CISSP
What should you ask in a CISSP interview, and how should candidates answer?
CISSP covers eight domains, so a CISSP on a CV signals breadth. These questions test one domain each in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CISSP candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How would you assess the risk of a new SaaS vendor?
Listen for: What data and processes it touches, the threats, likelihood and impact, a treatment choice (accept, reduce, transfer, avoid) and an owner who signs it off. Supply chain risk named.
Domain 1: Security and Risk Management
How do you decide how long we keep data, and how we dispose of it?
Listen for: Classification first, then legal and business retention needs, a named owner, and secure disposal at end of life.
Domain 2: Asset Security
When would you choose symmetric over asymmetric encryption?
Listen for: Symmetric for speed and bulk data, asymmetric for key exchange and signatures, usually both together, and key management as the hard part.
Domain 3: Security Architecture and Engineering
How would you segment our network?
Listen for: Zones by trust and data sensitivity, only the flows that are needed, monitoring at the boundaries, and how remote and cloud access fit.
Domain 4: Communication and Network Security
Walk me through joiners, movers and leavers.
Listen for: Approved provisioning, role-based access, regular access reviews, and access removed on the day someone leaves.
Domain 5: Identity and Access Management
How do you know a control actually works?
Listen for: A test plan, evidence, the difference between a vulnerability scan and a penetration test, and a report the control owner acts on.
Domain 6: Security Assessment and Testing
Talk me through the first hour of a ransomware incident.
Listen for: Contain, preserve evidence, follow the incident plan, escalate, communicate, and leave any payment decision to the business and legal.
Domain 7: Security Operations
How do you get security into a development team's sprint?
Listen for: Threat modeling early, secure coding standards, automated testing in the pipeline, and a person in the team who owns it.
Domain 8: Software Development Security
CISSP interview scorecard
CISSP interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you assess the risk of a new SaaS vendor? | What data and processes it touches, the threats, likelihood and impact, a treatment choice (accept, reduce, transfer, avoid) and an owner who signs it off. Supply chain risk named. | |
| 2 | How do you decide how long we keep data, and how we dispose of it? | Classification first, then legal and business retention needs, a named owner, and secure disposal at end of life. | |
| 3 | When would you choose symmetric over asymmetric encryption? | Symmetric for speed and bulk data, asymmetric for key exchange and signatures, usually both together, and key management as the hard part. | |
| 4 | How would you segment our network? | Zones by trust and data sensitivity, only the flows that are needed, monitoring at the boundaries, and how remote and cloud access fit. | |
| 5 | Walk me through joiners, movers and leavers. | Approved provisioning, role-based access, regular access reviews, and access removed on the day someone leaves. | |
| 6 | How do you know a control actually works? | A test plan, evidence, the difference between a vulnerability scan and a penetration test, and a report the control owner acts on. | |
| 7 | Talk me through the first hour of a ransomware incident. | Contain, preserve evidence, follow the incident plan, escalate, communicate, and leave any payment decision to the business and legal. | |
| 8 | How do you get security into a development team's sprint? | Threat modeling early, secure coding standards, automated testing in the pipeline, and a person in the team who owns it. |
Source: https://credentialpress.com/guides/cissp-interview-questions
Which questions should a CISSP candidate prepare for?
Which domain is your strongest, and which your weakest?
How to answer: Name both. For the weak one, say what you did about it and how it shows in your work.
CISSP is broad. Where is your depth?
How to answer: Pick one or two domains and give a real example in each. Breadth got you the interview; depth gets the offer.
Tell me about a security decision the business pushed back on.
How to answer: Describe the risk in business terms, what you proposed, what was agreed and what you would do differently.
How do you keep current?
How to answer: Name your sources and how you earn continuing education credits. Specific beats generic.
What should a candidate ask the employer?
- Which of the eight domains will this role spend most of its time in?
- Who does security report to, and how often does it reach the board?
- How do you measure whether security is working?
Where next?
Also free: the CISSP mind map and the CISSP 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CISSP Exam Guide and the CISSP Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CISSP candidate?
Questions that test each exam domain in practice, for example: How would you assess the risk of a new SaaS vendor? How do you decide how long we keep data, and how we dispose of it? When would you choose symmetric over asymmetric encryption?
What should a CISSP candidate ask the employer?
Which of the eight domains will this role spend most of its time in? Who does security report to, and how often does it reach the board? How do you measure whether security is working?
How should a candidate prepare for a CISSP interview?
Name both. For the weak one, say what you did about it and how it shows in your work.
Which books go deeper on CISSP?

Certified Information Systems Security Professional. 14 chapters, 396 pages.

Practice questions with full rationales, sized to the published domain weights. 217 pages.
Sources
- ISC2, CISSP Certification Exam Outline, effective 15 April 2024, read 3 October 2026
- ISC2, Computerized Adaptive Testing, read 2 October 2026
- NIST SP 800-53 Rev. 5, Security and Privacy Controls
- NIST SP 800-34 Rev. 1, Contingency Planning Guide
- NIST FIPS 186-5, Digital Signature Standard
Credential Press is independent of ISC2.