CISSP study material // original practice items

Not exam content · rev 2026-10

CISSP CAT Practice

CISSP prep console8 domains · outline Apr 2024

Get the app

Doc CC-06Rev 2026-10Class study materialRead ~8 min

CISSP Domain 1: Security and Risk Management (16%) — what’s tested and the traps

Domain 1 of the ISC2 CISSP (Certified Information Systems Security Professional) exam is Security and Risk Management: 16% of the current outline (effective April 2024), the heaviest of the eight domains. It tests judgment from a manager’s chair — ethics, governance, law, continuity, personnel and risk.

Exam readout

Format
CAT, every language
Items
100–150
Time
3 hours
Pass mark
700 / 1000 scaled
Outline
8 domains · Apr 2024

Domain 1 at a glance

  • Weight

    16%

    Largest slice of the outline; 15% in the 2021 version.

  • Point of view

    Manager

    Advise, align, escalate. Fix it yourself: rarely.

  • Arithmetic

    Light

    Two risk formulas and one downtime inequality. That is the whole budget.

  • Practice here

    12 items

    Every option explained.

What Domain 1 is really testing

Domain 1 reads like a governance syllabus, but the questions are not recall drills. An item hands you a scenario — a merger, a breach, a regulator, a vendor with a worrying contract — and asks what to do first or what is best. All four options will be defensible; the item writers are thorough like that.

The winning option is what a security advisor reporting to senior management would do. Management owns risk and is the only party that accepts it; the security function measures and recommends. Quietly accepting a risk on the company’s behalf, or patching before anyone with authority knows, is a distractor in a hero costume.

The mindset carries into the other seven domains, so Domain 1 belongs early in a study plan. The format itself lives on the CISSP exam page.

The order a Domain 1 answer usually follows

When two options both look right, rank them against this sequence. It breaks most ties.

  1. Step 01

    People’s safety

    Human life before data, systems and schedules. An evacuation beats a backup every time.

  2. Step 02

    Law and the business mission

    Legal and regulatory obligations, then the organization’s objectives.

  3. Step 03

    Policy and the risk owner

    Check what policy says, then inform or escalate to the owner. Senior management makes the acceptance call.

  4. Step 04

    Analysis before action

    Assess, run the business impact analysis, gather facts. Buying a tool before you know the risk is a favorite wrong answer.

  5. Step 05

    The technical control

    The fix ranks last — not because it matters less, but because someone else has to approve it.

The Domain 1 map

Domain 1 register: topic, question shape, usual trap
RefTopicThe question asks you toThe usual trap
R-01Professional ethicsResolve a conflict with the ISC2 Code of EthicsTreating the canons as equal — the earlier one wins
R-02Security conceptsName the property a control protects: CIA, authenticity, non-repudiationConfusing integrity with authenticity
R-03Governance and rolesMatch a duty to management, owner, custodian or securityLetting the security team accept risk
R-04Due care and diligenceLabel an activity as investigating or actingSwapping the two
R-05Law, regulation, privacyRecognize law types, IP protections, privacy roles, export rulesCalling a trade secret a patent
R-06InvestigationsPick the type and its standard of proofThe criminal standard for an internal policy breach
R-07Policy hierarchyPlace a document in the hierarchyReading a guideline as mandatory
R-08Business continuityRun the BIA, derive RTO, RPO and MTDTreating RPO as a downtime target
R-09Personnel securityChoose the hiring, transfer or termination controlRevoking access after the exit meeting
R-10Risk managementCalculate ALE, choose a response, classify a controlWeighing a safeguard against SLE, not ALE
R-11Threat modelingApply a method such as STRIDEModeling after deployment
R-12Supply chain riskAssess a supplier, set contract requirementsThinking outsourcing moves accountability
R-13Awareness and trainingTell awareness, training and education apartCounting attendance as behavior change

Due care vs due diligence

The pair the exam returns to most, worded least consistently across study sources. Pick one definition and hold it.

