CISSP Certification Guide / Chapter 7
Domain 1 Practice Test: Security and Risk Management
Twenty-five original questions covering the exam blueprint, governance and law, risk management, business continuity, and security policy, with an answer key, rationales, and score-based triage rules for Domain 1.
How to take this test
This test covers everything Domain 1 tested in Chapters 2 through 6: the blueprint and its mechanics, governance and the legal map, the risk vocabulary and mathematics, continuity planning, and the policy and personnel layer. Twenty-five questions is a small sample of what the real exam draws from a 16 percent domain, but it is a fair sample of the ideas, because each question is built on the decision pattern the real exam scores.
Run it the way the CAT runs. Give yourself thirty minutes, which is about a minute and a quarter per question, the pace Chapter 2 set for a 150-item session. Answer every question, even the ones you are unsure of, because a blank is a wrong answer and the engine does not care how you arrived at the one you submitted. Do not look ahead at the answer key, and do not return to a question you have moved past. The real exam gives you no item review, and the practice that transfers is the practice that reproduces the constraint, not the practice that removes it.
One instruction governs how you read the stems. Before you pick a control, name the risk: the asset, the threat, the vulnerability, the response that the facts point to. Most of the questions here are written so that two options are technically familiar and only one fits the facts as stated. When you are torn between two defensible answers, apply the tie-breaker from Chapter 2: which option would a responsible manager defend in front of the board, with the acceptance documented and the accountability named. That rule resolves more of these questions than any vocabulary list.
When you are done, score yourself honestly and read the score interpretation section before you move on. The score is a triage instrument, not a verdict. A rough result in one area of Domain 1 tells you exactly which chapters to re-read, which is information worth more than the number itself.
The 25 questions
-
A candidate answers 101 items on the adaptive exam and the session ends with a pass result. Which explanation is most accurate?
A. The engine reached 95 percent statistical confidence that the candidate’s ability exceeded the passing standard, which it may do once the minimum 100 items are complete. B. The candidate answered all 25 pretest items correctly, which closed the exam early. C. The engine exhausted its stock of easy items and was forced to terminate. D. The exam always ends at the first item count above 100, regardless of performance.
-
A candidate scores well below the proficiency band in Domain 6 but well above it in Domain 1 on a practice analysis, and worries that one weak domain will fail the exam by itself. What is accurate about the real exam’s scoring?
A. The exam is scored per domain, and every domain must be passed independently. B. Items from a domain where the candidate is weak are removed from the scoring pool. C. A single pass or fail is computed over all operational items, so strong performance in a heavily weighted domain can offset weaker performance elsewhere. D. Any domain below the proficiency band triggers an automatic fail once the minimum length is reached.
-
An internal audit team conducts an independent review of the risk management process and reports its findings directly to the audit committee of the board, not to the functions it reviewed. In the three lines of defense model, which line is this team?
A. The first line, because it operates controls. B. The second line, because it monitors operational risk. C. The third line, because it provides independent assurance. D. The board itself, because it oversees the audit.
-
A CISO drafts a risk appetite statement and wants it to carry the organization’s authority so that every business unit’s risk decisions are measured against it. Who must approve it for that to be true?
A. The board of directors or senior management, since risk appetite is a governance decision at the top. B. The CISO alone, as the author and program owner. C. The internal audit team, to keep the measure independent. D. The risk analysts who produced the underlying estimates.
-
After a data breach, a government agency acting on its statutory powers opens an inquiry, issues subpoenas, and may levy fines, applying its own procedural and evidentiary rules. Which category of law is exercising this authority?
A. Criminal law. B. Civil law. C. Contract law. D. Regulatory law.
-
A controller in the European Union discovers that a breach exposed the personal data of customers. Under the GDPR, what is the controller’s first notification obligation?
A. Notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware. B. Notify affected individuals within 24 hours of discovery. C. Notify the data protection officer, who alone decides whether a report is required. D. Notify the national police before any other party.
-
A manufacturer protects a proprietary formula through restricted access, non-disclosure agreements, and need-to-know, and has filed no registration with any government. What does the formula’s legal protection depend on?
A. Filing a patent application within 20 years of first use. B. Publication of the formula to establish prior art. C. Continued secrecy maintained through reasonable confidentiality measures. D. Registration with the copyright office as a literary work.
-
An acquiring bank tells a merchant that maintaining compliance with the PCI DSS is a condition of the card brands’ merchant agreement. Which statement about the PCI DSS is most accurate?
