Advanced security-practitioner certification covering all eight (ISC)2 CISSP domains, from security and risk management to software development security.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleSecurity and Risk Managementeasy
Which statement BEST describes the relationship between the ISC2 Code of Professional Ethics canons and an employer's internal code of conduct for a CISSP-certified employee?
- AThe ISC2 canons apply to certified professionals at all times and complement, rather than replace, lawful employer codes of conduct.check_circle Correct
- BThe employer's code of conduct overrides the ISC2 canons whenever the two appear to conflict in the workplace.
- CThe ISC2 canons only apply when the CISSP is performing security work outside of normal employment duties.
- DEither code can be ignored provided the professional acts in line with applicable national law and contractual obligations.
Recognise that the ISC2 Code of Ethics binds the certified professional continuously and operates alongside, not in place of, lawful organisational codes. Holding the CISSP is a personal undertaking to abide by the ISC2 canons in every professional act, while an employer's code defines workplace duties owed to a principal. Both apply concurrently, and where a lawful employer rule and a canon point the same way the professional follows both; the canons set the floor and an organisational code can add stricter expectations on top.
Why A is correct: The canons bind the certificant personally and continuously, while a lawful employer code governs workplace duties; the two are designed to coexist, with the canons providing the professional baseline.
Why B is wrong: Tempting because employees normally follow employer policy, but a CISSP holder agreed to uphold the ISC2 canons as a condition of certification, so the canons are not displaced by internal policy.
Why C is wrong: Plausible to a candidate who thinks ethics codes only cover voluntary or external activity, but the canons attach to the certificant in every professional context, not only off-hours engagements.
Why D is wrong: Compliance with law is necessary but not sufficient; the ISC2 canons impose duties beyond legal minimums, and ignoring an employer's lawful code breaches duty owed to principals.
lock_openFree sampleSecurity Assessment and Testingmedium
An organisation is drafting its annual security assessment strategy and wants to distinguish a security assessment from a security audit so the right activity is scoped for each engagement. Which statement BEST captures the conceptual difference between these two activities?
- AAn assessment is always performed by external parties for regulatory reasons, whereas an audit is always performed internally by the security function for management oversight.
- BAn assessment evaluates the overall effectiveness of controls against stated objectives, whereas an audit verifies conformance to a defined standard or policy and produces formal evidence of compliance.check_circle Correct
- CAn assessment uses automated scanning tools while an audit relies exclusively on interviews and document review, with no overlap in technique.
- DAn assessment is concerned with detecting vulnerabilities and an audit is concerned with detecting fraud, so the two engagements rarely share scope or stakeholders.
Distinguish a security assessment from a security audit by purpose, rigour, and the form of evidence produced. Assessments judge whether the control set is effective at meeting risk and business objectives and tend to be advisory in tone. Audits test conformance to a defined criterion, such as a standard, regulation, or internal policy, and produce formal evidence supporting an opinion or attestation. Scoping each activity correctly avoids paying for an audit when an advisory assessment was needed, or vice versa.
Why A is wrong: Tempting because external assessors and internal auditors are common patterns, but the distinction is incorrect: assessments can be internal and audits can be external. Independence and scope are separate from the assessment-versus-audit distinction.
Why B is correct: Correct. Assessments are broader, advisory engagements that judge whether controls achieve risk-management goals, while audits are evidence-driven exercises that test conformance to a specific baseline such as ISO 27001 or an internal policy and yield an attestation.
Why C is wrong: Plausible because assessments often involve scanners and audits often involve interviews, but both activities can use a mix of automated and manual techniques. The defining difference is purpose and evidentiary rigour, not toolset.
Why D is wrong: Conflates security assessment with vulnerability assessment and audit with financial fraud detection. Security audits cover control conformance broadly, and assessments examine more than vulnerabilities; the framing is too narrow.
lock_openFree sampleSecurity Architecture and Engineeringmedium
A security architect is briefing a board on the difference between defence in depth and zero trust as guiding design principles for a new corporate platform. Which statement BEST captures the conceptual distinction between the two?
- ADefence in depth layers independent controls so that the failure of any single control does not breach the asset, whereas zero trust removes implicit trust based on network location and continuously verifies each subject, device, and request.check_circle Correct
- BDefence in depth is a network segmentation technique that encrypts traffic between tiers, while zero trust is a procurement requirement that all suppliers attest to their secure software development practices.
- CDefence in depth replaces perimeter firewalls with identity-aware proxies, while zero trust focuses on encrypting data at rest and in transit at every storage tier.
- DDefence in depth and zero trust are interchangeable terms describing layered authentication, with defence in depth being the older vendor label and zero trust being the modern one.
Distinguish defence in depth as a layered-controls strategy from zero trust as a per-request verification model that removes implicit network trust. Defence in depth assumes individual controls will fail and builds redundancy so that compromise of one layer does not breach the asset. Zero trust is a trust model that abandons the assumption that traffic from inside the network can be trusted, requiring identity, device, and context to be verified on every request. The two are complementary but conceptually distinct: one is about layering, the other is about not granting trust by location.
Why A is correct: This correctly frames defence in depth as a layered-controls strategy whose value is failure tolerance, while zero trust is a trust model that replaces network-perimeter assumptions with per-request verification of identity, device posture, and context.
Why B is wrong: This is tempting because both ideas are often discussed alongside segmentation and supply-chain trust, but defence in depth is a broader layered-controls strategy not limited to network segmentation, and zero trust is a security model rather than a procurement clause.
Why C is wrong: This inverts the two concepts: identity-aware proxies are typical of zero trust enforcement, and ubiquitous encryption is a cryptographic control rather than the essence of either principle.
Why D is wrong: Candidates sometimes treat the terms as synonyms because both involve multiple checks, but they describe different ideas: layered independent controls versus an architectural trust model with no implicit network trust.
More free CISSP practice questions with worked answersFrequently asked questions
- How many questions are on the CISSP exam?
- The Certified Information Systems Security Professional (CISSP) exam has 100-150 questions (CAT) questions and runs for 180 minutes. The format is computerised adaptive testing (cat), multiple choice and advanced item types, at isc2 authorized pearson vue testing centers (ppc and pvtc select).
- What score do I need to pass CISSP?
- The pass mark is 700 / 1000. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the CISSP exam cost?
- The exam costs 749 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
- Is there a CISSP practice exam?
- Yes. Examworthy's exam mode runs a timed CISSP practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
- How does Examworthy help me prepare for CISSP?
- Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
- Is Examworthy affiliated with (ISC)2?
- No. Examworthy is not affiliated with or endorsed by (ISC)2. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by (ISC)2. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CISSP and related marks belong to their respective owners.