CISSP practice questions
ISC2 · CISSP · 300 questions
Original practice questions for the ISC2 Certified Information Systems Security Professional (CISSP) exam, covering security and risk management, asset security, security architecture and engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security.
This course contains the use of artificial intelligence.
About the CISSP exam
- Exam fee
- $749 USD
- Time allowed
- 3 hours
- Questions
- 100-150 (CAT, adaptive)
- Passing score
- 700 out of 1000
- Format
- Computerized Adaptive Testing (CAT); multiple choice and advanced item types; Pearson VUE / ISC2 Authorized PPC and PVTC Select centers. Languages: Chinese, English, German, Japanese, Spanish.
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Security and Risk Management · 48 questions
- A county CISO is pressured by a council member to hide a ransomware disclosure from the public dashboard while still telling staff that the office follows ISC2 ethics. Which action best aligns with the ISC2 Code of Professional Ethics?
- A city HR director wants security staff to sign only the municipal employee handbook and skip any security-specific ethics acknowledgment. Why should leadership still require an organizational security code of ethics?
- A utilities security manager sees junior analysts sharing cracked commercial scanners 'to save the ratepayers money.' What is the most appropriate ethical response?
- A township contractor asks a security architect to soft-pedal assessment findings so a favorite vendor keeps the renewal. What should the architect do?
- A public-health clinic laptop with resident vaccination records is left unlocked on a picnic table during an outreach event. Which security pillar is primarily violated?
- A county assessor database shows parcel valuations silently altered overnight with no authorized change ticket. Which security pillar was primarily broken?
- A city's online permit portal is taken offline by a volumetric attack the week tax payments are due. Which security pillar is primarily at risk for residents who cannot file?
- A mayor's office disputes whether an emailed contract approval actually came from the city attorney. Which pair of concepts best addresses proving genuine origin and preventing credible denial of the act?
- A library consortium security program only tracks firewall uptime while the board's goal is protecting patron privacy and equitable access. What governance move best realigns security to the mission?
- After a municipal merger, nobody owns security decisions across former city and county IT. What should leadership establish first to restore oversight?
- A school district chart lists 'everyone is responsible for security' with no RACI for data owners versus custodians. How should leadership clarify roles?
- A transit agency must map controls for both federal grant auditors and card-payment compliance. Which approach best structures governance?
- After a breach, residents claim the city never researched reasonable safeguards before outsourcing billing. Which distinction best frames that claim?
- A parks department discovers a contractor exfiltrated membership PII. Beyond internal policy, what must leadership recognize?
- A GIS team installs extra seats of mapping software by sharing one license key across field tablets. What compliance problem does this primarily create?
- A tourism board wants to host resident contestant photos on a foreign social platform's free tier. Which concern should security raise first?
- A city CRM for 311 tickets includes medical notes from homeless outreach. What privacy approach should the security leader emphasize?
- A vendor contract promises 'bank-grade encryption' but the city also has a state records law. How should the security manager treat these drivers?
- An employee allegedly emailed sensitive permit lists to a personal account. HR wants an internal review before any police call. Which investigation type and purpose does that describe?
- A ransomware crew encrypts court case files; prosecutors may pursue criminal charges while the city also sues a negligent MSP. How do these investigation paths differ at CISSP breadth?
- A payment processor used for recreation fees triggers an industry-standard forensic review after suspected card skimming. What should the city security lead understand?
- A mayor demands a one-page 'encryption policy' that also lists exact cipher suites. How should the security manager separate the document types?
- Field crews need step-by-step wipe-and-return steps for retired tablets. Which document type should security publish?
- A recommended phishing-report habit is useful but not mandatory for seasonal volunteers. How should this artifact be classified?
- A county has draft policies that never left SharePoint. What does effective implementation still require?
- After a regional power outage, a city must restore systems under limited generator capacity. Stakeholders argue for 911 CAD, payroll, and the social-media desk. How should the business impact analysis prioritize restoration?
- Sanitation routing depends on a single SaaS vendor with no contracted alternate. What should the business impact analysis explicitly surface for continuity planning?
- After completing a BIA, a county has budget to harden only a subset of processes before storm season. What is the most appropriate next step for continuity investment?
- City council demands 'full continuity' for a rarely used intranet wiki equal to water SCADA HMI remote access. What should the security leader do?
- HR plans to skip a background check for a temporary records clerk who will handle sealed juvenile case files. What personnel security issue does this create?
- Seasonal park hire packets omit security policy acknowledgments and NDA language even though workers will use shared city devices. What control gap should be flagged?
- A network administrator is terminated on Monday, yet VPN and badge access remain active through Thursday. What personnel security failure is demonstrated?
- An external consultant is granted standing domain admin 'for convenience' with no contract security clauses or time-bound access. What should the city require instead?
- A permit-system risk workshop lists 'hackers' as the only entry without linking specific weaknesses in the application or its environment. What is missing for sound risk identification?
- Leadership wants a single red/yellow/green score for every city system without defined likelihood or impact criteria. What should the risk practitioner insist on?
- For a low-impact municipal brochure website, leadership considers cyber insurance and formally accepting residual risk after basic hardening. Which statement best describes this approach?
- Facilities labels a new lobby camera system 'preventive' though it primarily records incidents after they occur for later review. How should the control type be classified?
- A city's risk register is refreshed only during the annual budget cycle even though systems and threats change monthly. What improvement best aligns with sound risk management?
- A municipality invents a unique risk-scoring scheme that external auditors familiar with NIST- and ISO-class approaches cannot map. What should the security program prefer?
- Before launching a resident chatbot that answers tax questions, what security activity should the team perform early in design?
- Architects debating a new permitting portal disagree: one wants STRIDE-style threat categories; another says abuse cases are unnecessary because 'users are mostly honest.' What should the program choose?
- A transit mobile app adds in-app payments, but the team never revisits the threat model created for the earlier schedule-only release. What is required?
- Bargain network gear from an unknown reseller arrives with broken tamper-evident seals. What supply-chain risk concern should procurement and security raise first?
- A city is selecting a court e-filing SaaS provider. Which SCRM mitigation set best fits the procurement security requirements?
- A critical public-alert vendor offers no security SLA and no contractual right to audit. What SCRM gap does this represent?
- Annual sixty-slide PDF security training for city staff shows about two percent completion. Which change best improves awareness effectiveness?
- City help desks now face deepfake voice calls and AI-assisted phishing, but security training content has not been updated in years. What should the awareness program do?
- Leadership asserts 'we have training' but never tracks phishing click rates or other behavior-change indicators. What does an effective awareness program require?
Asset Security · 30 questions
- Building-permit PDFs, sealed adoption records, and public meeting agendas sit in the same file share without labels. What Domain 2 practice should drive their different handling?
- SCADA historian servers and lobby information kiosks are inventoried under one generic 'IT equipment' class with identical controls. What correction is needed?
- A city records clerk invents ad-hoc labels such as "super-secret-plus" that no other department recognizes. What should the information security program prefer for classification?
- Public works posts FOIA-ready monthly road reports, but a supervisor marks every file Confidential, blocking routine public release. What risk does this primarily illustrate?
- After water-quality lab results are labeled Sensitive, which next step best reflects how classification should drive asset security?
- Printed jury questionnaires marked Confidential sit unattended on a shared courthouse printer overnight. Which action best addresses the underlying asset-security gap?
- USB drives holding open case files circulate among court interns with no labels or checkout record. What should management require first?
- Child-welfare caseworkers discuss open cases, including names and addresses, at a crowded municipal cafeteria. Which control gap is most directly illustrated?
- An assessor emails a spreadsheet labeled Confidential—containing taxpayer identifiers—unencrypted to a personal Gmail account for weekend work. What does this primarily violate?
- Guided tour groups walk through operations areas where detailed classified facility maps remain posted on open walls. What should the security program tighten?
- Requests for access to the property-tax database stall because no official will approve them—ownership of the information asset was never assigned. What should the city establish?
- After a flood damages city hall, recovery stalls because the city cannot list which servers, badges, and workstations existed in the building. What capability was missing?
- Emergency management maintains custom routing algorithms and proprietary GIS layers that are critical to response, yet they appear nowhere in the asset register. What should the inventory include?
- New municipal laptops ship straight to end users with local administrator rights and no full-disk encryption. Which asset-security practice was skipped?
- Retired public-safety radios still appear as "active" in the configuration management database months after collection. What asset-management principle is most clearly broken?
- A contractor stores and processes photos submitted through the city's 311 app. Which mapping of data roles is most accurate?
- A summer festival wristband app demands each attendee's full Social Security number solely to pick up a colored band at the gate. What principle should the privacy and asset-security review apply?
- Chat logs from a temporary COVID information hotline are kept forever "just in case," long after the program ended and beyond any legal hold. What should govern these records?
- Surplus office PCs sold at the city auction still yield recoverable files with common freeware tools. Which issue must disposal procedures address before sale or reuse?
- The city shreds Confidential paper on schedule but has no approved destruction process for failed hard drives pulled from servers. What should asset security require?
- Badge-system software will reach vendor end-of-life next fiscal year, and no replacement budget line exists. How should the security program treat this situation?
- Perimeter firewall appliances are past vendor end-of-support and no longer receive security patches. What is the most accurate asset-security assessment?
- A litigation hold requires preserving certain email records even though the mail platform will be replaced next quarter. Which distinction should guide planning?
- A court e-filing module will lose vendor support in eighteen months. What timing best aligns with asset-security practice?
- Smart thermostats across city buildings are abandoned by the manufacturer with no further firmware updates. What should the asset-security response prioritize?
- File servers encrypt taxpayer data at rest, yet internal APIs send Social Security numbers in cleartext across the city WAN. Which data-protection gap is illustrated?
- A small public library cannot implement every control in a full federal baseline yet still handles patron privacy data. What approach best fits asset-security practice?
- A county assessor’s office needs encryption and logging baselines for resident tax files. Leadership wants something defensible at audit time, not tips pulled from random blogs. How should the security architect select those standards?
- Residents’ tax return PDFs keep leaving the city network through clerks’ personal webmail accounts. Which control class best detects and blocks that exfiltration while still allowing approved business email?
- Facilities staff store digital building plans in an unsanctioned consumer cloud drive that IT cannot see or govern. Which control approach best restores visibility and policy enforcement over that shadow SaaS use?
Security Architecture and Engineering · 39 questions
- A public-lobby kiosk in city hall was joined to the domain as a Domain Admin account “so Windows updates keep working.” What redesign best applies least privilege?
- Election-results uploads currently depend on a single perimeter firewall between the upload server and the internet. What architecture change best reduces single-control dependence?
- A new resident-services portal grants guest access to all modules whenever the identity provider is unreachable. What secure-design change should the architect require?
- In the municipal ERP, the same accounts-payable clerk can create a new vendor record and approve that vendor’s payment. Which design change best applies separation of duties?
- Remote assessors historically received broad trust to every sensitive appraisal app once their VPN connected. What access design best aligns with zero-trust principles?
- A city is building a resident AI chatbot that will process service requests containing personal data. Which secure-design principle should be baked into the project from the first architecture reviews?
- A military-adjacent emergency operations center must prevent staff with lower clearances from reading higher-classified briefings. Which classic access model’s confidentiality rules best match that goal?
- Water-quality lab instruments must reject lower-integrity telemetry that could corrupt validated sensor readings. Which classic model’s integrity focus best guides that design?
- Architects designing a multilevel public-safety records system must choose a classic model based on protection goals. When the dominant requirement is stopping unauthorized disclosure across clearance levels, which selection is most appropriate?
- A grant requirement states the city must "protect Criminal Justice Information in transit." Which control set best follows from that stated requirement?
- Legacy court case-management software cannot enforce MFA natively, yet remote clerks must keep using it. What is the most appropriate response?
- A proposal would require hardware security tokens for every anonymous brochure PDF on the parks website. What principle should guide a more appropriate control decision?
- Detective laptops must bind full-disk encryption keys to evidence of platform integrity before unlocking. Which capability best supports that design?
- A custom GIS plugin repeatedly corrupts neighboring processes by writing into their memory spaces. Which operating-system capability should architects insist on to contain that class of failure?
- An evidence-management system must cryptographically protect stored body-worn camera video at rest. What should architects treat as a required information-system capability?
- Thick-client tax software caches credentials on clerk workstations, and the backend database grants a single service account rights far beyond its job. What is the best remediation focus?
- A wastewater plant's PLC network was flat-bridged to city Wi-Fi "for convenience," exposing control traffic to the corporate wireless. What architectural response is most appropriate?
- The city is moving online permitting to a SaaS platform. Which statement best reflects how shared responsibility changes versus on-premises hosting?
- Smart parking sensors and edge gateways were deployed without a reliable patch or certificate-update channel. What risk assessment conclusion is most accurate?
- A 311 rewrite uses microservices, containers, and serverless functions with APIs left wide open between services. Which security concern should architects address first among those patterns?
- Election-night tabulation virtual machines share hypervisors with public web servers, and a research HPC cluster adds further multi-tenant exposure. What architectural concern is most critical?
- A parking-pay mobile app includes a homegrown cryptographic module that invents its own unreviewed network protocol. What is the primary architectural vulnerability?
- A city discovers dozens of TLS certificates for public portals with no inventory, no owner, and no scheduled rotation. Which cryptographic lifecycle action should the security architect prioritize first?
- County IT must encrypt multi-terabyte nightly backups for cold storage and separately assert agency identity when calling a partner court API. Which crypto method pairing best fits those two use cases?
- Two municipal court case-management systems must authenticate each other with mutual TLS. What PKI capability is most essential for that design?
- A city plans to encrypt archival tax records that must remain confidential for several decades. Which approach best reflects algorithm agility and emerging quantum awareness?
- An auditor asks whether the city can explain how brute-force, man-in-the-middle, and side-channel attacks threaten its deployed cryptography. What is the best demonstration of that understanding?
- A municipal payment portal uses a well-regarded cipher suite, yet testers recover plaintext via a padding-oracle style flaw and weak random number generation for nonces. Where should remediation focus?
- After a city Active Directory compromise, responders find reused NTLM hashes, forged Kerberos tickets, and ransomware staging. Which engineering focus best addresses the crypto and authentication-material risks highlighted by those attack methods?
- Facilities proposes placing a new network closet directly under a restroom drain line to shorten cable runs. What site-design response is most appropriate?
- A county is fitting out a municipal server room. Which control set best reflects appropriate facility engineering for that space?
- Digital evidence lockers and offline backup media for the police department currently sit on open shelves in a shared admin office. What facility control change is most appropriate?
- A riverside 911 communications facility sits in a floodplain with a history of utility outages. Which facility-planning emphasis is most critical?
- City hall needs a public lobby for visitors and badge-only work areas for records clerks handling sensitive files. How should facility controls be designed?
- A CAD replacement project skipped security requirements analysis and plans to "bolt on" controls the week before go-live. What lifecycle guidance should the security architect insist on?
- Before accepting a vendor-built citizen portal, the city must confirm security requirements were actually met. Which lifecycle activity does that describe?
- The city is decommissioning an old ERP. Which retirement actions are most essential from a security perspective?
- A new municipal records system is entering architectural design. What must occur regarding security before that design hardens?
- A small parks-and-recreation registration app is being given a highly custom, complex single sign-on stack that few staff understand. What secure-engineering response is most appropriate?
Communication and Network Security · 39 questions
- While troubleshooting a broken encrypted session between a city workstation and a cloud case portal, an engineer needs to reason about which networking layer typically provides confidentiality services for that session. Which approach best applies OSI/TCP-IP models?
- During IPv4/IPv6 dual-stack rollout, a city team treats anycast the same as local subnet broadcast for service discovery and opens overly broad multicast groups. What should the architect emphasize?
- Network staff still use cleartext Telnet to manage closet routers for a municipal campus. What is the most appropriate remediation?
- City VoIP phones and iSCSI storage traffic share the same congested campus links with no QoS and no segmentation. What risk assessment conclusion is most accurate?
- A city's microservices platform firewalled only north-south Internet edges while east-west service-to-service chatter remains unmonitored and unrestricted. What design correction is needed?
- County election systems require stronger isolation than general office IT, including management that does not ride the same production voting network. Which approach best matches that need?
- Finance servers and guest Wi-Fi clients currently share one flat VLAN in city hall. What logical segmentation approach should the architect apply?
- Incident responders trace lateral movement from a compromised lobby printer into the CAD network. Which network-security approach best limits that path going forward?
- A city Internet edge peers with two ISPs for the municipal data center. Engineers discover inbound routes accept almost any prefix and there is no scrubbing or rate-limiting plan for volumetric floods. Which design change best hardens ingress and egress at this peering edge?
- A parks department still runs city Wi-Fi with outdated cipher suites, while field crews also deploy Bluetooth beacons and Zigbee sensors for irrigation telemetry. Which approach best strengthens wireless security across these municipal links?
- Building inspectors tether GIS map updates over personal 5G hotspots with no mobile device management and no split-tunnel policy for city applications. Which control set best addresses the cellular and mobile network risk?
- A county publishes emergency-alert pages through a content delivery network. Architects worry that the origin is reachable directly and that poisoned cache objects could mislead the public. Which CDN design practice best addresses those concerns?
- A municipality replaces branch routers with SD-WAN and API-driven SDN controllers. A mis-pushed policy briefly black-holed traffic and later opened an unintended path between guest and finance VLANs. Which security awareness should guide ongoing SD-WAN and SDN operations?
- Municipal permitting and payment workloads are moving into a virtual private cloud. Planners need subnetting, gateways, and isolation that match sensitivity. Which VPC design principle is most appropriate?
- A city’s SOC cannot tell whether large outbound transfers from a records office are backups or exfiltration because no flow telemetry is collected on core egress. Which design addition best improves detection and fault awareness?
- Attackers induce abnormal jitter and latency on the WAN path that carries VoIP for the city’s 911 call-taking centers. Which statement best reflects how bandwidth, latency, jitter, and throughput should inform secure and resilient design?
- On the city’s core switches, management SSH and SNMP share the same VLANs and paths used by ordinary user data, with no ACL restricting who can reach the management plane. Which change best improves transport architecture security?
- A county portal still offers SSL and early TLS for 'compatibility,' including connections to citizen payment pages. Which protocol decision aligns with modern secure design?
- Fire stations need resilient connectivity back to the city’s public-safety systems. Which network architecture best meets secure design for these distributed sites?
- A metro fiber consortium carries traffic for several cities. One network team proposes skipping encryption on overlays because 'the underlay fiber is private.' Which conclusion is correct?
- Campus routers exchange routing updates and device management using protocols with authentication disabled, allowing trivial spoofing of peers. Which action best hardens protocol selection and configuration?
- A water utility’s OT network for pumps and PLCs was flatly trusted to the IT business network so billing apps could read meter data. Which segmentation approach is most appropriate?
- Public library Wi-Fi must serve patrons without reaching staff file shares or the integrated library system. Which wireless design best enforces that separation?
- Before accepting a vendor’s redesign of the city WAN and campus edge, security architects must review the proposal. Which review focus best applies secure design principles holistically?
