CISSP Certification Guide / Chapter 32
Exam Strategy and Question Technique
How to read the exam's questions like a test-taker: the anatomy of a CISSP item, the five question shapes, the clue words and qualifiers that carry the meaning, elimination as a disciplined two-phase method, four fully dissected sample questions, time budgeting for the adaptive engine, the honest guess, the protocol for the 125-question full practice exam, a complete exam-day plan, and a ten-question technique drill with rationales.
The endgame is a craft problem
Everything from Chapter 3 through Chapter 31 was content: the vocabulary, the frameworks, the controls, and the standards behind all eight domains. That work is done. What is left is craft, and craft is where candidates who know the material either bank their knowledge or leak it. Two people with identical domain knowledge can score differently on the CISSP, and the difference is not luck. It is how they read questions, how they spend the clock, and how they behave when the adaptive engine hands them a stretch of hard items.
This chapter turns test-taking into a method. It teaches you the anatomy of an item so you read the right part first. It names the five shapes the exam builds and what each shape demands of you. It turns elimination into a two-phase discipline instead of a feeling. It dissects four questions in full view, the way a coach would. It gives you a time budget and a guess policy that work inside the adaptive rules from Chapter 2: no skipping, no review, no returning. And it ends with a ten-question technique drill, tagged by the skill each question is meant to train, so you can practice the craft itself rather than only the content.
The exam is criterion-referenced at 700 out of 1000, and it is compensatory across domains. You do not need to be perfect. You need to convert what you know into answers at a steady pace under a machine that is designed to keep you at roughly fifty-fifty odds. That conversion is the craft. Here is how it works.
The anatomy of a question
Every CISSP item is three parts wearing a single sentence. The stem is the setup: the scenario, the system, the situation. The question line is the actual request, usually a single sentence that ends with a question mark: “Which of the following is the BEST approach?”, “What is the FIRST step?”, “Which statement is correct?” The options are the four choices. The most common mistake in the whole exam is reading the stem first and the question line second, because the stem is where you are invited to think like the story, and the question line is where you are actually asked to act.
Read the question line first. One sentence, maybe five seconds, and it tells you four things you need before you touch the scenario: the shape of the item, the qualifier, the verb, and the actor.
The shape tells you how the exam will grade you. The qualifier, words like BEST, MOST, LEAST, FIRST, PRIMARILY, is the exam telling you which level of judgment it wants. The verb, words like prevent, detect, protect, comply, authorize, tells you the control function the answer must serve. The actor, the person or role the question holds accountable, tells you whose job the answer is, and the single most common elimination trap in the book is an option that is true in general but not for the actor in the question. A question about what a security analyst should do is not answered by what the board should do, and a question about what a manager should decide is not answered by what a technician would type at a console.
The five shapes are worth naming, because each has a different attack:
| Shape | Question line signature | What it demands |
|---|---|---|
| Best answer | “BEST”, “MOST appropriate”, “most effective” | Rank the survivors by the decision hierarchy and the qualifier, not by technical truth alone |
| Direct recall | “Which of the following…”, “What is…”, “Which statement is correct?” | Match one option to the exact vocabulary or fact; watch for true-but-unrelated options |
| NOT or EXCEPT | “NOT”, “EXCEPT”, “all of the following… except” | Find the one option that does not belong; three options are true, one is false, or vice versa |
| Sequence | “FIRST step”, “NEXT step”, “before”, “last” | Name the earliest or latest defensible action in a process, never the most dramatic one |
| Judgment | “PRIMARY purpose”, “most important consideration”, “should” | Identify the reason, priority, or accountable decision, not a side benefit |
You will meet all five in every practice exam in this book, and the real exam mixes them freely because the adaptive engine draws items across all eight domains in outline-weighted proportions.
