Skip to content
ISC2 CISSP · CISSP

CISSP Domain 7: Security Operations

Domain 7.0: Security Operations · 13% of the exam

The largest objective count on the exam: all 15 objectives (7.1–7.15), from investigations and digital forensics through logging and monitoring, configuration and change management, incident management, detection and preventative measures, patch and vulnerability management, recovery and disaster recovery, business continuity, physical security and personnel safety.

15 modules · 59 topics 165-page PDF 120 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$129one-time · all 8 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

13% of your exam score

Domain 7.0 is worth 13% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CISSP objectives 7.1–7.15: 59 in-depth topics with worked scenarios and exam tips, in a 165-page guide you'll actually finish.

120 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cert that changes what you're paid

CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.

Serving, transitioning, or a military spouse?

CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 7.1, Investigations & forensics, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 7.1

Understand and comply with investigations

Collecting volatile evidence first, keeping custody unbroken, imaging correctly, and knowing where the artifacts live.

Nadia Rashid runs Aurora's security operations. The rule she trained every analyst on first is short: you get one chance at the evidence, and the clock starts before you know whether it matters. Most of this objective is downstream of that idea.

Order of volatility

Collect what disappears fastest, first. The sequence is examinable.

OrderSourceLost when
1CPU registers, cacheImmediately — effectively uncollectable in practice.
2Memory (RAM)Power off. Contains keys, decrypted data, injected code, network state.
3Network state, running processes, open sockets, ARP and routing tablesPower off or process termination.
4Temporary files, swap, unallocated spaceReboot or normal operation overwriting.
5Disk contentsPersistent, but wear levelling and normal use degrade deleted data.
6Remote and centralised logsRetention expiry.
7Archived media and backupsRetention expiry; the most durable source.
Exam focus · Do not pull the plug first

Shutting down a running system destroys memory, network state and any volume decrypted at boot. The default first action is to preserve volatile data from the live system, then decide about power. The exception is where continued running is causing active harm, and that decision belongs to whoever owns the incident, documented.

Chain of custody

ElementRequirement
Unique identificationEvery item labelled with a unique identifier, description, serial number, and where and when it was obtained.
Custody recordWho held it, from when to when, and why, with signatures at every transfer. No gaps.
Tamper-evident storageSealed with recorded seal numbers, held in the evidence store from objective 3.9.
Integrity verificationA hash computed at acquisition and re-verified whenever the item is used.
Minimum handlingEvery access is a custody entry and a potential challenge; touch it as little as possible.

Evidence must be admissible (lawfully obtained and relevant), authentic (demonstrably what it claims to be), complete (including material that is unfavourable), reliable (produced by a sound process) and believable (comprehensible to the decision maker).

Acquisition

PracticeDetail
Write blockerHardware or software preventing any write to the original medium during imaging.
Bit-for-bit imageCaptures slack space, unallocated space and deleted content — a file-level copy does not.
Hash on acquisitionCompute the hash of source and image; matching values prove the copy is faithful and detect later alteration.
Work on copiesAll analysis on a verified working copy; the original is sealed and untouched.
Live acquisitionRequired where memory, an encrypted volume or an active session would be lost. Changes the system, so document exactly what was run and its effect.
DocumentationContemporaneous notes: what was done, when, by whom, with what tool and version, and what was observed.
The guide continues for 165 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.

From module 7.1 · Investigations & forensics

  1. 1. Which source should be collected first under the order of volatility?

From module 7.2 · Logging & monitoring

  1. 1. Why must logs be forwarded off the generating host promptly?

From module 7.3 · Configuration management

  1. 1. What is the relationship between configuration management and change management?

117 more questions like these are waiting inside.