- Core distribution switches for city hall lack redundant power supplies, and maintenance contracts have lapsed past end-of-support. Which operational concern is most security-relevant?
- Copper Ethernet runs for a municipal annex travel in unlocked hallway cable trays where visitors can reach the bundles. Which control best addresses transmission-media risk?
- Unknown devices freely attach to the campus LAN at a municipal operations center. Which control best restricts network admission?
- Roaming assessor laptops connect from hotels and home networks to municipal apps but lack host firewalls and modern endpoint detection. Which measure best addresses this network-component concern?
- Auditors find default SNMP community strings still enabled on routers that manage traffic for utility billing. Which hardening step is most urgent?
- A failover WAN link for the courthouse activates during outages but intentionally bypasses the primary firewall and IDS to 'guarantee connectivity.' Which principle should redesign follow?
- Administrators currently manage city firewalls from the same in-band production networks used by employees. Which management approach is preferred where practical?
- End-of-support wireless access points remain in city lobby SSIDs and no longer receive security patches. Which lifecycle action is most appropriate?
- City council chambers use cloud collaboration rooms and softphones with open dial-in numbers and weak meeting locks. Which practice best secures voice, video, and collaboration channels?
- County network admins still share a jump-host password over cleartext chat to reach core routers. Which change best implements secure remote administrative access?
- A water utility’s remote reservoirs rely on satellite and microwave backhaul that can be intercepted or spoofed. Which protection best addresses integrity and confidentiality for that data path?
- Telecom and hardware vendors dial into municipal SCADA support modems with no monitoring or access constraints. What should the security architect require for third-party connectivity?
- A sheriff’s office exchanges Criminal Justice Information (CJI) with state systems and also runs a public website. How should channel security be matched to data sensitivity?
- Hybrid municipal staff need to reach internal desktops from home. Which remote workforce access pattern is appropriate?
- A city allows vendor engineers into internal systems for after-hours repairs but rarely watches those sessions. What oversight should be added to third-party communication channels?
Identity and Access Management (IAM) · 39 questions
- A county court hosts sealed juvenile records that must stay available only to authorized staff. Which access approach correctly addresses both information and systems?
- Badge readers on the police evidence room unlock automatically when power fails. What facility access design principle should the security architect enforce?
- A city’s public snowplow-location API accidentally shares the same exposure path as internal fleet-admin services. What access-control boundary should be applied?
- A municipality protects both a data-center cage and a public library self-checkout kiosk. How should access-control strength be applied?
- An auditor finds a stolen city badge can be paired with passwords written on sticky notes at workstations. What lesson about combined physical and logical controls applies?
- A county clerk’s office grants application rights user-by-user instead of by job function for clerks versus auditors. Which identity strategy should replace that practice?
- Finance staff reach the treasury network over VPN using passwords alone. Which authentication strategy change is most appropriate?
- Library staff leave authenticated sessions open on shared public-service PCs between patrons. What session-management control should be required for sensitive apps?
- Remote contractors receive municipal accounts from an emailed spreadsheet with no identity proofing. What registration practice should replace that process?
- County applications currently force unique passwords everywhere, while a trusted state identity provider already authenticates the same employees. Which approach applies federated identity management?
- Shared service-account passwords for city integrations are stored in a wiki editable by dozens of staff. What credential-management change is required?
- Residents must maintain twenty separate logins for related city services. How should single sign-on be applied?
- Fire-department IT admins hold standing domain privileges for tasks they perform only a few times a year. Which authorization design reduces that risk?
- Legacy on-premises mutual-aid applications must accept identities from a partner agency’s identity provider. Which design best secures that on-prem federation?
- A SaaS HR platform will authenticate city employees via the city’s identity provider. What must the architect manage for cloud federation?
- Some municipal apps remain on-premises while others are SaaS, yet leadership wants one coherent identity strategy. Which approach fits hybrid federation?
- Federation to a low-assurance partner app currently releases full Social Security numbers with every login. What trust-boundary fix is required?
- A firefighter separates from the department but still can open mutual-aid apps through federation. What lifecycle control is missing?
- A building-permit system needs permissions that match clerk job duties rather than one-off exceptions. Which authorization model should be implemented?
- A city fusion center stores highly sensitive investigative files under system-enforced classification labels, while a parks department team drive lets folder owners decide who can share documents. Which access-control contrast best describes these two approaches?
- A municipal ERP portal must allow finance staff access only during published business hours and only from city office subnets. Which authorization approach best matches that design?
- Mobile health inspectors need access to case records only when their clearance is sufficient, they are within an assigned district geofence, and the request occurs during their shift. Which model best expresses that decision?
- A county employee account attempts to sign in at 03:00 from a country the worker has never visited. What access-control response best reflects a risk-based decision?
- A city zero-trust design uses a central policy engine to evaluate access requests while API gateways and VPN concentrators only allow or deny based on that decision. Which roles do those components play?