Clue words: the grammar of the exam
The qualifier is load-bearing, and Chapter 2 introduced its core: “best” and “most” invite the strongest overall judgment, “least” points at the smallest safe step, “should” asks what a reasonable manager would do, “must” and “always” mark a non-negotiable obligation. This chapter adds the rest of the grammar, because the exam uses a small, consistent vocabulary and rewards the candidate who reads it as code.
Absolute words are red flags when they appear in an option, and they are usually the sign of a distractor: “always”, “never”, “guarantees”, “completely”, “only”, “solely”, “impossible”. Security controls do not guarantee outcomes, so an option that claims one almost always overreaches. The correct answer to a “which statement is accurate” question is usually the qualified one, the one that says a control raises the cost, reduces the likelihood, or supports a process, rather than the one that promises certainty. When a stem itself uses “must”, it is asking about a mandatory requirement, typically a compliance obligation from a standard such as PCI DSS v4.0 or a regulatory rule such as the GDPR, and the answer is the requirement, not the good idea.
NOT and EXCEPT flip the polarity of the entire item, and this is the shape candidates miss at speed. You must consciously restate the question in your head: “which of these four is not a component”, “which is not appropriate”, “which is the exception”. Three of the four options will look entirely reasonable, because they are supposed to be. The skill is finding the odd one, not the best one.
Sequence words (“first”, “next”, “before anything else”) reward the earliest defensible action. The exam’s expected first step is almost never the most dramatic option on the page. It is the verification, the triage, the notification, the classification, the read: the small action that precedes the big one. When you see “FIRST”, ask what must be true before the louder options can be done responsibly.
“Primary” and “most important” ask for the reason something exists, not a benefit it happens to produce. A business impact analysis has many outputs; its primary purpose is identifying critical processes and quantifying the impact of their loss over time so that recovery objectives can be set. Every other answer may be a true byproduct, and the exam counts on you picking the purpose.
Elimination as a discipline
Elimination is the core mechanic of multiple-choice testing, and on the CISSP it is not a fallback for when you do not know the answer. It is the method, because the exam is written so that most items have at least one option you can kill with certainty, and often two. Work it in two phases, always in this order.
Phase one is the kill phase. Read each option and ask three questions. Is it factually wrong, per the standards this book cites? Is it out of scope for the actor or the phase the question names? Does it use absolute language that makes it overclaim? The first kill is the standard-based kill: an option that contradicts a named standard, like claiming the GDPR allows unlimited retention of personal data or that a parameterized query does not stop injection, dies immediately. The second kill is the scope kill: an option that is a true statement but belongs to a different actor, a different phase of a process, or a different function than the question asks about. The third kill is the language kill: “always”, “never”, “guarantees”, “completely”, which no control earns. Kill what you can kill, and leave the survivors alone until you have seen all four. Do not fall in love with the first option that looks right, because the exam places its best distractor right after it.
Phase two is the choose phase, and it only happens among survivors. Rank the survivors with the decision hierarchy from Chapter 2: people before property, name the risk, prevention over detection, least privilege and need to know, defense in depth, business alignment and cost-effectiveness, escalation and accountability, and above all the tie-breaker, the answer a responsible manager would defend in front of the board. Then apply the qualifier from the question line. “Best” means the strongest overall survivor. “Least” means the smallest safe survivor. “Must” means the mandatory survivor. If the survivors split on a fact, the fact wins; if they split on judgment, the hierarchy wins.
Three traps deserve their own names. The answer-pair trap: when two options are direct opposites, one of them is usually correct, and the test of the pair is the hierarchy, not your mood. The true-but-different trap: an option that is a correct statement about something else entirely, technically true and completely irrelevant, which the exam plants to reward the candidate who read the question line. The dramatic-action trap: the option that does something impressive, immediate, and wrong, like terminating an employee on suspicion, paying a ransom, disconnecting a server before validating the alert, or unilaterally contacting the media, because the impressive action ignores evidence, authority, and process. When you are torn between a process answer and a dramatic answer, the process answer is the exam’s answer.
