7.0 Security Operations CISSP Practice Quiz
104 exam-style questions covering 13% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regional bank's SOC is rebuilding its incident response runbooks after a tabletop exercise. The security operations team must make a decision involving investigations in security operations. What is the best recommendation?
- A. Preserve evidence, document chain of custody, and coordinate with legal before expanding the investigation
- B. Reach out to regulators informally before legal and executive coordination
- C. Permit any admin to handle potential evidence without chain of custody
- D. Email investigation details to all employees in the name of transparency
Operational investigations require evidence integrity, authorized handling, and legally informed decisions. This is the correct answer.
A pharmaceutical contract manufacturer is updating its operations playbooks after a peer breach. A proposed operational process creates risk around investigations in security operations. Which change best addresses the concern?
- A. Safeguard evidence, document chain of custody, and coordinate with legal before expanding the investigation
- B. Contact regulators ahead of any legal or executive coordination
- C. Permit any admin to alter potentially relevant evidence without records
- D. Email investigation status to all employees for transparency
Operational investigations require evidence integrity, authorized handling, and legally informed decisions. This is the correct answer.
A federal civilian agency is integrating logging and monitoring across its civilian-tier systems. An operational review identifies a weakness in investigations in security operations. Which action should be prioritized?
- A. Contact regulators by phone before coordinating with legal and executives
- B. Determine the investigation type and authority before collecting sensitive employee, customer, or system data
- C. Allow administrators to alter potential evidence without documentation
- D. Post investigation status broadly to staff for transparency
Administrative, civil, criminal, regulatory, and industry investigations have different requirements. This is the correct answer.
A defense contractor is reviewing its security operations against revised CMMC L2 requirements. Executives need a risk-based explanation for investigations in security operations. Which response best aligns with security operations practice?
- A. Notify regulators informally before legal team or executive involvement
- B. Establish the investigation type and authority before collecting sensitive employee, customer, or system data
- C. Allow administrators broad access to potential evidence without documentation
- D. Post investigation details enterprise-wide for transparency
Administrative, civil, criminal, regulatory, and industry investigations have different requirements. This is the correct answer.
A regional credit union's SOC is integrating new EDR tooling across its branches. Executives need a risk-based explanation for logging and monitoring activities. Which response best aligns with security operations practice?
- A. Turn off alerts because the SOC receives too many notifications
- B. Synchronize time across systems so events can be correlated accurately
- C. Ingest every available log with no plan for tuning or retention
- D. Save security logs where monitored administrators can freely delete them
Consistent timestamps are essential for monitoring, incident reconstruction, and audits. This is the correct answer.
A children's hospital is reviewing its incident response capabilities ahead of an OCR audit. The CISO asks for CISSP-level guidance on investigations in security operations. Which approach is most appropriate?
- A. Inform regulators informally before legal and executive engagement
- B. Permit any admin to touch evidence-grade artifacts without records
- C. Limit investigation details to personnel with a legitimate need to know
- D. Send investigation updates to every employee for transparency
Confidentiality protects evidence, privacy, and the integrity of the investigative process. This is the correct answer.
A regional utility's SOC is integrating OT and IT alert telemetry following an industry warning. The security operations team must make a decision involving investigations in security operations. What is the best recommendation?
- A. Reach out to regulators by phone before coordinating internally
- B. Permit any admin to handle and modify potential evidence without records
- C. Restrict investigation details to personnel with a legitimate need to know
- D. Send investigation conclusions to all staff for transparency
Confidentiality protects evidence, privacy, and the integrity of the investigative process. This is the correct answer.
A SaaS provider is hardening its production runbooks following a degraded-service incident. A security operations exercise must address investigations in security operations. What should the security professional recommend?
- A. Reach out to regulators directly before involving legal or executives
- B. Allow administrators to handle potential evidence with no documentation
- C. Broadcast investigation findings widely to staff for transparency
- D. Coordinate containment actions with evidence preservation requirements
Operational response can alter evidence, so investigators must balance stopping harm with preserving facts. This is the correct answer.
Key Terms in This Domain
- ISO 27001: International standard for an information security management system (ISMS)
- HSM: Hardware Security Module: tamper-resistant key management device
- Incident Response: Detection, response, mitigation, reporting, recovery, remediation, lessons learned
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- Threat: Any potential cause of an unwanted incident harming a system
- RTO: Recovery Time Objective: max acceptable downtime
- RPO: Recovery Point Objective: max acceptable data loss
- NIST Risk Management Framework: NIST SP 800-37 lifecycle for managing information system risk
- Data Processor: Processes personal data on behalf of a controller
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/security-operations/
<a href="https://quizbuffet.com/isc2-cissp/security-operations/">CISSP (ISC2) Security Operations practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 2.0 Asset Security
- 3.0 Security Architecture and Engineering
- 4.0 Communication and Network Security
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.