- A library catalog system holds only public bibliographic data and needs simple staff roles, while a police evidence vault needs label-enforced separation. What should the CISO emphasize when choosing authorization models?
- A quarterly IAM review for a city internship program finds dozens of dormant accounts that still have portal access months after interns left. What control practice does this finding primarily reinforce?
- A permitting clerk transfers to the assessor's office but retains write access to the old permitting workflow for six months. Which IAM lifecycle gap is most evident?
- A utility billing clerk is promoted to supervisor. Leadership wants the new role approvals without keeping every former clerk entitlement. What is the soundest approach?
- Server admins on the city virtualization cluster use uncontrolled sudo and local admin elevation with little logging. What should governance require first?
- An audit finds batch-job service accounts for the water billing system with non-expiring passwords and interactive logon rights on jump hosts. Which remediation best hardens those accounts?
- A smart-city pilot ends, yet project AD groups and API keys still grant access to IoT dashboards. What should IAM operations prioritize?
- HR ticket-only provisioning for a large city workforce causes multi-day delays and frequent wrong-role assignments. Which improvement best addresses reliability while retaining governance?
- A municipality is modernizing identity: a central directory, MFA for remote access, and federation to cloud SaaS used by multiple departments. What implementation priority best keeps those pieces coherent?
- Help-desk phishing calls successfully harvest SMS one-time passcodes from city employees. Which authentication direction best reduces that risk where feasible?
- Remote staff authenticate with MFA, yet unmanaged personal laptops freely reach the tax-system VPN. What gap should the access design close?
- A 311 mobile app embeds long-lived static API keys that call backend microservices. Which change best improves service-to-service authentication?
- Emergency break-glass admin accounts for the city identity platform are used weekly for routine changes and generate no alerts. What redesign is most appropriate?
- SIEM dashboards show repeated failed logons and impossible-travel alerts for municipal SSO, but the identity team never tunes or responds to them. What practice is missing?
- Several legacy line-of-business apps still require NTLM-only authentication and thereby block MFA enforcement for those pathways. What should the security program prioritize?
Security Assessment and Testing · 36 questions
- A city CISO asks the internal security and audit teams to design ongoing tests of IAM and network controls that the organization itself will execute under city authority. What are they primarily building?
- Leadership hires an outside firm to review the city access-control policy implementation for gaps, without requesting a formal regulated attestation report. Which assessment type best fits?
- The city parking-payment platform must satisfy card-brand expectations with an independent assessor's formal report. Which strategy element is essential?
- An assessment strategy covers only the on-premises CAD servers and ignores cloud email and hybrid identity integrations. What design flaw does that reveal?
- A county runs vulnerability scans on rapidly changing cloud citizen apps only once per year. Risk and change rate are both high. What should leadership conclude about the assessment strategy?
- A city CIO must choose assessors for the annual review of the tax-collection system and wants both independence and deep knowledge of legacy workflows. Which approach best balances those tradeoffs?
- Quarterly authenticated scanning of the county property-appraisal system reports missing OS and application patches. What is the primary security-assessment purpose of that activity?
- A municipality is launching a new online payments portal and wants an exercise that both attacks and improves detection simultaneously. Which team model best fits that goal?
- Domain-controller privileged logons for the school-district directory have gone unreviewed for months. Which testing activity should the security manager add first?
- After a change window, the housing authority needs continuous proof that resident-portal MFA still completes successfully. Which testing approach best provides that assurance?
- Custom fee-calculator code for city building permits is about to release. What should security assessment include before production?
- Testers validating the park-and-recreation permit site only exercise successful purchase paths. What should they add to strengthen security testing?
- A vendor claims the library catalog API is 'fully tested,' but cannot show which security suites or paths were exercised. What should the city demand?
- The city's 311 mobile app exposes a citizen UI, backend APIs, and network entry points. How should security testing be scoped across those surfaces?
- Transit IT wants ongoing proof that SIEM detections fire for common attacker techniques against fare systems. Which control-testing approach fits best?
- Card payment terminals at the municipal recreation center must meet PCI-aligned hardening rules. What assessment activity confirms systems still match required baselines?
- Leadership reviews only automated vulnerability-scan scores for the courts case-management system and calls the program a full penetration test. What correction should the assessor make?
- A water utility plans penetration testing near pressure-control PLCs. What scoping principle is most important?
- The county identity team needs management-visible evidence about joiner-mover-leaver health. Which process data should assessment collect?
- The CISO prepares a quarterly pack for the city manager on security-program health. Which data best serves as key performance and risk indicators?
- The public-works backup dashboard shows nightly job success, yet nobody has restored a sample lately. What process data is still missing for assurance?
- After mandatory cyber awareness for city employees, leadership asks whether behavior improved. Which metrics should be collected?
- After a tabletop on courthouse continuity, what process data most improves BC/DR maturity for the next cycle?