A. It is a federal regulation enforced by the FTC. B. It is derived from GDPR Article 32 and applies to every controller that processes personal data. C. It applies only to merchants that store cardholder data, never to processors or acquirers. D. It is an industry standard maintained by the PCI Security Standards Council and enforced through the payment card brands’ contracts, not by government.
-
An ISC2 member discovers that software they maintain for a client exposes the personal data of thousands of people, and the client instructs them to keep the finding quiet. The member escalates through proper channels and the client refuses to act. What does the ISC2 Code of Ethics require?
A. Protect society, the common good, and necessary public trust and confidence, which the code ranks ahead of duty to principals. B. Obey the client, because duty to principals comes first. C. Remain silent, because ethics obligations do not bind contractors. D. Publicly disclose the finding to the press immediately, before any other step.
-
An organization is building its first compliance program and has no existing map of what it must satisfy. What is the soundest first step?
A. Purchase a governance, risk, and compliance tool to track controls. B. Run a penetration test of the network to find current gaps. C. Identify the legal, regulatory, and contractual obligations that apply to its business. D. Draft an information security policy and obtain board sign-off.
-
An application server cluster is valued at $900,000. A ransomware event would cost 40 percent of that value in restoration and downtime. Records show events of this kind hitting comparable clusters twice in the last five years. What is the annualized loss expectancy?
A. $144,000 B. $72,000 C. $360,000 D. $900,000
-
A database has an asset value of $500,000 and an exposure factor of 50 percent under current controls, with an annual rate of occurrence of 0.4. A proposed control would cut the exposure factor to 10 percent at a fully loaded cost of $30,000 per year. Based purely on annualized cost and benefit, what should the organization do?
A. Reject the control: it costs $30,000 per year and reduces no risk. B. Accept the control: it reduces the ALE by $50,000 per year, a net benefit of $20,000. C. Reject the control: the residual ALE of $20,000 is still too high to justify spending. D. Accept the control: it reduces the ALE by $80,000 per year, a net benefit of $50,000.
-
A hospital accepts that a legacy clinical system with known, uncorrectable vulnerabilities will remain in service because replacement is years away. The acceptance is documented, approved by the accountable executive, and scheduled for annual review. Which risk response is this?
A. Acceptance B. Avoidance C. Mitigation D. Transfer
-
After controls are implemented on a customer data platform, residual risk remains, and the security analyst who identified it believes it is acceptable. Who must formally accept that residual risk?
A. The analyst who identified the risk. B. The CISO, as head of the security program. C. The external auditor who validates the risk register. D. Management at the level accountable for the asset, with the decision documented and reviewed.
-
A system is categorized under FIPS 199 with confidentiality rated moderate, integrity rated high, and availability rated moderate. What is the system’s overall impact level?
A. Moderate B. High C. Low D. Undetermined until the annualized loss expectancy is computed.
-
During threat modeling, a team identifies that an attacker could impersonate a legitimate user to access another account, and could also modify records without authorization. Which two STRIDE categories do these threats map to?
A. Repudiation and denial of service B. Spoofing and tampering C. Information disclosure and elevation of privilege D. Tampering and repudiation
-
Which sequence reflects the order of the NIST SP 800-37 Revision 2 Risk Management Framework?
A. Categorize, Select, Assess, Implement, Authorize, Monitor B. Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor C. Select, Prepare, Categorize, Implement, Assess, Monitor, Authorize D. Assess, Categorize, Select, Implement, Authorize, Monitor
-
A team must decide quickly whether a novel, rarely observed threat merits a control, and no actuarial or historical data exists on it. Which approach fits the situation best?
A. Quantitative analysis, because the lack of data makes precision more valuable. B. A formal penetration test before any analysis. C. Defer the decision until three years of incident data accumulate. D. Qualitative analysis, using expert ratings of likelihood and impact, because it works when history is thin and decisions must move fast.
-
An organization is starting its continuity program from scratch. Which sequence reflects correct practice?
A. Select the alternate site, then write the plan, then conduct the BIA. B. Test the plan, then write the BIA based on the test results. C. Conduct the business impact analysis, set recovery targets, then choose strategies, then write and test the plan. D. Write the disaster recovery plan first, so the BIA can justify it.
-
A business process must resume accepting work within two hours of any disruption, and may lose no more than fifteen minutes of data. Which statement is correct?
A. The recovery point objective is two hours, and the recovery time objective is fifteen minutes. B. The recovery time objective is two hours, and the recovery point objective is fifteen minutes. C. The maximum tolerable downtime is fifteen minutes, and the recovery time objective is two hours. D. The recovery time objective and recovery point objective are both two hours.
