B would edge it.
Yeah, it's B. Mutual authentication actually verifies the site so phishing domains get blocked out.
Q: 16

Fill in the blank with the appropriate security method. ____________ is a system, which enables an authority to control access to areas and resources in a given physical facility, or computer- based information system.

Your Answer
6 comments in the community discussion
3
Seen this one in practice sets a lot. Access Control.
Q: 17

Fill in the blank with the appropriate security device. ___________ is a device that contains a physical mechanism or electronic sensor that quantifies motion that can be either integrated with or connected to other devices that alert the user of the presence of a moving object within the field of view.

Your Answer
4 comments in the community discussion
8
Not 100% sure but looks like it's motion detector. Can someone confirm if that's right?
6
Motion detector fits best here, since it's all about sensing movement using sensors. Some might confuse it with a camera or alarm, but those don't quantify motion directly. Pretty sure that's what they want for this. Open to debate if anyone disagrees!
Q: 18

Fill in the blank with the appropriate phrase. The is a simple document that provides a high-level view of the entire organization's disaster recovery efforts.

Your Answer
8 comments in the community discussion
3
Master Disaster Recovery Plan fits best here since it covers the whole organization's efforts, not just specific systems. If the question asked for a more detailed or system-focused doc, it'd be different-like an IT DRP instead of master.
1
Master Disaster Recovery Plan is the phrase, not just Disaster Recovery Plan. DRP alone is too specific to one system or department.
Q: 19

Fill in the blank with the appropriate encryption system. The ______ encryption system is an asymmetric key encryption algorithm for the public-key cryptography, which is based on the Diffie- Hellman key agreement.

Your Answer
2 comments in the community discussion
I think it's RSA for this one.
Q: 20
Which of the following SDLC phases consists of the given security controls: Misuse Case Modeling Security Design and Architecture Review Threat and Risk Modeling Security Requirements and Test Cases Generation
Options
3 comments in the community discussion
D, not A. I just think test cases and requirements are set when you first gather requirements, so D fits for me. Haven't seen those controls listed in the design phase on my projects.
Its D, since requirements and test cases sound like they're made during gathering, right? Not sure though.
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top