Four dissections
Theory compresses into practice quickly, so here are four original items, dissected in full view: the question line read first, the killers found, the hierarchy applied, the answer landed. Read each one and try to beat the commentary before you read it.
Dissection 1. Function matching. A security manager must select a control to prevent unauthorized access to customer data stored in a database. Which control is BEST?
A. Encrypt the database at rest. B. Enforce role-based access control with least privilege and monitor access. C. Take nightly backups of the database. D. Place a firewall between the database and the internet.
The question line asks for one function: prevent unauthorized access. The verb is “prevent”, and the object is “access”. Run the options against that function, not against general security. Encryption is a confidentiality control: it makes data unreadable if it is taken, but it does not prevent someone with valid access from reading it, and it says nothing about who may access. Backups are an availability control: they restore data after loss, and they do not govern access at all. The firewall filters network traffic, a perimeter layer, but it does not authorize a user who reaches the application. Role-based access control with least privilege is the authorization control: it decides who may access what, which is precisely the function the question names, and monitoring pairs with it because prevention without detection leaves you blind. B survives the function test and the others do not. The hierarchy’s level 4 (least privilege and need to know) and level 5 (defense in depth, prevention paired with detection) both point the same way.
Dissection 2. Most important, with a regulator watching. An organization suffers a personal data breach affecting customers in several countries. Which consideration is MOST important when deciding how to respond?
A. Notify all affected customers immediately, before the facts are verified. B. Verify the facts of the incident, determine which legal regimes apply, and notify in line with their requirements, including the GDPR’s rule that a breach notice to the supervisory authority go out without undue delay and, where feasible, within 72 hours. C. Wait until the investigation is fully complete before notifying anyone. D. Issue a public statement to the media before contacting the regulator.
The question line says “MOST important”, which is a priority question, and the scenario plants a regulatory stake: affected customers “in several countries” raises GDPR Article 33, which requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware. Option A fails because notification without verified facts can be wrong notification, and a wrong notification is a second incident. Option C fails because the GDPR’s 72-hour duty exists precisely because full investigation may take longer than the law allows. Option D is theater: the media does not outrank the regulator, and the GDPR does not ask for a press release. Option B holds the balance: verify what happened, map the legal regimes, then notify on their timelines. The hierarchy’s level 2 (name the risk) and the compliance obligation resolve the pair.
Dissection 3. Least privilege, in practice. An auditor needs occasional access to a payroll system to complete a one-off review. Which approach BEST reflects least privilege?
A. Grant permanent administrator access so the review is never blocked. B. Grant time-limited access to the specific records and functions the review needs, then revoke it when the review ends. C. Grant the same access as the payroll manager, permanently. D. Grant read-only access to the entire database.
The question line names the principle, least privilege, so every option is graded against the principle, not against convenience. Permanent administrator access is the opposite of least privilege: it grants the largest possible set of rights for an indefinite period. Matching the payroll manager’s access over-grants by construction, because the auditor does not hold the payroll manager’s role. Read-only access to the entire database over-grants on scope: the review needs specific records, not the whole schema. B is the pattern least privilege actually means: scoped to the task, limited in time, revoked at the end, and the NIST SP 800-53 Revision 5 control family expresses the same idea as AC-6, Least Privilege. The exam asks you to recognize the pattern, not just the term.
Dissection 4. Time pressure is not an exemption. A partner connection requires a new firewall rule, and the change window is short. Which is the BEST approach?
A. Add the rule directly to the production firewall because the window is short. B. Submit the change through change management, get approval, test it in a non-production environment, and apply it in the scheduled window. C. Ask the vendor for a recommended rule and apply it verbatim. D. Disable the firewall during the change and re-enable it afterward.
The trap is the word “short”, which exists to make the direct production edit feel responsible. It is not. Change management exists so that changes are approved, tested, and reversible; the change governance in Chapter 29 treats the pipeline of change as the thing to protect. Option A skips approval and testing exactly when the window is short, which is when mistakes are most expensive. Option C treats a vendor recommendation as authorization, but a recommendation is input, not approval. Option D removes the control entirely during the change, trading a firewall for a gap. B is the process answer: the change goes through the governance that exists precisely for time-constrained situations, with a backout plan implied. The hierarchy’s level 3 (prevention) and the escalation principle (level 7) both live in B.
Time and the adaptive engine
Chapter 2 gave you the arithmetic and it is worth one line here because it drives everything: 100 items in 180 minutes is 1.8 minutes per item, 150 items is 1.2 minutes per item, so the working budget is about a minute and a quarter per item, with the understanding that the exam stops when the engine is confident, not when you finish the page.
The pacing rules follow from the machine. First, hold the average and protect the floor. A minute and a quarter per item is an average, not a quota for each item: some items deserve two minutes and some deserve forty seconds, and the skill is not to let the two-minute items eat the forty-second ones. Second, set a hard cap per item. When you reach two minutes on one question, you have almost certainly learned everything it is going to teach you. Eliminate what you can, pick the best survivor, confirm, and move. The adaptive engine does not reward heroics, and Chapter 2 established that you cannot return, so the cost of dwelling is paid in questions you never reach. Third, check the clock at fixed marks, not constantly. At the 25-item mark you should be near the 30-minute mark; at the 50-item mark, near the hour. If you are ahead, the surplus is banked for the hard stretch; if you are behind, tighten the cap from two minutes to ninety seconds until you are even. Fourth, never leave a blank. A blank is a wrong answer, and the pretest items embedded in the run must be answered to reach the graded minimum even though they do not score, so the blank costs twice: once for the item, once for the minimum.
The psychological side is part of the budget. The engine calibrates difficulty to your ability, which means a stretch of hard questions is not a verdict, it is the machine testing you at your level. Do not read meaning into it, and do not read meaning into length: an exam that stops at 101 items and one that runs to 150 can both be passes, because the difference is statistical confidence, not quality of performance. When the hour mark arrives, take the reset: close your eyes, breathe, re-grip the mouse, and start the next item as if the exam had just begun. Fatigue is managed in the same arithmetic as time, with the same rule: the next item is the only item.
The honest guess
Guessing is not a failure state on this exam, it is a phase of the method, and the only dishonest guess is the one you make without eliminating first. When you are down to two survivors and the clock is on you, the hierarchy is your tie-breaker: pick the survivor a responsible manager would defend, the one that prevents rather than detects, the one that is scoped and time-limited rather than permanent, the one that goes through process rather than around it. When you are down to three or four, you are probably missing a kill, so re-run the three kill questions quickly: is it standard-wrong, is it out of scope, is it overclaiming? Then commit.
Two habits make guessing productive instead of anxious. First, treat the guess as a decision, not a confession: decide, confirm, and release the item, because the engine gives you no review and the release is the whole point. Second, never let a guessed item leak into the next one. The exam cannot know you guessed, the next item is drawn from your estimated ability, not your confidence, and the only thing dwelling accomplishes is borrowing time from questions you might know cold.
The full practice exam, Chapters 33 and 34
Chapters 33 and 34 together form the full 125-question practice exam, built at the current blueprint weights, with 63 questions in the first sitting and 62 in the second, and answers and rationales at the end of each. This is the closest the book gets to a dress rehearsal, so treat it like one.
Run it once as a single 3-hour session, if you can clear the time. The real exam is 100 to 150 items in 180 minutes, so 125 is a fair training distance: long enough to feel the fatigue, short enough to fit a real calendar. Apply every rule you have met: a minute and a quarter per item, a two-minute cap, no skipping, no review, no blanks, no notes, no phone, no comfort stop in the middle. When you finish, score the whole run and then score it again per domain against the outline weights, because the per-domain number is the one that feeds your score sheet and your triage, per the rules set in Chapter 1: below 60 percent sends the domain through the re-read, redo, retest loop, 60 to 80 percent gets targeted rationale review, above 80 percent gets one weekly pass.