-
A bank requires near-zero recovery time and near-zero data loss for a core payments system and has the budget to match. Which recovery site option fits those targets?
A. Mirrored site B. Cold site C. Warm site D. Hot site
-
An organization wants to prove that its alternate site can process live workloads before committing to a cutover, without risking production availability. Which test fits that objective?
A. Checklist review B. Tabletop exercise C. Full interruption test D. Parallel test
-
A security team publishes a document that mandates a specific approved full-disk encryption product and key escrow arrangement for all laptops, and states that compliance is compulsory. What is this document?
A. A guideline. B. A procedure. C. A standard. D. A program policy.
-
An employee is terminated effective immediately on a Friday morning. Which access-related response is correct?
A. Disable logical accounts and revoke the badge at the moment of termination, collect equipment, and conduct an exit interview. B. Keep the accounts active through the weekend so the employee can finish the handover. C. Disable network access but leave email active until the end of the pay period. D. Revoke access only after the employee returns the laptop.
-
A quarterly campaign uses short messages, posters, and a brief quiz to help all employees recognize phishing emails and use the reporting channel. Which rung of the learning continuum is this?
A. Education B. Training C. Awareness D. Certification
Answer key
| Question | Answer | Question | Answer |
|---|---|---|---|
| 1 | A | 14 | D |
| 2 | C | 15 | B |
| 3 | C | 16 | B |
| 4 | A | 17 | B |
| 5 | D | 18 | D |
| 6 | A | 19 | C |
| 7 | C | 20 | B |
| 8 | D | 21 | A |
| 9 | A | 22 | D |
| 10 | C | 23 | C |
| 11 | A | 24 | A |
| 12 | D | 25 | C |
| 13 | A |
Rationales
-
A. The confidence interval rule ends the CAT once the ability estimate excludes the passing standard with 95 percent confidence, and the rule can apply as soon as the minimum 100 items are complete. Pretest items are unscored and cannot close the exam early (option B), the engine has no easy-item exhaustion rule (option C), and there is no fixed stopping count above 100 (option D). A short, passing exam means the engine found the candidate’s level quickly.
-
C. ISC2 describes its exam scoring as compensatory: one pass or fail is computed over all operational items, and a candidate does not need to score above the proficiency level in every domain. There are no independent per-domain passes (option A), no items are removed from anyone’s scoring pool (option B), and weakness in one domain does not by itself produce a fail (option D).
-
C. In the three lines of defense model, published by the Institute of Internal Auditors, the third line is independent internal audit, reporting to the audit committee rather than to the functions it reviews. The first line owns and operates controls (option A), the second line monitors and challenges the first line (option B), and the board oversees rather than performs the audit (option D). Independence of reporting is the defining feature of the third line.
-
A. Risk appetite is a governance instrument: the amount and type of risk the organization is willing to pursue or retain, in the language of ISO 31000:2018, and it only binds the organization when it carries the authority of the top governance layer. The CISO drafts and advises but cannot grant the document the organization’s authority by signing it alone (option B). Internal audit must not author the instrument it later verifies (option C), and the analysts who produced the estimates own the numbers, not the decision (option D).
-
D. An agency exercising statutory powers, with its own procedures, subpoena authority, and fines, is the defining shape of regulatory law and a regulatory investigation. Criminal law is the state prosecuting an individual or corporation with the possibility of imprisonment (option A), civil law is a dispute between private parties seeking damages or an injunction (option B), and contract law governs agreed obligations between parties (option C).
-
A. GDPR Article 33 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware. Article 34 separately requires notification to affected individuals when the breach is likely to result in high risk to their rights and freedoms. There is no 24-hour rule (option B), the DPO advises but does not absorb the notification duty (option C), and the regulation does not impose a police-first priority (option D).
-
C. A trade secret is protected only as long as it remains secret through reasonable confidentiality measures; no registration exists, and protection can last indefinitely. A patent requires a public application process and expires 20 years from filing (option A), publication would destroy the secrecy the protection depends on (option B), and copyright protects expression in a fixed medium, not an underlying formula (option D).
-
D. The PCI DSS is an industry standard written and maintained by the PCI Security Standards Council and imposed on every entity in the payment chain through the card brands’ contracts, which is why the acquiring bank can require it. It is not an FTC regulation (option A), it is not derived from the GDPR (option B), and it applies to any entity that stores, processes, or transmits cardholder data, including processors and acquirers, not only merchants (option C).