Due diligence
The knowing part: investigating, assessing and verifying — a supplier assessment, a risk analysis, an audit of a control. Mnemonic: do detect.
Due care
The doing part: acting as a prudent person would by implementing and maintaining protections. Mnemonic: do correct.

The ISC2 Code of Ethics: four canons and a tie-breaker

Ethics items are short and unforgiving. The Code has a preamble and four canons, and the favorite move is a conflict between two of them. The canons carry an order of priority — when two pull apart, the earlier one decides:

  • Protect society, the common good, public trust and the infrastructure.
  • Act honorably, honestly, justly, responsibly and legally.
  • Give diligent, competent service to principals — your employer or client.
  • Advance and protect the profession.

A duty to the public outranks a duty to your employer, and the profession comes last. Read each scenario for whose interest is at stake: hiding a flaw to keep a client contract versus disclosing it to protect the public is not close under this ordering.

Policy, standard, baseline, procedure, guideline

Document hierarchy, from intent to instructions
DocumentMandatory?What it saysExample
PolicyYesSenior management’s intent, high levelData at rest is encrypted
StandardYesA specific, uniform requirementAES with 256-bit keys on every laptop
BaselineYesMinimum configuration for a system typeThe hardened build every server starts from
ProcedureYesStep-by-step instructionsHow to enroll a laptop in disk encryption
GuidelineNoRecommended practiceSuggested passphrase style

Only the guideline is optional. The other four are requirements written at different altitudes.

Law, investigations and privacy

Domain 1 stays at manager level: which kind of law applies, who investigates, and how much proof each path needs. Nobody asks you to cite statutes.

Four investigation types

  • Criminal — brought by the state; beyond a reasonable doubt.
  • Civil — between parties, usually over money; preponderance of the evidence.
  • Administrative — internal policy breaches; the lowest bar.
  • Regulatory — the standard set by the regulator or industry rule.

Intellectual property and privacy

Copyright protects expression such as code, trademarks protect names and logos, patents protect inventions in exchange for public disclosure, and trade secrets stay valuable only while secret — file a patent on one and it stops being a secret. On privacy, expect GDPR roles (the controller decides why and how data is processed; the processor acts on its behalf), transborder data flow, licensing and export controls on cryptography. Data handling itself belongs to Domain 2.

The risk arithmetic

Quantitative risk analysis on the exam is multiplication with acronyms. Learn the names cold; the numbers tend to be friendly.

  • Single loss expectancy

    SLE = AV × EF

    Asset value times exposure factor, the share one incident destroys.

  • Annualized loss expectancy

    ALE = SLE × ARO

    ARO is the yearly rate: once in ten years is 0.1.

  • Safeguard value

    ALE before − ALE after − annual safeguard cost

    Positive means the control pays for itself. Forgetting the last term is the classic slip.

  • Downtime ceiling

    MTD ≥ RTO + WRT

    Restore time plus work recovery time must fit inside maximum tolerable downtime.

Risk work beyond the arithmetic

A worked case: a warehouse system worth $400,000 loses 25% of its value in a flood, so SLE is $100,000. Floods come once in 20 years (ARO 0.05), so ALE is $5,000. A barrier cuts ARO to 0.01 and ALE to $1,000, but costs $6,000 a year: $5,000 − $1,000 − $6,000 = −$2,000. It loses money; pick another response.

Qualitative analysis ranks risks with ratings, scenarios and expert judgment; the Delphi technique keeps opinions anonymous so the most senior voice does not set the score. The exam usually asks which method a scenario describes.

Four responses and one non-answer

  • Mitigate — controls that lower likelihood or impact.
  • Transfer or share — insurance or contract moves the financial impact.
  • Avoid — stop the risky activity.
  • Accept — a documented management decision for residual risk within appetite.

Ignoring a risk is never on the list, however often it happens in practice.

