title: "CISSP Guided Scenarios" summary: "A set of review-gated management scenarios with explicit validation, evidence, teardown, cost, and safety requirements."

Scenario method

CISSP application uses management scenarios rather than product configuration labs. Read the role and authority first. Identify people, assets, owners, obligations, business priorities, risk, uncertainty, and the question’s time horizon.

For each scenario:

  1. State the safest and most authoritative first action.
  2. Separate policy, management decision, process, and technical implementation.
  3. Preserve life safety, legal duties, evidence, and business continuity.
  4. Compare plausible actions and reject those that are premature, unauthorized, irreversible, or too narrow.
  5. Name the accountable owner, required communication, evidence, and follow-up.

The ten scenarios cover risk treatment, BIA, classification, architecture, networks, identity, assessment, incidents, recovery, and secure development/suppliers. They remain in named technical review and are not represented as ISC2 questions or CAT simulation.

cissp-s01 · technical-review

Risk treatment and governance decision

60 min

Choose a management response to a material risk while preserving ownership, due diligence, and residual-risk acceptance.

Objectives
1.1, 1.2, 1.3, 1.4, 1.6, 1.8, 1.9, 1.12
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A business owner wants to accept a high-impact risk to meet a launch date while a regulator and key customer impose relevant obligations.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. The response distinguishes risk owner from security adviser.
  2. Mandatory obligations are not accepted away.
  3. Residual risk and decision authority are documented.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s02 · technical-review

Business impact and continuity

60 min

Derive recovery priorities, dependencies, RTO/RPO, alternate processes, exercises, and executive decisions.

Objectives
1.7, 7.13
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A revenue process depends on identity, a third party, a data feed, and one facility; current recovery priorities were set only by technical teams.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Business process impact drives priorities.
  2. External and upstream dependencies are included.
  3. Exercises validate the plan and create corrective actions.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s03 · technical-review

Classification and information lifecycle

60 min

Assign ownership and controls from collection through defensible deletion.

Objectives
2.1, 2.2, 2.3, 2.4, 2.5, 2.6
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A global analytics project wants to combine customer, employee, supplier, and public data across jurisdictions and cloud services.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Data owners and processing roles are explicit.
  2. Handling follows classification and applicable obligations.
  3. Retention, remanence, legal hold, and deletion are addressed.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s04 · technical-review

Architecture and threat-model review

60 min

Apply secure design, models, control selection, platform risk, cryptography, facilities, and lifecycle governance.

Objectives
1.10, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A critical distributed system crosses cloud, on-premises, mobile, and physical-site trust boundaries and handles regulated data.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Threats are connected to trust boundaries and assets.
  2. Controls address architecture and lifecycle, not only perimeter devices.
  3. Cryptography includes key lifecycle and implementation risk.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s05 · technical-review

Secure communication and network design

60 min

Choose segmentation, components, channels, remote access, and monitoring for a mixed-trust environment.

Objectives
4.1, 4.2, 4.3
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A merger requires rapid connectivity between differently managed networks, remote users, voice/video systems, APIs, and third parties.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Connectivity is constrained before trust is established.
  2. Channels are protected according to data and identity risk.
  3. Monitoring and failure containment are included.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s06 · technical-review

Identity governance and access lifecycle

60 min

Design proofing, authentication, federation, authorization, provisioning, review, and revocation.

Objectives
5.1, 5.2, 5.3, 5.4, 5.5, 5.6
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

Employees, contractors, partners, services, devices, and privileged administrators need access across acquired and cloud systems.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Identity types and authoritative sources are distinct.
  2. Authorization follows role/attribute/business need and least privilege.
  3. Joiner/mover/leaver and emergency access are auditable.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s07 · technical-review

Assessment and audit strategy

60 min

Select safe, independent, evidence-based testing and communicate defensible results.

Objectives
6.1, 6.2, 6.3, 6.4, 6.5
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

Leadership requests assurance before an external audit, but production testing could disrupt a safety-sensitive service.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Scope, authorization, independence, and safety are explicit.
  2. Test methods match assurance objectives.
  3. Findings are validated, risk-ranked, owned, and tracked.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s08 · technical-review

Incident command and evidence

60 min

Coordinate investigation, telemetry, containment, vulnerability/change actions, communication, recovery, and lessons learned.

Objectives
1.5, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7.9
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A privileged account shows anomalous behavior during a sensitive change window; the business wants immediate deletion of affected systems.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Authority and incident roles are established.
  2. Evidence is preserved before destructive action when safe.
  3. Containment, business communication, recovery, and root-cause remediation are addressed.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s09 · technical-review

Disaster recovery, physical security, and safety

60 min

Prioritize personnel, execute recovery, validate operations, and return safely to normal.

Objectives
7.10, 7.11, 7.12, 7.14, 7.15
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A regional event affects staff safety, primary facilities, communications, suppliers, and data-processing capacity.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Life safety precedes asset recovery.
  2. Declared authority, communications, alternate sites, data restoration, and dependencies are covered.
  3. Testing, failback, and post-event correction are explicit.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.
cissp-s10 · technical-review

Secure development and supplier review

60 min

Integrate SDLC, pipeline, testing, acquisition, coding, and supply-chain controls into a release decision.

Objectives
1.11, 8.1, 8.2, 8.3, 8.4, 8.5
Cost
No cloud resources are required; this is a paper or group scenario.
Validation
needs-review: Scenario and scoring guide require named CISSP-domain technical review.

Architecture or scenario

A product team needs to ship a critical service using acquired components, third-party code, cloud CI/CD, and a supplier with limited assurance evidence.

Prerequisites

  • Answer from the role and authority stated in the scenario.
  • Distinguish business decision, policy, process, and technical implementation responsibilities.

Procedure

  1. Identify assets, stakeholders, authority, constraints, obligations, and uncertainty.
  2. List viable responses and order them by policy, risk, reversibility, and business impact.
  3. Choose the best next action and explain why technically attractive alternatives are not first.
  4. Record required evidence, communication, approval, and follow-up.

Validate

  1. Requirements and acceptance criteria precede release.
  2. Repositories, pipelines, secrets, dependencies, artifacts, and environments are protected.
  3. Supplier gaps have contractual, compensating, monitoring, and exit controls.

Teardown or closeout

  1. Remove names and organizational identifiers from notes.
  2. Keep only the reusable decision record and objective references.