-
A. The ISC2 Code of Ethics states that when its canons conflict they are resolved in the order of the canons, and Canon I, protecting society, the common good, and necessary public trust and confidence, precedes the duty to principals in Canon II. The member escalates through proper channels, documents, and treats public protection as the governing duty. The code binds candidates and members alike, so option C is wrong, and leaking to the press before exhausting proper channels is not what the code prescribes (option D).
-
C. Every mature compliance program starts by mapping the obligations that actually apply, the statutes, regulations, and contracts triggered by the business, before it selects tools, tests, or policies. A GRC tool without an obligation map is a tracking system with nothing tracked (option A), a penetration test measures security gaps, not compliance obligations (option B), and a policy signed before the obligation map exists may not address the binding requirements at all (option D).
-
A. SLE = AV × EF = $900,000 × 0.40 = $360,000. ARO = 2 events in 5 years = 0.4. ALE = SLE × ARO = $360,000 × 0.4 = $144,000 per year. Option C is the single loss expectancy rather than the annualized figure, and option B divides by the wrong factor; the annualized figure is $144,000.
-
D. Current SLE = $500,000 × 0.50 = $250,000, and current ALE = $250,000 × 0.4 = $100,000. With the control, SLE = $500,000 × 0.10 = $50,000, and ALE = $50,000 × 0.4 = $20,000. The ALE reduction is $80,000 per year against a $30,000 annual cost, a net benefit of $50,000, so the arithmetic says implement it. The benefit is the reduction in ALE, not the remaining exposure (option C), and the reduction is $80,000, not $50,000 (option B).
-
A. Acceptance is the deliberate, documented decision to retain a risk, and it is exactly what the hospital is doing: the risk is recorded, the exposure is approved by the accountable executive, and the decision is reviewed on a schedule. Avoidance would remove the system from service (option B), mitigation would reduce the risk rather than keep it unchanged (option C), and transfer would shift the financial consequence to another party (option D).
-
D. Residual risk is formally accepted by management at the level with authority to bear the consequences, with the decision documented, dated, and reviewed, which is the governance chain of Chapter 3 in action. The analyst who found the risk reports but does not own the exposure (option A), the CISO advises and runs the program but does not silently accept business risk on the organization’s behalf (option B), and the auditor verifies the register rather than accepting risks in it (option C).
-
B. FIPS 199 assesses confidentiality, integrity, and availability at low, moderate, or high impact, and the system’s overall impact level is the high-water mark, the highest of the three ratings. With integrity rated high, the system is a high-impact system regardless of the other two ratings. The categorization is a judgment about impact, not a product of the loss mathematics (option D).
-
B. Impersonating a legitimate user to gain access is spoofing, which violates authenticity, and modifying records without authorization is tampering, which violates integrity. Repudiation is the ability to deny an action, denial of service is exhausting the system, information disclosure is exposing data, and elevation of privilege is gaining a higher privilege level; none of those describes the two threats as stated (options A, C, D).
-
B. The NIST SP 800-37 Revision 2 sequence is Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor, with categorization grounded in FIPS 199 and the authorization to operate as the step where residual risk is formally accepted. Options A, C, and D each reorder or drop steps, and getting the order wrong defeats the framework’s logic: you cannot select controls before categorizing impact, and you cannot authorize before assessing.
-
D. Qualitative analysis rates likelihood and impact through expert judgment, which is exactly the right tool when history is thin and the decision must move fast. Quantitative analysis needs defensible loss and probability data that does not exist for a novel threat (option A), a penetration test is a testing activity, not a risk analysis of a threat that may not even be exploitable in the current build (option B), and deferring a decision for three years is not a decision at all (option C).
-
C. The continuity discipline runs in a fixed order: the BIA establishes what the organization loses over time and produces the targets, the targets drive the strategies, the strategies produce the plan, and testing proves it. Selecting a site before the BIA exists builds the last mile of a road to nowhere (option A), and the reverse orderings in options B and D get the whole sequence backwards. NIST SP 800-34 Revision 1 places the BIA second in its contingency planning process, immediately after the policy, and before prevention, strategy, and plan development.
-
B. The recovery time objective is the maximum time after a disruption before the process is restored, two hours here, and the recovery point objective is the maximum acceptable data loss, fifteen minutes here. The RTO drives the restoration design and the RPO drives the data strategy, and swapping them (option A) is the exam’s favorite trap. MTD is the outer bound management will tolerate, not a data loss target (option C).
