Study. uk . com
  1. Home
  2. All questions
  3. Security operations

CISSP study material: Security operations

76 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 7. A hospital group is chartering an information security continuous monitoring programme. Analysts propose to alert on every configuration change across the estate. The risk officer wants the programme scoped so its output actually drives decisions. Against what should the programme measure what it observes?
  2. 13. A small water utility runs office IT and plant operational technology with one three-person team. It has worked from version 1.0.1 of CISA's Cross-Sector Cybersecurity Performance Goals and is moving to version 2.0. Which changes in 2.0 shape how the team plans its work? Choose two.
  3. 14. A hospital is retiring 400 laptop drives that held patient records. The security manager argues that only physical shredding can count as sanitisation and that a verified overwrite is worthless. The media sanitisation lead answers by citing the standard's own test for when media counts as sanitised. Which principle does the lead cite?
  4. 15. A cloud provider must decommission self-encrypting drives from a multi-tenant storage array inside a two-hour maintenance window far too short for a full-block overwrite of the array. Each drive holds ciphertext belonging to many tenants, and the drives are leased and must be returned to the lessor in working order. Which sanitisation method meets these constraints?
  5. 19. A logistics firm sends decommissioned equipment to a recycler. Some devices held only public route maps, while others held customer payment records, and the asset manager wants one defensible rule for choosing a disposal technique. Which rule matches the media sanitisation guidance?
  6. 21. A privacy lead is scoping a programme against the federal guide to protecting personally identifiable information and must set the steering committee's expectations about the guide's actual reach. Which statements correctly describe its scope? Choose two.
  7. 34. An enterprise peers with an upstream provider and mistakenly advertises routes for its internal 10.0.0.0/8 space. The provider's router silently drops the advertisement, and the enterprise operations team raises a ticket claiming the peer is generating routing protocol errors. How should this behaviour be characterised?
  8. 41. To cut handshake cost on a heavily loaded TLS 1.3 service, a platform team configures its servers to issue resumption tickets advertising a thirty-day lifetime. A reviewer warns that clients will ignore the advertised value long before then. Which description of ticket lifetime handling is correct?
  9. 46. A security manager is rewriting the password policy for a workforce portal to align with NIST SP 800-63B-4. The current policy mandates a mix of upper case, digits and symbols, expires every password after 90 days, and screens new passwords against a blocklist of breached values. Which two changes bring the policy into line? Choose two.
  10. 53. A compliance analyst at a regional insurer must confirm that firewall change records and the current rulesets agree with documented policy, with no interruption to claims processing. The engagement letter allows the analyst to review artefacts only, with no interaction with live devices. Which assessment method fits this work?
  11. 55. A bank's board wants to learn how far an intruder could get before the security operations centre reacts, so the exercise must run while operations staff remain unaware of it. The assessors ask what has to be in place before they begin. Which condition governs this kind of exercise?
  12. 59. An energy utility is standing up an information security continuous monitoring programme and already maintains a current inventory of the systems it owns. To deliver the remaining aims of such a programme, which two capabilities must it add? Choose two.
  13. 63. A security operations centre receives forty incident tickets during one shift, and a new analyst begins working them in the order they arrived. The incident manager wants a defensible handling order the organisation can justify to auditors. Which basis should determine which incident is worked first?
  14. 64. Ransomware is confirmed on three file servers, and the response team has isolated all three. Management asks the team to state how large the incident is before recovery planning begins. Which action best establishes the true scope of the incident?
  15. 65. An organisation is writing the mitigation section of its incident response plan for workloads hosted by a cloud provider whose platform contains some incidents automatically. Which two requirements should that section state? Choose two.
  16. 66. During an intrusion, an analyst proposes leaving the attacker's access in place and steering the session into an instrumented sandbox to observe their techniques before the incident is shut down. Which action should the incident commander take before that diversion begins?
  17. 67. An enterprise marks a patch as complete once its deployment console reports the package was pushed to the target group. An auditor later finds several of those servers still running the vulnerable version. Which activity closes the patch management cycle?
  18. 68. Mission owners at a manufacturer keep deferring maintenance windows because downtime costs production, while the technology owners want fixes applied promptly. The chief information security officer needs a framing that settles the standing disagreement about whether patching is worth its cost. Which approach should be adopted?