What's inside

  • 59 in-depth topics across 15 modules, mapped to objectives 7.1–7.15
  • 120 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • Order of volatility, chain of custody and cloud forensics
  • The five DR exercise types, and what each one cannot prove
  • Complete CISSP acronym & key-term reference
  • 165-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 7.1

    Investigations & forensics

    Understand and comply with investigations

    8 Qs
    Order of volatilityChain of custodyWrite blockers & hashingLive vs. dead acquisitionArtifacts: host, network, mobile, cloudEvidence admissibility
  2. 7.2

    Logging & monitoring

    Conduct logging and monitoring activities

    8 Qs
    Log lifecycle & retentionTime synchronisation & correlationSIEM tuning & alert fatigueEgress monitoringThreat intelligence & huntingUEBA
  3. 7.3

    Configuration management

    Perform configuration management (CM) (e.g., provisioning, baselining, automation)

    8 Qs
    Secure provisioning & golden imagesBaselines from benchmarksDrift detectionAutomation & infrastructure as codeImmutable infrastructureCMDB accuracy
  4. 7.4

    Foundational operations concepts

    Apply foundational security operations concepts

    8 Qs
    Need-to-know vs. least privilegeSegregation of duties & collusionCompensating controls in small teamsPrivileged account managementJob rotation & mandatory vacationSLAs, SLOs & operational reality
  5. 7.5

    Resource protection

    Apply resource protection

    8 Qs
    Media lifecycle & inventoryMedia protection techniquesBackup media as concentrated riskData at rest controlsData in transit controlsKey separation
  6. 7.6

    Incident management

    Conduct incident management

    8 Qs
    Seven phases in orderPreparation & the planDeclaration & escalation criteriaContainment vs. evidenceEradication of persistenceLessons learned
  7. 7.7

    Detection & preventative measures

    Operate and maintain detection and preventative measures

    8 Qs
    Firewall & IPS operationAllow-listing vs. deny-listingSandboxing & evasionHoneypots & honeynetsManaged security servicesML/AI-based detection
  8. 7.8

    Patch & vulnerability management

    Implement and support patch and vulnerability management

    8 Qs
    Vulnerability lifecycleRisk-based prioritisationAuthenticated scanning & coveragePatch testing & ringsEmergency patchingExceptions & compensating controls
  9. 7.9

    Change management

    Understand and participate in change management processes

    8 Qs
    Request, assess, approve, implement, verifyStandard, normal & emergency changesChange advisory boardSecurity impact assessmentRollback planningUnauthorised change detection
  10. 7.10

    Recovery strategies

    Implement recovery strategies

    8 Qs
    Full, incremental & differential3-2-1 and immutable copiesCold, warm, hot & mirrored sitesMultiple processing sitesHigh availability & clusteringRAID is not backup
  11. 7.11

    Disaster recovery processes

    Implement Disaster Recovery (DR) processes

    8 Qs
    Declaration & responseNamed roles & deputiesOut-of-band communicationsDamage assessmentRestoration priority orderTraining & lessons learned
  12. 7.12

    Testing disaster recovery plans

    Test Disaster Recovery Plans (DRP)

    8 Qs
    Read-through & tabletopWalkthrough & simulationParallel testFull interruptionCommunications exercisesFindings tracked to closure
  13. 7.13

    Business continuity planning

    Participate in Business Continuity (BC) planning and exercises

    8 Qs
    BC vs. DR vs. crisis managementNon-technology disruptionsManual workarounds & enduranceMinimum resource requirementsPlan maintenance triggersBC exercises
  14. 7.14

    Managing physical security

    Implement and manage physical security

    8 Qs
    Perimeter barriers & standoffLighting & surveillance coverageGuards & responseBadge zones & anti-passbackMantraps & visitor managementOperational review & testing
  15. 7.15

    Personnel safety & security

    Address personnel safety and security concerns

    8 Qs
    Life safety precedenceTravel risk & clean devicesInsider threat awarenessSocial media exposureMFA fatigue / push bombingDuress codes & emergency management
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 8 CISSP domains

Sitting the whole exam? Get the Complete CISSP Collection.

Every domain of the exam, including this guide, for $129, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CISSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (7.1–7.15), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 120 practice questions, plus a 165-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 7.0 (13% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 13% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide