Certified Information Systems Security Officer Exam Prep
Free practice questions

Free C)ISSO Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)ISSO exam has 100 questions and runs 2 hours.

These 10 free C)ISSO questions are organized by exam domain, so you can see how each part of the Certified Information Systems Security Officer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Risk Management

Question 1

A security officer identifies a database vulnerability with no evidence of exploitation. A patch is scheduled during the next maintenance window. Which risk response is being applied?

Show answer & explanation

Correct answer: B - Mitigate the risk

Domain 2: Security Management

Question 2

Which security model primarily enforces confidentiality by preventing subjects from reading data at a higher classification level?

Show answer & explanation

Correct answer: A - Bell-LaPadula

Domain 3: Cryptography

Question 3

A company encrypts large archives while minimizing processing overhead. Which cryptographic approach is most appropriate?

Show answer & explanation

Correct answer: C - Symmetric encryption

Domain 4: Identification, Authentication, and Access Control

Question 4

An organization assigns permissions according to job functions such as auditor and administrator. Which access control model best fits this design?

Show answer & explanation

Correct answer: A - Role-based access control

Domain 5: Data Security Management

Question 5

A company finds sensitive records are retained indefinitely. Which data security activity should be addressed first?

Show answer & explanation

Correct answer: B - Define retention and secure deletion rules

Domain 6: Operations Security

Question 6

Security logs show an account downloading hundreds of unusual files outside normal hours. What is the best initial action?

Show answer & explanation

Correct answer: B - Investigate using monitoring records

Domain 7: Network Connections, Protocols, Devices, and Designs

Question 7

Which network design principle limits attacker movement after one system is compromised?

Show answer & explanation

Correct answer: A - Network segmentation

Domain 8: IT and Business Security Architecture

Question 8

A company prevents one employee from approving and implementing a sensitive change. Which principle is applied?

Show answer & explanation

Correct answer: B - Separation of duties

Domain 9: Software Development Security

Question 9

Developers discover application input is inserted into database queries without validation. Which vulnerability is most likely?

Show answer & explanation

Correct answer: A - Injection

Domain 10: Business Continuity, Disaster Recovery, and Incident Management

Question 10

After identifying malware-affected systems, an incident team prevents further spread while preserving evidence. Which phase is occurring?

Show answer & explanation

Correct answer: B - Containment

The rest of the C)ISSO blueprint

The C)ISSO exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)ISSO questions with explanations.

Continue in the free practice test →

View plans