CISSP

What should you ask in a CISSP interview, and how should candidates answer?

CISSP covers eight domains, so a CISSP on a CV signals breadth. These questions test one domain each in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.

What should an employer ask a CISSP candidate?

Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.

  1. How would you assess the risk of a new SaaS vendor?

    Listen for: What data and processes it touches, the threats, likelihood and impact, a treatment choice (accept, reduce, transfer, avoid) and an owner who signs it off. Supply chain risk named.

    Domain 1: Security and Risk Management

  2. How do you decide how long we keep data, and how we dispose of it?

    Listen for: Classification first, then legal and business retention needs, a named owner, and secure disposal at end of life.

    Domain 2: Asset Security

  3. When would you choose symmetric over asymmetric encryption?

    Listen for: Symmetric for speed and bulk data, asymmetric for key exchange and signatures, usually both together, and key management as the hard part.

    Domain 3: Security Architecture and Engineering

  4. How would you segment our network?

    Listen for: Zones by trust and data sensitivity, only the flows that are needed, monitoring at the boundaries, and how remote and cloud access fit.

    Domain 4: Communication and Network Security

  5. Walk me through joiners, movers and leavers.

    Listen for: Approved provisioning, role-based access, regular access reviews, and access removed on the day someone leaves.

    Domain 5: Identity and Access Management

  6. How do you know a control actually works?

    Listen for: A test plan, evidence, the difference between a vulnerability scan and a penetration test, and a report the control owner acts on.

    Domain 6: Security Assessment and Testing

  7. Talk me through the first hour of a ransomware incident.

    Listen for: Contain, preserve evidence, follow the incident plan, escalate, communicate, and leave any payment decision to the business and legal.

    Domain 7: Security Operations

  8. How do you get security into a development team's sprint?

    Listen for: Threat modeling early, secure coding standards, automated testing in the pipeline, and a person in the team who owns it.

    Domain 8: Software Development Security

CISSP interview scorecard

CISSP interview scorecard

Candidate: ______ Interviewer: ______ Date: ______

#QuestionListen forScore 1 to 4
1How would you assess the risk of a new SaaS vendor?What data and processes it touches, the threats, likelihood and impact, a treatment choice (accept, reduce, transfer, avoid) and an owner who signs it off. Supply chain risk named.
2How do you decide how long we keep data, and how we dispose of it?Classification first, then legal and business retention needs, a named owner, and secure disposal at end of life.
3When would you choose symmetric over asymmetric encryption?Symmetric for speed and bulk data, asymmetric for key exchange and signatures, usually both together, and key management as the hard part.
4How would you segment our network?Zones by trust and data sensitivity, only the flows that are needed, monitoring at the boundaries, and how remote and cloud access fit.
5Walk me through joiners, movers and leavers.Approved provisioning, role-based access, regular access reviews, and access removed on the day someone leaves.
6How do you know a control actually works?A test plan, evidence, the difference between a vulnerability scan and a penetration test, and a report the control owner acts on.
7Talk me through the first hour of a ransomware incident.Contain, preserve evidence, follow the incident plan, escalate, communicate, and leave any payment decision to the business and legal.
8How do you get security into a development team's sprint?Threat modeling early, secure coding standards, automated testing in the pipeline, and a person in the team who owns it.

Source: https://credentialpress.com/guides/cissp-interview-questions

Which questions should a CISSP candidate prepare for?

  1. Which domain is your strongest, and which your weakest?

    How to answer: Name both. For the weak one, say what you did about it and how it shows in your work.

  2. CISSP is broad. Where is your depth?

    How to answer: Pick one or two domains and give a real example in each. Breadth got you the interview; depth gets the offer.

  3. Tell me about a security decision the business pushed back on.

    How to answer: Describe the risk in business terms, what you proposed, what was agreed and what you would do differently.

  4. How do you keep current?

    How to answer: Name your sources and how you earn continuing education credits. Specific beats generic.

What should a candidate ask the employer?

  • Which of the eight domains will this role spend most of its time in?
  • Who does security report to, and how often does it reach the board?
  • How do you measure whether security is working?

Where next?

Also free: the CISSP mind map and the CISSP 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CISSP Exam Guide and the CISSP Practice Questions go domain by domain.

Frequently asked questions

What should an employer ask a CISSP candidate?

Questions that test each exam domain in practice, for example: How would you assess the risk of a new SaaS vendor? How do you decide how long we keep data, and how we dispose of it? When would you choose symmetric over asymmetric encryption?

What should a CISSP candidate ask the employer?

Which of the eight domains will this role spend most of its time in? Who does security report to, and how often does it reach the board? How do you measure whether security is working?

How should a candidate prepare for a CISSP interview?

Name both. For the weak one, say what you did about it and how it shows in your work.

Which books go deeper on CISSP?

Cover of CISSP Exam Guide

CISSP Exam Guide

Certified Information Systems Security Professional. 14 chapters, 396 pages.

Cover of CISSP Practice Questions

CISSP Practice Questions

Practice questions with full rationales, sized to the published domain weights. 217 pages.