If a single 3-hour sitting is not possible, run the two chapters on consecutive days, 63 and 62 questions each, under the same no-review rules, and note on the score sheet that it was split. The scoring is still honest; the fatigue simulation is not, and you should know that the last-hour discipline from the time section is exactly what the split run does not train. Do not open the answer key early. Do not re-litigate a question you flagged mentally; the flag is data for the review, not a second attempt.
The exam-day plan
The plan below is the one this book recommends. The details of your test center may differ slightly, so verify what you can before you go, and treat anything the center tells you as the authority over anything here.
The night before, do the opposite of cramming. Review only the material you already know well, ideally a one-page mnemonic sheet or a set of flashcards from your weakest domains, and stop at a reasonable hour. Pack the essentials: a current, government-issued photo ID with your name exactly as it appears on your registration, your appointment confirmation, and nothing else you are not willing to leave in a locker, because the test center controls what enters the room. Eat a normal meal, sleep, and do not start a new topic at 11 p.m. because a new topic at 11 p.m. will be a thin topic at 8 a.m. and a source of worry in between.
The morning of, give yourself slack. Leave early enough to arrive at the center with time to spare; check-in takes longer than people expect, and an arrival crisis costs more than an hour of sleep. Eat and hydrate before you enter, because the session is three continuous hours and Chapter 2 established that any break you take counts against the clock. Use the 15-minute preview tutorial before the exam clock starts to do exactly what it is for: click through the interface, confirm how to finalize an answer, check the clock display, and get your hands comfortable. None of that time touches the three hours.
Inside the session, run the loop. Read the question line, identify the shape and qualifier, kill what you can kill, choose among survivors by the hierarchy, confirm, move. Check the clock at the 25-item and 50-item marks. When the engine hands you a hard stretch, read it as calibration, not as a verdict, and take the reset at the hour. Answer every item, even the ones you hate, because the blank is the only answer that is guaranteed wrong. If a question makes you want to change an answer you already confirmed, do not: the engine offers no review, and the want is the same psychological noise the exam is designed to produce.
When the session ends, the center shows you a provisional pass or fail, and the official result follows later through ISC2, as Chapter 1 described. Take the provisional result at face value and leave. If it is a pass, you have earned the right to stop analyzing; the endorsement step belongs to the final readiness review in Chapter 35. If it is not a pass, remember the retake arithmetic from Chapter 2, thirty test-free days after the first attempt, sixty after the second, ninety after the third, and remember that a failed attempt is data, not identity: the proficiency feedback by domain is a diagnostic no practice bank can give you, and it tells you exactly where the next study hours go. Either way, do not spend the evening re-litigating items from memory. The only signal that matters printed itself on the screen.
The technique drill
Ten questions, each tagged with the technique it trains. Take them the way you will take the real items: read the question line first, kill, choose, commit. Do not open the answer key until you have an answer for all ten, and do not read the tags as hints during the run; read them afterward, when each rationale names the skill the question was built to test.
1. (Qualifier: LEAST; scope.) A company laptop containing unencrypted customer personal data is stolen from an employee’s car overnight. Which of the following is the LEAST appropriate initial action?
A. Invoke the incident response plan and preserve evidence such as access logs and video. B. Begin a forensic examination of the laptop to determine what the thief accessed. C. Verify what data was on the laptop and where it was stored. D. Notify the privacy officer so that breach assessment and any notification obligations are considered.
2. (Sequence: FIRST.) A SOC analyst sees an alert for outbound traffic from a database server to an address known to be a command and control endpoint. Which of the following is the FIRST step in handling the alert?
A. Report the event to the executive team. B. Immediately isolate the database server from the network. C. Verify the alert against related logs and the runbook’s validation steps before acting. D. Begin notifying customers of a data breach.