- SOC analysts compile rich security process metrics that never leave the operations drawer. What is required for those metrics to fulfill their assessment purpose?
- A vulnerability report for the business-license portal lists CVSS scores but no owners or deadlines. What must reporting add to drive remediation?
- A critical library catalog finding will not be fixed this quarter due to a vendor dependency. How should that decision be handled?
- An independent researcher privately reports a flaw in the city permit portal. What process should the city follow?
- Assessment results for the emergency-dispatch network must inform both the city council and the engineering team. How should reports be tailored?
- Scanner output for the tax-assessor web farm is flooded with noise, and analysts fear real issues are buried. What analysis step is required?
- Developers report that a high-severity finding on the utility billing API is fixed. What should happen before the finding is closed?
- A city CIO asks internal audit to review IT general controls for the finance ERP before year-end. What should that engagement primarily evaluate?
- External financial auditors for a county ask for evidence that IT controls affecting the CAFR reporting path are operating. What is the security team's best facilitation focus?
- A transit authority must satisfy a federal grant condition that requires an independent security audit of fare-collection systems. Which approach best meets that requirement?
- A municipal hybrid estate runs voter-registration data in a cloud SaaS tenant and legacy case files in an on-premises data center. What should an enterprise security audit scope include?
- County security leads want audits to stop becoming last-minute fire drills. What practice best prepares teams for efficient facilitation?
- A city CISO contrasts an annual independent audit of payroll ITGCs with the SOC's weekly vulnerability scans. What distinction best explains their different purposes?
Security Operations · 39 questions
- After a suspected insider leak of permit-office records, investigators seize a clerk's laptop and relevant log exports. What practice is essential for those materials?
- A municipal investigation into stolen case-management data may involve desktops, network captures, and city-issued phones. What approach best reflects sound digital forensics practice?
- HR and legal counsel request a report after an investigation into misuse of a library-patron database. What quality should that investigation report emphasize?
- A city's SOC wants better visibility across utility SCADA jump hosts, ERP, and public web apps. What logging approach best supports monitoring and actionable alerting?
- County network defenders deploy intrusion detection and prevention for traffic to citizen-services portals. What operational practice is most important after install?
- Analysts notice a clerk account querying property-tax records at 2 a.m. from an unusual location. Which monitoring mix best helps confirm anomalous insider-style behavior?
- A utility security team worries about sensitive GIS exports leaving the network. What monitoring emphasis best addresses that risk while staying effective over time?
- Firewall and server configurations for a city DMZ keep drifting from the approved build. What configuration-management approach best reduces that drift?
- Night-shift NOC operators for a transit network need console access to keep services running. How should their access be set?
- A county treasurer's office wants stronger day-to-day security operations around privileged work. Which control set best addresses conflicting duties and elevated accounts?
- Backup tapes holding court records travel by courier to an offsite vault. What media-protection practice is most appropriate in transit?
- Ransomware encrypts a public-works file share. Which sequence best reflects a complete incident management lifecycle response?
- A confirmed breach of a 311 call-center database may require notice beyond the SOC. What escalation practice is most appropriate?
- Citizens use a city permitting portal on the public internet. Which control set is most appropriate to operate for that exposure?
- A school-district SOC is choosing complementary host and deception controls beyond the firewall. Which mix is used appropriately?
- A mid-size city outsources after-hours monitoring to an MSSP and pilots ML-based anomaly detection. What oversight is most important?
- Water-treatment OT controllers and office laptops share a vulnerability management program. How should patching be handled?
- An emergency firewall change stops an active attack on a courts case-management VPN. What must still happen afterward, and what should normal changes require?
- Facing ransomware risk, a city plans backups for tax and utility billing systems. Which storage strategy is most thoughtful?
- A county 911 CAD system must resume within hours after a data-center outage, while a rarely used archive warehouse can wait days for space and hardware. Which recovery-site strategy best matches those two needs?
- After a flood closes City Hall’s primary data center, the emergency manager asks security to run the disaster recovery playbook end to end. Which set of activities best reflects implementing DR processes?
- A transit authority wants to validate its DR plan without cutting over live rider apps yet. Leadership also wants a later exercise that runs recovery systems in parallel with production. Which testing progression best fits?
- A city clerk’s office must keep issuing marriage licenses if the permit software is offline for a week. IT DR restores servers, but leadership asks security to join broader continuity work. What should that participation emphasize?
- A new civic records annex needs layered physical protection from the property line inward. Which control pairing best matches perimeter versus internal needs?
- County inspectors who travel to remote sites and clerks who handle cash both face personal-safety risks, including duress and MFA-fatigue social engineering. Which operational focus best addresses personnel safety and security?
- A library consortium’s SOC currently opens a few firewall logs when someone complains. Leadership wants continuous monitoring with measurable outcomes. What change best establishes that program?
