CISSP Cheat Sheet 2026
The 30 highest-yield CISSP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
240 min time limit
70% to pass
- What is the PRIMARY purpose of a Configuration Management Database (CMDB) in security operations? → Maintaining authoritative records of IT assets and their relationships
- A data owner has labeled a file as 'Confidential.' Who is responsible for implementing the appropriate security controls on that file? → The data custodian
- What is the primary consideration when implementing changes to security architecture? → Impact assessment and change management
- An organization's IR plan calls for isolating an infected workstation by disabling its network interface. Which containment strategy does this represent? → Short-term containment
- Which BCP document lists the specific steps staff must follow to restore a critical system after a disaster? → Disaster Recovery Plan
- An IDS generates an alert for a known attack signature, but investigation reveals no actual attack occurred. This scenario is BEST described as: → False positive
- A CISSP candidate evaluates a third-party library with an open-source license. What is the MOST critical security concern for software supply chain integrity? → Verifying the library's cryptographic hash against the official repository
- What is the purpose of a 'tiger team' in the context of security assessments? → A group of security experts authorized to conduct aggressive, goal-based offensive testing
- The Gramm-Leach-Bliley Act (GLBA) primarily requires which type of organization to protect customer financial information? → Financial institutions
- A company's BCP requires that critical systems be restored within 4 hours of a disaster. Which metric defines this requirement? → Recovery Time Objective (RTO)
- Which NIST Special Publication provides the primary guidelines for computer security incident handling? → NIST SP 800-61
- Which sanitization method is appropriate for reusing a hard drive within the SAME security domain? → Purging (overwriting)
- An organization wants to protect its perimeter from vehicle ramming attacks. Which control is MOST effective? → Bollards or concrete barriers
- An organization stores customer credit card data. Under PCI DSS, what is the MINIMUM protection required for stored Primary Account Numbers (PAN)? → Any of: truncation, tokenization, hashing, or encryption
- Which factor is MOST important when selecting a geographic location for an alternate processing site? → Location outside the same natural disaster risk zone as the primary site
- Which threat modeling methodology uses attack trees to enumerate potential attack paths against a system? → Attack tree analysis
- Which type of data classification is MOST common in private sector organizations? → Public / Internal / Confidential / Restricted
- Which metric is most useful for evaluating program effectiveness in CISSP? → Outcome-based performance indicators
- Which concept describes the risk that cloud data may be subject to the laws of the country where the data center resides? → Data sovereignty
- A CISSP candidate reviews a system where subjects access objects based on their security clearance and object classification labels. Which model is in use? → Bell-LaPadula
- What is the PRIMARY purpose of a call tree in a BCP? → To ensure rapid and structured notification of key personnel
- Which XML-specific vulnerability allows an attacker to read arbitrary files on the server by referencing external entities in a crafted XML document? → XML External Entity (XXE) Injection
- Which padding scheme is recommended for RSA encryption to prevent attacks such as Bleichenbacher's attack? → OAEP (Optimal Asymmetric Encryption Padding)
- What is the key benefit of evidence-based decision making in CISSP management? → It improves accuracy and reduces bias in decisions
- The Clark-Wilson integrity model primarily addresses which type of environment? → Commercial transaction integrity
- What is the main purpose of a privacy impact assessment (PIA)? → To identify and mitigate privacy risks before deploying new systems or processes
- What is a rainbow table attack, and what control most effectively mitigates it? → Precomputed hash lookup attack; mitigated by salting passwords
- When implementing IPsec in tunnel mode between two VPN gateways, which part of the original packet is encrypted? → The entire original IP packet (header + payload)
- In a SaaS model, who is responsible for patching the application software? → The cloud service provider
- In a zero trust architecture, what is the role of the Policy Decision Point (PDP)? → Evaluates access requests against policy and grants or denies access
Turn these facts into recall:
Was this helpful?