ISC2 CISSP-ISSEP Sample Questions:

01. Which of the following federal laws are related to hacking activities?
(Choose three.)
a) 18 U.S.C. 1030
b) 18 U.S.C. 1029
c) 18 U.S.C. 2510
d) 18 U.S.C. 1028
02. In which of the following DIACAP phases is residual risk analyzed?
a) Phase 2
b) Phase 3
c) Phase 5
d) Phase 1
e) Phase 4
03. Which of the following types of CNSS issuances establishes criteria, and assigns responsibilities?
a) Advisory memoranda
b) Directives
c) Instructions
d) Policies
04. Which of the following DITSCAP/NIACAP model phases is used to show the required evidence to support the DAA in accreditation process and conclude in an Approval To Operate (ATO)?
a) Verification
b) Validation
c) Post accreditation
d) Definition
05. NIST SP 800-53A defines three types of interview depending on the level of assessment conducted. Which of the following NIST SP 800-53A interviews consists of informal and ad hoc interviews?
a) Abbreviated
b) Significant
c) Substantial
d) Comprehensive
06. You work as an ISSE for BlueWell Inc. You want to break down user roles, processes, and information until ambiguity is reduced to a satisfactory degree.
Which of the following tools will help you to perform the above task?
a) PERT Chart
b) Gantt Chart
c) Functional Flow Block Diagram
d) Information Management Model (IMM)
07. Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?
a) DoD 5200.22-M
b) DoD 8910.1
c) DoD 5200.40
d) DoD 8000.1
08. Which of the following is NOT an objective of the security program?
a) Security education
b) Information classification
c) Security organization
d) Security plan
09. Which of the following configuration management system processes keeps track of the changes so that the latest acceptable configuration specifications are readily available?
a) Configuration Identification
b) Configuration Verification and Audit
c) Configuration Status and Accounting
d) Configuration Control
10. Which of the following principles are defined by the IATF model?
(Choose two.)
a) The degree to which the security of the system, as it is defined, designed, and implemented, meets the security needs.
b) The problem space is defined by the customer's mission or business needs
c) The systems engineer and information systems security engineer define the solution space, which is driven by the problem space.
d) Always keep the problem and solution spaces separate.


Question: 01
Answer: a, b, c
Question: 02
Answer: e
Question: 03
Answer: d
Question: 04
Answer: b
Question: 05
Answer: a
Question: 06
Answer: d
Question: 07
Answer: c
Question: 08
Answer: d
Question: 09
Answer: c
Question: 10
Answer: b, c, d