- After containing a ransomware incident that hit a water-utility SCADA jump host, the city files a polished after-action PDF and shelves it. What should happen next for lessons learned to improve operations?
- A public-health clinic still runs FDA-cleared diagnostic devices that the vendor will not patch this year. Vulnerability scans keep flagging them. What is the most appropriate security-operations response?
- A city’s online building-permit system must keep issuing permits if the primary processing site fails. Leadership wants failover across sites with enough capacity. Which approach best meets that need?
- During a declared DR event for the county tax portal, who must receive timely, pre-planned communications and why does that matter operationally?
- A regulated municipal health-benefits system schedules a parallel DR test that may briefly affect reporting interfaces. What communications obligation should the test plan include?
- Compared with ordinary open-plan offices, how should a police evidence-storage room’s internal physical controls differ?
- Server administrators for a city’s identity directory currently share a standing admin password on a sticky note. Which privileged-account operations practice should replace that approach?
- Endpoint protection coverage across city departments is uneven, definitions are stale on many PCs, and detections often sit untriaged. What should anti-malware operations prioritize?
- Investigators believe a stolen city-issued phone holds messages relevant to a fraud case. What must guide collection of mobile-device artifacts?
- A change to open a database port from the Internet is headed to the city’s change advisory board without security review. Why should security participate in that CAB process?
- A DMV branch must still serve walk-in customers when the licensing software is down. Ops teams schedule drills for paper tickets and manual queues. What are these exercises primarily validating?
- Public-works employees have been posting photos of badge printers and server closets from inside restricted areas. What should personnel security awareness in operations emphasize?
- During a large public event, municipal networks experience congestion while emergency voice and video must stay usable for first responders. How does QoS support resilience here?
Software Development Security · 30 questions
- A county is building a new benefits-enrollment application. Leadership proposes a single security review one week before go-live. What SDLC practice should security advocate instead?
- The city’s internal DevOps team is adopting continuous delivery, while a legacy vendor still delivers waterfall releases for a mainframe tax batch system. How should security engage both?
- A CIO asks whether the municipality’s custom-development practices are immature or advancing. Which approach best answers that question?
- Developers want to push an emergency schema change straight into the production court-records database overnight. What secure-SDLC expectation should govern that change?
- A high-risk rewrite of a court case-management system is starting. Which teaming model best includes security from the outset?
- A city permitting portal went live last quarter, yet new dependency CVEs keep appearing. What Domain 8 practice should continue as part of SDLC sustainment?
- Municipal developers install unofficial IDE plugins and pull unvetted libraries into a tax-assessment build. Beyond source review, what else must security harden?
- An attacker targets the city's CI/CD system that builds and deploys the citizen services portal. Which pipeline protections should the security architect prioritize?
- The county wants stronger software configuration management for its shared code repositories. Which control set best addresses repository security?
- Before promoting custom city code, the AppSec lead wants defects found without executing the program. Which testing approach belongs in the pipeline?
- Security wants to probe a running staging build of the public parks reservation portal the way an external attacker would. Which test fits?
- A municipal fee calculator ships with dozens of open-source packages. Which control specifically finds known-vulnerable third-party components?
- For a complex city case-management application, testers want runtime insight combined with code-level analysis during functional tests. Which approach matches?
- Developers began using unapproved cloud scanners that upload municipal source to third-party tenants. What should leadership do first for tooling governance?
- A sudden configuration change in production broke the city's utility billing API. What software-security control would best support investigation and accountability?
- SAST and SCA flooded the backlog after a civic services scan. How should the team prioritize remediation?
- Leadership asks whether mandatory SAST gates actually improve outcomes for city applications. What should AppSec measure?
- Before promoting the new municipal grants portal to production, what should the release board require?
- Two weeks after launching a new online license renewal feature, how should the city assess software security effectiveness?
- The planning department wants to buy a commercial off-the-shelf permitting package. What should security do before purchase?
- A city analytics team wants to embed an open-source charting library in an internal dashboard. What assessment is required?
- The city adopts a managed enterprise HR module plus third-party add-ons. What risk posture change should leadership recognize?
- IT must choose SaaS, PaaS, or IaaS for a new citizen engagement app. Why does that choice matter for software security?
- Procurement is evaluating a high-risk vendor for a courts case-management platform. Which due-diligence artifacts are proportionate?
- City developers are wiring a new payment callback that builds database queries from raw request fields. What source-level issue must secure coding prevent?
- The city publishes a public API for street-closure data used by third-party apps. Which controls are essential?
- Municipal engineering wants consistent secure coding across teams building internal services. What should leadership adopt?
- The platform team wants security controls to travel with infrastructure and app deployments automatically. Which approach fits?
- Developers use an LLM coding assistant while building a municipal records search service. What oversight is mandatory?
- The city's delivery pipelines block merges that violate secure coding standards, yet emergencies occur. How should exceptions be handled?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by ISC2, Inc.