# CISSP interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you assess the risk of a new SaaS vendor? | What data and processes it touches, the threats, likelihood and impact, a treatment choice (accept, reduce, transfer, avoid) and an owner who signs it off. Supply chain risk named. | |
| 2 | How do you decide how long we keep data, and how we dispose of it? | Classification first, then legal and business retention needs, a named owner, and secure disposal at end of life. | |
| 3 | When would you choose symmetric over asymmetric encryption? | Symmetric for speed and bulk data, asymmetric for key exchange and signatures, usually both together, and key management as the hard part. | |
| 4 | How would you segment our network? | Zones by trust and data sensitivity, only the flows that are needed, monitoring at the boundaries, and how remote and cloud access fit. | |
| 5 | Walk me through joiners, movers and leavers. | Approved provisioning, role-based access, regular access reviews, and access removed on the day someone leaves. | |
| 6 | How do you know a control actually works? | A test plan, evidence, the difference between a vulnerability scan and a penetration test, and a report the control owner acts on. | |
| 7 | Talk me through the first hour of a ransomware incident. | Contain, preserve evidence, follow the incident plan, escalate, communicate, and leave any payment decision to the business and legal. | |
| 8 | How do you get security into a development team's sprint? | Threat modeling early, secure coding standards, automated testing in the pipeline, and a person in the team who owns it. | |

Source: https://credentialpress.com/guides/cissp-interview-questions