3. (Shape: NOT/EXCEPT.) An incident response policy must cover all of the following EXCEPT:
A. The exact product versions of the tools used by a specific third-party contractor. B. A definition of what constitutes an incident and the severity levels used to classify one. C. Roles and responsibilities for the response team, including escalation paths. D. Reporting and communication requirements for stakeholders.
4. (Actor: accountability.) A security analyst discovers a high-severity vulnerability in a customer-facing application. The analyst’s manager is on leave, and the fix will take time. Per the organization’s risk framework, who should decide whether the residual risk of delaying the fix is acceptable?
A. The analyst, because they found the vulnerability and understand it best. B. The help desk, because they see the reported issues daily. C. The external penetration tester who reported a similar finding in last year’s test. D. The application owner, at the level that can bear the risk, after a documented risk assessment.
5. (Absolute language.) Which of the following statements about encryption is MOST accurate?
A. AES-256 guarantees that encrypted data can never be read by an attacker. B. Strong encryption raises the cost of reading protected data substantially, but the security it provides depends on the keys, the implementation, and the surrounding controls. C. Data encrypted in transit is automatically safe while at rest. D. Encryption alone provides complete protection against data theft.
6. (Answer pairs; least privilege.) A bank wants to let employees use personal devices for internal email. Which approach BEST reflects least privilege applied to the program?
A. Allow personal devices only for functions the business has approved, with the minimal data and access needed for those functions, managed under a documented device policy. B. Allow every employee to use any personal device for any work function. C. Allow personal devices and grant every employee administrative rights to the corporate directory. D. Forbid all personal devices because personal devices are all insecure.
7. (Judgment: PRIMARY purpose.) What is the PRIMARY purpose of a business impact analysis in business continuity planning?
A. To assign responsibility for past outages. B. To purchase replacement hardware before it is needed. C. To identify critical business processes and quantify the impact of their loss over time, which drives recovery objectives such as recovery time objective and recovery point objective. D. To document employee performance during emergencies.
8. (Business alignment; cost-effectiveness.) A small company stores non-sensitive marketing data in the cloud and has a limited security budget. Which control choice BEST fits a risk-based approach?
A. Build a second data center for full redundancy because availability is always the priority. B. Purchase the most expensive security product on the market. C. Ignore risks for data that is not regulated. D. Classify the data, apply controls proportional to its value and the assessed risk, and document the decisions.
9. (Due process; evidence.) An employee is suspected of leaking sensitive documents. Which action BEST fits proper personnel and evidence handling?
A. Terminate the employee immediately based on the suspicion. B. Confront the employee in front of the team to discourage others. C. Ask the employee’s colleagues to investigate informally. D. Collect evidence properly, coordinate with legal and human resources, restrict access as appropriate, and investigate before deciding on disciplinary action.
10. (Defense in depth.) A web application is being deployed to production. Which approach BEST reflects defense in depth?
A. Apply input validation, parameterized queries, a web application firewall, monitoring, and access controls so that several independent layers each protect the application. B. Rely on the web application firewall alone, because it stops most attacks. C. Remove all error messages so that attackers learn nothing from the application. D. Enforce a single strong password policy and rely on it.
Answers and rationales
-
B. The qualifier is LEAST, so the task is to find the option that is not merely suboptimal but wrong as an initial action. The laptop is gone, so a forensic examination of the device is impossible by definition, and it is also premature: no one has verified what the laptop contained. The other three options are defensible initial actions that support the investigation and legal assessment. The scope kill is the whole question: you cannot examine a device you do not possess.
-
C. The question line says FIRST, and the first step in handling an alert is validation: confirm the indicator against related logs and the runbook before containment, escalation, or notification, which is where NIST SP 800-61 Revision 2’s Detection and Analysis phase begins. Option B is the dramatic-action trap, wrong at this step because unvalidated containment can disrupt a critical server on a false positive; options A and D are escalations that presume the event is confirmed, which is exactly what step one has not yet established.