-
A. The mirrored site is the top of the site ladder: full real-time replication with an RTO and RPO near zero and the highest cost, which matches a core payments system with near-zero targets and an unconstrained budget. A hot site is fully configured and can take over in hours, but it does not promise near-zero data loss (option D), and cold and warm sites trade recovery speed for economy (options B and C).
-
D. The parallel test runs the workload at both the primary and the alternate site and compares the results, proving the recovery environment processes live work without abandoning production. A checklist review verifies the document only (option A), a tabletop exercise tests coordination by discussion (option B), and the full interruption test is the only test that proves the whole claim but shuts down the primary operation to do it (option C). The parallel test is the standard answer for proving capability without risking availability.
-
C. In the document stack of NIST SP 800-12 Revision 1, a standard specifies uniform use of specific technologies, parameters, or procedures and is normally compulsory, which is exactly what a mandate for a specific encryption product and escrow arrangement is. A guideline recommends rather than binds (option A), a procedure is a set of detailed steps for a task (option B), and a program policy states direction at a high level without choosing the technology (option D).
-
A. At termination, access is revoked at the point of departure: accounts disabled and the badge revoked at the moment of termination, equipment collected, and an exit interview held, with surviving obligations like the non-disclosure agreement reaffirmed. For an involuntary termination, revocation happens at or before the person is told. Options B, C, and D all leave working credentials in the hands of a departing employee, which is a sabotage waiting for a schedule. NIST SP 800-53 PS-4 and ISO/IEC 27002:2022 control 6.5 carry the same discipline.
-
C. Awareness is the rung that focuses attention on security and aims to change behavior or reinforce good practice, with the learner as a recipient of packaged information, which is exactly what messages, posters, and a short quiz do. NIST SP 800-50 is explicit that awareness is not training. Training builds job skills with measurable objectives (option B), education integrates a multidisciplinary body of knowledge to produce specialists (option A), and certification is a credential, not a rung of the learning continuum (option D).
Reading your Domain 1 score
Score yourself against the bands Chapter 1 set for every domain test in this book:
| Score | Verdict | Action |
|---|---|---|
| 0–14 (below 60%) | The domain’s concepts have not landed. | Re-read Chapters 2 through 6, redo all of their practice questions, and retake this test in three to five days. |
| 15–19 (60–80%) | The concepts are mostly there. | Review only the rationales you missed, redo those questions until you can explain each rationale aloud, and keep Domain 1 in weekly spaced review. |
| 20–25 (above 80%) | The domain is in good shape. | One weekly review pass. Spend the reclaimed hours on weaker domains. |
A single number hides the information you actually need, so break the misses down by area. Domain 1 is a composite, and the triage that matters is the triage at the topic level:
| Area | Questions | If you missed 2 or more |
|---|---|---|
| Blueprint and exam mechanics | 1–2 | Re-read Chapter 2: the CAT rules and the manager-perspective hierarchy. |
| Governance, compliance, and law | 3–10 | Re-read Chapter 3: the three lines, the legal map, the compliance catalog, and the Code of Ethics. |
| Risk management and threat modeling | 11–18 | Re-read Chapter 4: the SLE/ARO/ALE math, the response ladder, FIPS 199, and STRIDE. |
| Continuity and recovery | 19–22 | Re-read Chapter 5: the BIA, the time metrics, the site ladder, and the test ladder. |
| Policy, personnel, and awareness | 23–25 | Re-read Chapter 6: the document stack, the employment lifecycle, and the learning continuum. |
Two habits make the score useful. First, log the result and the area misses on your score sheet, because the full practice exam in Chapter 33 will re-test this domain and you want the comparison. Second, treat a miss pattern as a question about your process, not just your facts: if the misses cluster on questions where you picked a technically familiar option that did not fit the facts, your problem is stem reading, and the fix is to name the risk before you look at the options. If the misses cluster on the math questions, the fix is to redo the arithmetic cold, without the chapter open.
What the score means for your plan
Domain 1 carries the largest single weight on the current outline, 16 percent, and its ideas appear in every other domain: an incident response question is a risk question wearing operations clothes, and a privacy question is a governance question wearing asset security clothes. That is why this book spends five chapters here and why the practice exam at the end of the book will draw its heaviest slice from this material.
Pass this test at the level your score band demands and you have earned the right to move to Part III with confidence. Fail it, and you have earned something rarer: a precise list of what to re-read. Either way, the score sheet is now the authority on where your Domain 1 hours go, and the next chapter opens Domain 2 with the asset inventory and the ownership model that every classification scheme in the rest of the book builds on.
Continue reading
Full table of contents