← All exams
Home · (ISC)² Certified Information Systems Security Professional

(ISC)² Certified Information Systems Security Professional

This certification is for experienced security practitioners, managers, and executives interested in proving their knowledge across a wide array of security practices and principles. Passing the exam demonstrates the advanced knowledge and technical skills to design, engineer, and manage an organization's overall security posture.

Pass mark 28/40 45 minutes Real test fee approx (ISC)² How many can I get wrong?
Weak on a topic? Drill just that one till it clicks, then move on.
Free practice questions
Try 3 real (ISC)² Certified Information Systems Security Professional questions
Have a go, then reveal the worked explanation. A taster from a bank of 208 original questions — unlock for unlimited drills and full timed mocks.
Q1. According to the (ISC)² Code of Ethics, which canon holds the highest priority and must be followed above all others?
  • A.  Provide diligent and competent service to principals.
  • B.  Act honorably, honestly, justly, responsibly, and legally.
  • C.  Protect society, the common good, necessary public trust and confidence, and the infrastructure.
  • D.  Advance and protect the profession.
Show answer & explanation
✓ Answer: C. Protect society, the common good, necessary public trust and confidence, and the infrastructure.
The first canon, 'Protect society, the common good...', is considered paramount. All other professional responsibilities and actions are secondary to this primary directive.
Q2. An organization is decommissioning several solid-state drives (SSDs) that contained highly sensitive information. Which data sanitization method is MOST effective for these devices?
  • A.  Degaussing
  • B.  Standard Formatting
  • C.  Cryptographic Erase (Crypto-Shredding)
  • D.  Overwriting with a single pass of zeros
Show answer & explanation
✓ Answer: C. Cryptographic Erase (Crypto-Shredding)
Degaussing is ineffective on SSDs as they store data electronically, not magnetically. Cryptographic erase, which involves destroying the encryption key, is the most effective and efficient method for sanitizing SSDs.
Q3. When evaluating a system's security architecture, what is the primary characteristic of the Trusted Computing Base (TCB)?
  • A.  It includes all hardware and software components within a system.
  • B.  It is the set of all protective mechanisms within a system responsible for enforcing the security policy.
  • C.  It is a third-party service that validates the system's security posture.
  • D.  It refers exclusively to the cryptographic hardware module, such as a TPM.
Show answer & explanation
✓ Answer: B. It is the set of all protective mechanisms within a system responsible for enforcing the security policy.
The TCB is the totality of protection mechanisms (hardware, firmware, software) that are responsible for enforcing a security policy. It should be kept as small as possible to be verifiable.
Start here
Ten questions to see where you stand
Two minutes, no timer, marked the moment you finish with every answer explained. Then you'll know which topics need the work before you sit a full mock.
Exam mode
Full mock exam
40 random questions, real timing, marked against the official pass mark. Different every time.
Create a free account for a full mock
No card needed. A free account unlocks a full timed mock and 3 drills on every exam.
Try it free
Topic drills
Ten quick questions on one topic, marked instantly with explanations.
1 free drill left — then a free account unlocks 3 + a full mock.
Security and Risk Management · 30
Asset Security · 30
Security Architecture and Engineering · 30
Communication and Network Security · 30
Identity and Access Management (IAM) · 29
Security Assessment and Testing · 19
Security Operations · 20
Software Development Security · 20
(ISC)² Certified Information Systems Security Professional — common questions
Frequently asked
How many questions are in the (ISC)² Certified Information Systems Security Professional?
The exam has 40 questions. Every Revision Robin mock uses the same 40-question format so your practice matches the real thing.
What is the pass mark for the (ISC)² Certified Information Systems Security Professional?
You need 28 out of 40 correct to pass, which is about 70%. Our mocks mark you against this exact threshold.
How long do you get?
The test is timed at 45 minutes. Our full mock runs on the same clock so you can practise your pacing.
Are these the real exam questions?
No. Our questions are original and written to match the current syllabus, so they give realistic practice without copying the official paper. Every answer comes with a plain-English explanation. Always confirm current rules and content with (ISC)².
How much does the official test cost?
The official (ISC)² fee is approx. Revision Robin practice is separate and helps you pass first time so you only pay that fee once.