-
A. The NOT/EXCEPT shape asks for the odd one out, and the odd one is the option that names a specific contractor’s tool versions. A policy is a management-level statement of definition, roles, and process; specific product versions belong in a procedure or an operating guide, not in the policy. Options B, C, and D are standard policy components per the incident response planning guidance in NIST SP 800-61 Revision 2.
-
D. The actor question is accountability. The risk framework assigns risk ownership to the party accountable for the asset, which is how ISO 31000:2018 defines a risk owner: the person accountable for managing a risk. The analyst found the vulnerability but does not own the application’s risk; the help desk and the external tester have no authority over acceptance. Acceptance decisions must be documented and made at a level that can bear the risk, the decision hierarchy’s level 7.
-
B. The qualifier is MOST, and the language kill does the work: “guarantees”, “never”, “automatically”, “completely”, and “alone” overclaim what any control can deliver. Option B is the qualified statement, and it is also the technically accurate one: the security of encryption depends on key management, correct implementation, and the controls around it, per the cryptography material in Chapter 13 and the AES definition in FIPS 197. The exam’s accurate answers are almost always the qualified ones.
-
A. Options B and D are the answer pair, direct opposites, and both are wrong at the same point: they treat the program as a yes or no rather than a scoping question. A is the qualified middle: approved functions, minimal data and access, documented policy, which is least privilege applied to a device program. Option C fails the least privilege test by granting administrative rights to the directory, a privilege far beyond internal email.
-
C. The PRIMARY purpose question asks for the reason the analysis exists. A BIA identifies critical processes and quantifies the impact of their loss over time, and that quantification is what sets the recovery time objective and recovery point objective that Chapter 5 describes. The other options are byproducts, confusions, or fiction; none of them is why a BIA is performed.
-
D. The scenario sets the constraints, small company, non-sensitive data, limited budget, and the risk-based approach is proportionality: classify the asset, size the control to the risk, document the decision, which is the cost-effectiveness level of the decision hierarchy. Option A fails on “always” and on economics, a second data center for marketing data is not proportional. Option C confuses low sensitivity with zero risk, and option B is spending without analysis.
-
D. The SHOULD question is decided by process and evidence. Termination on suspicion, public confrontation, and informal peer investigation all fail the same tests: they act before the facts are established, they can destroy evidence, and they bypass the functions that own personnel and legal decisions. D preserves evidence, coordinates with legal and human resources, and restricts access without prejudging the outcome, which is the pattern Chapter 26’s investigations and Chapter 6’s personnel security both teach.
-
A. Defense in depth is the layering of independent controls, and A is the only option that layers: input validation and parameterized queries address injection at the application, the firewall filters at the boundary, monitoring detects what passes, and access controls limit who reaches the application at all. The single-control options, B and D, are the trap the hierarchy’s level 5 exists to catch, and option C is not a control, it is the removal of diagnostic information that operators also need.
Carry the craft in
Content got you to the exam; craft gets you through it. The two are inseparable now: the kill questions run on the standards this book cited, the choose phase runs on the hierarchy, and the clock runs on the arithmetic you have known since Chapter 2. Read the question line first, every time, even when you are tired. Name the shape and the qualifier before you commit to the stem. Kill what you can kill, choose among survivors by the hierarchy, and release the item when you choose it. Hold the minute and a quarter, check the clock at the marks, answer every question, and treat a hard stretch as calibration.
Chapter 33 starts the full practice exam, 63 questions at the current blueprint weights, and Chapter 34 continues with 62. Run them under the rules in this chapter, score them per domain, and let the score sheet decide where the remaining hours go. After that, Chapter 35 turns your numbers into a verdict: the readiness review, the final plan, and the steps that come after a pass.
The material is in you. The rest is execution.
Continue reading
Full table of contents