  19. 69. An adversary edits the endpoint detection agent's configuration and deletes the log forwarding pipeline, so alerts stop reaching the security operations centre and analysts can no longer trust their consoles. In the current MITRE ATT&CK Enterprise matrix of fifteen tactics, which tactic describes this behaviour?
  20. 70. An agency tracks the CISA Known Exploited Vulnerabilities catalog. Two vulnerabilities were added to the listing on the same day; one record is flagged as requiring forensic triage under Binding Operational Directive 26-04 and the other carries no such flag. How does that flag affect the two remediation deadlines?
  21. 71. A skilled intruder held access to a domain member server for weeks, and the full set of techniques they used remains unknown. The team plans to rebuild the server from a backup taken before the earliest known activity. Which three actions should the recovery include? Choose three.
  22. 72. A vulnerability management team wants to pull the CISA Known Exploited Vulnerabilities catalog into its scanner automatically each morning and to give priority to flaws that attackers have used in ransomware campaigns. Which two published features of the catalog support this? Choose two.
  23. 78. A payments service fails part way through a multi-step transfer: funds have left the source ledger and the destination write has errored. Developers propose a handler that retries the remaining step and, failing that, marks the transfer complete so a nightly job can reconcile it. Which handling matches OWASP's 2025 guidance on exceptional conditions?
  24. 79. At a software vendor, one maintainer can merge a change and deploy it to production without another reviewer, and every environment rebuilds the application from source before deployment. A poisoned upstream dependency recently reached the entire customer fleet within an hour. Which two changes align with OWASP's 2025 supply chain guidance? Choose two.
  25. 411. An incident response plan cites the four-phase circular life cycle from the 2012 edition of NIST's incident handling guide. What changed in Revision 3?
  26. 412. In the SP 800-61 Rev. 3 life cycle, which Functions are preparation that supports response without being part of it, and which are the response itself?
  27. 413. A team holds every lesson learned until a formal review three months after recovery completes. What does NIST SP 800-61 Rev. 3 recommend?
  28. 414. Which two changes in the incident landscape does NIST SP 800-61 Rev. 3 give as reasons for recasting the life cycle? Choose two.
  29. 415. An analyst proposes that every event in the log stream be triaged as a potential incident. How does NIST SP 800-61 Rev. 3 define an event?
  30. 416. A power failure takes down a data hall. Under the vocabulary of NIST SP 800-61 Rev. 3, how is this classified, and is it in scope?
  31. 417. Which conditions bring an occurrence within the definition of a cybersecurity incident used by NIST SP 800-61 Rev. 3? Choose two.
  32. 418. A detection rule fires on an adverse cybersecurity event. What does NIST SP 800-61 Rev. 3 say about declaring an incident at that point?
  33. 419. A reader complains that Revision 3 of the incident response guidance no longer explains how to perform containment or eradication. What reason does the document give?
  34. 420. A board asks the security team to guarantee that no further incidents will occur. Which framing does NIST SP 800-61 Rev. 3 offer instead?
  35. 421. An operations team downloads a vendor patch and installs it straight onto a test host. Which step does NIST SP 800-40 Rev. 4 say must come first, and why?
  36. 422. A security lead argues patch testing is a security control. How does NIST SP 800-40 Rev. 4 characterise its purpose?
  37. 423. Two patches are available: one closes a critical flaw on internet-facing servers, the other a minor flaw on three test machines. On what basis does NIST SP 800-40 Rev. 4 say to order them?
  38. 424. After a patch deployment, an audit finds that several hardened settings have reverted to vendor defaults. Which risk does NIST SP 800-40 Rev. 4 identify here?
  39. 425. A monitoring dashboard shows a patch as installed but the vulnerability scanner still reports the flaw. Which explanation does NIST SP 800-40 Rev. 4 offer?
  40. 426. A patch causes an application to fail in production. Which three remedies does NIST SP 800-40 Rev. 4 name? Choose three.
  41. 427. An organisation records a patch as deployed once the distribution tool reports success. Which further step does NIST SP 800-40 Rev. 4 identify, and what does it need at scale?
  42. 428. Which four scenarios does NIST SP 800-40 Rev. 4 expect maintenance plans to cover?
  43. 429. A production line controller cannot be patched without vendor recertification that will take two years. Which approach does NIST SP 800-40 Rev. 4 prescribe? Choose two.
  44. 430. Which three tiers make up a log management infrastructure in NIST SP 800-92? Choose three.