Control types and categories

Types say what a control does: preventive, detective, corrective, deterrent, recovery, compensating, directive. Categories say what it is made of: administrative, technical or physical. A guard dog deters and detects at once. A compensating control stands in for one you cannot implement; a corrective control repairs damage after the event.

Business continuity: BIA, RTO, RPO, MTD

Continuity planning starts with the business impact analysis: critical processes, their dependencies, and how long each can be down before the damage is unacceptable. Every recovery number on the exam comes from the BIA, not from what IT thinks it can manage.

  • MTD — the longest a process can be unavailable.
  • RTO — the target time to restore the system.
  • WRT — time to verify data and resume work once the system is back.
  • RPO — tolerable data loss measured in time; it sets backup frequency, not downtime.

The BCP keeps critical business functions running and is strategic; the disaster recovery plan restores IT and facilities and is one tactical part of it. An option calling the DRP the broader plan is wrong. Recovery sites and DR tests belong to Domain 7 — the study guide maps where each topic sits.

Twelve Domain 1 scenarios

Original practice items for this domain, with a note on every option once you answer. They show where your reasoning holds; they do not estimate a score. Mixed domains are on the practice test.

Domain drill

Item 01 / 12

Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.

D1Security and Risk Management

A critical application experiences an outage once every five years. The typical disruption lasts for 4,320 minutes before services are restored. The business impact analysis determines that downtime costs $500 per hour. Management is evaluating several continuity strategies to improve resilience. Which strategy is financially justified?

Rationale

Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.

The smaller objectives that still cost points

Personnel security

Background checks before hiring, NDAs at onboarding, separation of duties, job rotation and mandatory vacation to surface fraud, and access removal at termination — while the exit interview is happening, not the following Monday. Contractors fall under the same controls through their contracts.

Threat modeling

STRIDE sorts threats into spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege; PASTA is a risk-centric process in seven stages. The exam tests timing: model threats at design, while changes are cheap.

Supply chain risk management

Suppliers extend your attack surface through tampered hardware, compromised updates and weak service providers. Expect assessment before signing, security requirements and audit rights in the contract, and monitoring afterwards. Third-party components return in Domain 3.

Awareness, training and education

Awareness changes attention, training builds a job skill, education builds understanding over a career. A sound program is role-based, refreshed on a schedule and measured by behavior, not by clicks on complete.

Questions people ask

Q01What is Domain 1 of CISSP?

Security and Risk Management, the heaviest of the eight domains at 16% of the outline effective April 2024: ethics, security concepts, governance, law and privacy, investigations, policies, continuity, personnel, risk, threat modeling, supply chain and awareness. The authoritative list is the ISC2 exam outline.

Q02What is the difference between due care and due diligence?

Due diligence is investigating and verifying — assessments, audits, risk analysis. Due care is acting on it as a prudent person would — implementing and maintaining controls. Diligence finds out; care follows through.

Q03How many Domain 1 questions are on the CISSP exam?

ISC2 publishes weights, not a per-domain count. The adaptive exam runs 100–150 items, so the number varies; 16% means Domain 1 is the largest share on average.

Q04Does Domain 1 overlap with CISM?

In governance and risk, yes. CISM goes deeper on security management; CISSP adds seven more domains. See CISSP vs CISM.

Debrief · key takeaways

  1. Domain 1 is 16% of the current outline, the largest single domain.
  2. Answer from the advisor’s chair; the technical fix comes last.
  3. Due diligence investigates; due care implements.
  4. Only the guideline is optional in the policy hierarchy.
  5. ALE = SLE × ARO; a safeguard must cut ALE by more than it costs per year.
  6. RPO drives backup frequency; RTO plus WRT must fit inside MTD.

Where to go next

Field kit

Take the Domain 1 scenarios with you

More practice by domain on your phone, with the reasoning behind every option.

Get the appPractice free on this site

End of document

Handle with mild caffeine