TechNuggets Academy
CISSP

Free ISC2 Certified Information Systems Security Professional (CISSP) Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$7498 exam domainsLevel Expert2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Security and Risk Management
A CISSP-certified professional, while performing contracted work, discovers that continuing to follow the client's explicit instructions would violate applicable law. The client insists the work continue as directed. According to the (ISC2) Code of Ethics, the four canons are applied in order of precedence when they conflict. Which canon takes precedence in this situation?
The (ISC2) Code of Ethics lists the four canons in strict order of precedence. Canon I, 'Protect society, the common good, necessary public trust and confidence, and the infrastructure,' always supersedes the other three when a genuine conflict exists, because it protects the broadest set of stakeholders regardless of any single client's or employer's wishes.
Question 2 of 12 · Asset Security
A financial services company's compliance team discovers that a business unit has been storing customer PII in a shared drive without any classification labels. The CISO wants to establish clear, ongoing accountability for determining the classification level of this data. Which role should be assigned this responsibility?
The data owner (typically a business unit leader) is accountable for determining the classification level and protection requirements of data based on its business value, sensitivity, and applicable regulations.
Question 3 of 12 · Security Architecture and Engineering
A government agency is designing a system to enforce mandatory access control where users cleared at a higher classification level must not be able to disclose information to users at a lower classification level, but reading information at a lower level is permitted. Which security model BEST enforces this requirement?
Bell-LaPadula enforces confidentiality via the simple security property (no read up) and the star property (no write down), permitting a subject to read objects at or below its clearance level while preventing it from writing data down to a lower classification, which stops disclosure exactly as required.
Question 4 of 12 · Communication and Network Security
A financial services company must allow a third-party auditor temporary access to a single internal application for a compliance review, without exposing the rest of the internal network. Which solution BEST meets this requirement?
SDP creates a 'black cloud' architecture that hides all resources except the specific, authenticated and authorized application, enforcing least privilege and enabling dynamic, time-limited third-party access.
Question 5 of 12 · Identity and Access Management (IAM)
A multinational corporation needs to provide employees with single sign-on access to cloud-based applications hosted by multiple external business partners, where each partner maintains its own separate identity store. Which technology BEST meets this requirement?
SAML enables federated SSO across organizational boundaries using signed XML assertions exchanged between an identity provider and service providers, allowing browser-based access to partner-hosted applications without either side sharing its credential store.
Question 6 of 12 · Security Assessment and Testing
A financial services company wants to validate that its e-commerce checkout process functions correctly and securely without using live customer data or waiting for actual customer transactions. Which testing technique BEST meets this requirement?
Synthetic transactions are artificially generated actions that simulate real user behavior in a controlled manner, allowing an organization to continuously validate that a critical business process (like checkout) is functioning and secure without depending on real customer traffic.
Question 7 of 12 · Security Operations
A digital forensic investigator arrives at a workstation involved in a suspected intrusion. The screen shows an active command-line session with what appears to be an attacker's remote shell still connected. Per the order of volatility, what should the investigator do FIRST?
The order of volatility dictates capturing the most volatile evidence first. RAM contents (running processes, network connections, encryption keys, the attacker's active session) are lost the instant power is removed, so memory must be imaged before the system is powered down or disconnected.
Question 8 of 12 · Software Development Security
A financial services company is performing security testing on a production-like web application without access to source code, focusing on runtime behavior and simulating external attacker techniques. Which testing methodology BEST fits this requirement?
DAST tests the running application from the outside, simulating attacker behavior against the live system without needing source code access.
Question 9 of 12 · Security and Risk Management
A risk assessment determines that a critical database server has an asset value of $500,000. A successful ransomware attack is estimated to destroy or corrupt 20% of the asset's value (exposure factor), and historical data across similar organizations shows this type of attack occurs on average once every two years (ARO = 0.5). What is the Annualized Loss Expectancy (ALE)?
SLE = Asset Value x Exposure Factor = $500,000 x 0.20 = $100,000. ALE = SLE x ARO = $100,000 x 0.5 = $50,000. The ARO of 0.5 must be applied to the SLE to annualize the loss.
Question 10 of 12 · Asset Security
An organization is decommissioning a batch of solid-state drives (SSDs) that contained data classified as Secret. The security team's standard sanitization procedure calls for degaussing prior to disposal. What is the BEST course of action?
Per NIST SP 800-88 guidance, degaussing relies on magnetic fields and has no effect on flash-based SSDs. Proper sanitization of SSDs requires cryptographic erase or vendor-supported purge commands, followed by physical destruction for the highest classification levels.
Question 11 of 12 · Security Architecture and Engineering
A financial trading platform must ensure that low-integrity data (e.g., unverified market feeds) cannot corrupt high-integrity trade execution records, while high-integrity processes may only access lower-integrity sources through a controlled interface. Which security model was designed specifically to address this integrity requirement?
Biba enforces 'no write up' (a low-integrity subject cannot write to a high-integrity object) and 'no read down' (a high-integrity subject cannot read from a low-integrity object), directly preventing contamination of trusted data by less trustworthy sources.
Question 12 of 12 · Communication and Network Security
A retailer must isolate its cardholder data environment (CDE) from the general corporate LAN to reduce PCI DSS scope, while still allowing specific database traffic between the two zones. Which control BEST achieves this while minimizing scope creep?
Separating the CDE into its own VLAN with a next-generation firewall enforcing least-privilege rules to specific database ports is the standard segmentation approach recognized to reduce PCI DSS scope, since systems outside the CDE with no connectivity path fall out of scope.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CISSP exam — quick answers

How much does the CISSP exam cost?

The exam fee is approximately $749 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 8 domains: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (IAM) (13%), Security Assessment and Testing (12%), Security Operations (13%), Software Development Security (10%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Security and Risk Management →Security Architecture and Engineering →Communication and Network Security →Identity and Access Management (IAM) →Security Operations →