  45. 431. A server receives logs from several hundred hosts and forwards them onward. What does NIST SP 800-92 call such a server, and where may the data live?
  46. 432. An architect places a first level of log servers close to the generators that simply receive and forward. Which two benefits does NIST SP 800-92 attribute to this arrangement? Choose two.
  47. 433. An organisation cannot fund a dedicated logging network. Which two points from NIST SP 800-92 apply? Choose two.
  48. 434. Which two things does NIST SP 800-92 say log rotation achieves, and what commonly happens to the closed file? Choose two.
  49. 435. An investigator asks the logging team to keep a set of firewall logs that the schedule would delete next week. Which form of archival is this, and how does it differ from the routine kind?
  50. 436. A logging team suppresses duplicate and routine informational entries from its analysis pipeline. What does NIST SP 800-92 say about the effect on the original logs?
  51. 437. A thousand log entries each recording part of one network scan are replaced by a single entry stating how many hosts were probed. Which log management function is this?
  52. 438. What distinguishes log reduction from event reduction in NIST SP 800-92, and when are they typically applied?
  53. 439. A team must correlate logs from sources that record time in different formats and label the field differently. Which function addresses this, and what is its cost?
  54. 440. Which two problems does NIST SP 800-92 identify when normalising times across log sources, and what does it recommend? Choose two.
  55. 441. An archive of log files must be shown to be unaltered months later. Which mechanism does NIST SP 800-92 describe, and what must be done with its output?
  56. 442. Why does NIST SP 800-92 insist that log management functions leave the original logs unaltered?
  57. 443. A team wants to find relationships between entries from a firewall and entries from an authentication server. Which function is this, and what is its commonest form?
  58. 444. A legacy appliance cannot forward its logs to any server and is not networked. What does NIST SP 800-92 suggest where those logs must still reach the infrastructure?
  59. 445. A large enterprise runs dozens of separate log management infrastructures and an auditor calls for consolidation into one. Which three objections does NIST SP 800-92 support? Choose three.
  60. 446. A tool reads database-held log records and writes them out as structured text files, filtering and normalising along the way. Which function does NIST SP 800-92 name for this?
  61. 447. Which three arrangements does NIST SP 800-34 recognise for obtaining an alternate site? Choose three.
  62. 448. A facility offers floor space, power, telecommunications connections and environmental controls, but no servers or network equipment. Which alternate site type is this?
  63. 449. A recovery facility holds some of the required servers and network equipment along with power and connectivity, but is not fully configured or staffed. Which site type does NIST SP 800-34 describe?
  64. 450. Which three characteristics does NIST SP 800-34 attribute to a hot site? Choose three.
  65. 451. A utility needs recovery capability that can be moved to wherever the disruption occurs. Which option does NIST SP 800-34 describe, and what is its practical timing?
  66. 452. Which two statements about a mirrored site match NIST SP 800-34? Choose two.
  67. 453. A budget review asks which alternate site type is cheapest to maintain and what it costs the organisation in return. What does NIST SP 800-34 say?
  68. 454. A firm proposes an alternate site five kilometres from its head office, in the same river valley, to keep travel short. Which two considerations from NIST SP 800-34 apply? Choose two.
  69. 455. A system categorised low impact under FIPS 199 has no alternate site strategy, and an auditor records this as a deficiency. What does NIST SP 800-34 actually require?
  70. 456. A team tests its backup media each quarter by restoring a sample in its own data centre. Which further test does NIST SP 800-34 call for?
  71. 457. An alternate site offers ample space, power and connectivity but cannot meet the system's access control and monitoring requirements. What does NIST SP 800-34 say about accepting it?
  72. 458. A ransomware group encrypts a victim's systems, having first copied the data out, and threatens to publish it unless paid. What is this pattern called, and what variant does CISA also describe?
  73. 459. An organisation keeps nightly backups on a network share reachable from the servers it protects. Which risk does CISA's ransomware guidance identify?
  74. 460. A recovery plan relies entirely on redeploying golden images. Which two additional measures does CISA's ransomware guidance recommend? Choose two.
  75. 461. An incident response plan is stored on the corporate file share and in the ticketing system. What does CISA's ransomware guidance ask for in addition?
  76. 462. A team proposes moving all backups to immutable cloud storage as a complete answer to ransomware. Which two cautions does CISA raise? Choose two.