CISSP Cheat Sheet 2026

The 30 highest-yield CISSP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
240 min time limit
70% to pass
  1. What is the PRIMARY purpose of a Configuration Management Database (CMDB) in security operations? Maintaining authoritative records of IT assets and their relationships
  2. A data owner has labeled a file as 'Confidential.' Who is responsible for implementing the appropriate security controls on that file? The data custodian
  3. What is the primary consideration when implementing changes to security architecture? Impact assessment and change management
  4. An organization's IR plan calls for isolating an infected workstation by disabling its network interface. Which containment strategy does this represent? Short-term containment
  5. Which BCP document lists the specific steps staff must follow to restore a critical system after a disaster? Disaster Recovery Plan
  6. An IDS generates an alert for a known attack signature, but investigation reveals no actual attack occurred. This scenario is BEST described as: False positive
  7. A CISSP candidate evaluates a third-party library with an open-source license. What is the MOST critical security concern for software supply chain integrity? Verifying the library's cryptographic hash against the official repository
  8. What is the purpose of a 'tiger team' in the context of security assessments? A group of security experts authorized to conduct aggressive, goal-based offensive testing
  9. The Gramm-Leach-Bliley Act (GLBA) primarily requires which type of organization to protect customer financial information? Financial institutions
  10. A company's BCP requires that critical systems be restored within 4 hours of a disaster. Which metric defines this requirement? Recovery Time Objective (RTO)
  11. Which NIST Special Publication provides the primary guidelines for computer security incident handling? NIST SP 800-61
  12. Which sanitization method is appropriate for reusing a hard drive within the SAME security domain? Purging (overwriting)
  13. An organization wants to protect its perimeter from vehicle ramming attacks. Which control is MOST effective? Bollards or concrete barriers
  14. An organization stores customer credit card data. Under PCI DSS, what is the MINIMUM protection required for stored Primary Account Numbers (PAN)? Any of: truncation, tokenization, hashing, or encryption
  15. Which factor is MOST important when selecting a geographic location for an alternate processing site? Location outside the same natural disaster risk zone as the primary site
  16. Which threat modeling methodology uses attack trees to enumerate potential attack paths against a system? Attack tree analysis
  17. Which type of data classification is MOST common in private sector organizations? Public / Internal / Confidential / Restricted
  18. Which metric is most useful for evaluating program effectiveness in CISSP? Outcome-based performance indicators
  19. Which concept describes the risk that cloud data may be subject to the laws of the country where the data center resides? Data sovereignty
  20. A CISSP candidate reviews a system where subjects access objects based on their security clearance and object classification labels. Which model is in use? Bell-LaPadula
  21. What is the PRIMARY purpose of a call tree in a BCP? To ensure rapid and structured notification of key personnel
  22. Which XML-specific vulnerability allows an attacker to read arbitrary files on the server by referencing external entities in a crafted XML document? XML External Entity (XXE) Injection
  23. Which padding scheme is recommended for RSA encryption to prevent attacks such as Bleichenbacher's attack? OAEP (Optimal Asymmetric Encryption Padding)
  24. What is the key benefit of evidence-based decision making in CISSP management? It improves accuracy and reduces bias in decisions
  25. The Clark-Wilson integrity model primarily addresses which type of environment? Commercial transaction integrity
  26. What is the main purpose of a privacy impact assessment (PIA)? To identify and mitigate privacy risks before deploying new systems or processes
  27. What is a rainbow table attack, and what control most effectively mitigates it? Precomputed hash lookup attack; mitigated by salting passwords
  28. When implementing IPsec in tunnel mode between two VPN gateways, which part of the original packet is encrypted? The entire original IP packet (header + payload)
  29. In a SaaS model, who is responsible for patching the application software? The cloud service provider
  30. In a zero trust architecture, what is the role of the Policy Decision Point (PDP)? Evaluates access requests against policy and grants or denies access
Turn these facts into recall:
Was this helpful?