CISSP Domain 7: Security Operations
Domain 7.0: Security Operations · 13% of the exam
The largest objective count on the exam: all 15 objectives (7.1–7.15), from investigations and digital forensics through logging and monitoring, configuration and change management, incident management, detection and preventative measures, patch and vulnerability management, recovery and disaster recovery, business continuity, physical security and personnel safety.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
13% of your exam score
Domain 7.0 is worth 13% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CISSP objectives 7.1–7.15: 59 in-depth topics with worked scenarios and exam tips, in a 165-page guide you'll actually finish.
120 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cert that changes what you're paid
CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.
Serving, transitioning, or a military spouse?
CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 7.1, Investigations & forensics, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Understand and comply with investigations
Collecting volatile evidence first, keeping custody unbroken, imaging correctly, and knowing where the artifacts live.
Nadia Rashid runs Aurora's security operations. The rule she trained every analyst on first is short: you get one chance at the evidence, and the clock starts before you know whether it matters. Most of this objective is downstream of that idea.
Order of volatility
Collect what disappears fastest, first. The sequence is examinable.
| Order | Source | Lost when |
|---|---|---|
| 1 | CPU registers, cache | Immediately — effectively uncollectable in practice. |
| 2 | Memory (RAM) | Power off. Contains keys, decrypted data, injected code, network state. |
| 3 | Network state, running processes, open sockets, ARP and routing tables | Power off or process termination. |
| 4 | Temporary files, swap, unallocated space | Reboot or normal operation overwriting. |
| 5 | Disk contents | Persistent, but wear levelling and normal use degrade deleted data. |
| 6 | Remote and centralised logs | Retention expiry. |
| 7 | Archived media and backups | Retention expiry; the most durable source. |
Shutting down a running system destroys memory, network state and any volume decrypted at boot. The default first action is to preserve volatile data from the live system, then decide about power. The exception is where continued running is causing active harm, and that decision belongs to whoever owns the incident, documented.
Chain of custody
| Element | Requirement |
|---|---|
| Unique identification | Every item labelled with a unique identifier, description, serial number, and where and when it was obtained. |
| Custody record | Who held it, from when to when, and why, with signatures at every transfer. No gaps. |
| Tamper-evident storage | Sealed with recorded seal numbers, held in the evidence store from objective 3.9. |
| Integrity verification | A hash computed at acquisition and re-verified whenever the item is used. |
| Minimum handling | Every access is a custody entry and a potential challenge; touch it as little as possible. |
Evidence must be admissible (lawfully obtained and relevant), authentic (demonstrably what it claims to be), complete (including material that is unfavourable), reliable (produced by a sound process) and believable (comprehensible to the decision maker).
Acquisition
| Practice | Detail |
|---|---|
| Write blocker | Hardware or software preventing any write to the original medium during imaging. |
| Bit-for-bit image | Captures slack space, unallocated space and deleted content — a file-level copy does not. |
| Hash on acquisition | Compute the hash of source and image; matching values prove the copy is faithful and detect later alteration. |
| Work on copies | All analysis on a verified working copy; the original is sealed and untouched. |
| Live acquisition | Required where memory, an encrypted volume or an active session would be lost. Changes the system, so document exactly what was run and its effect. |
| Documentation | Contemporaneous notes: what was done, when, by whom, with what tool and version, and what was observed. |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.
From module 7.1 · Investigations & forensics
1. Which source should be collected first under the order of volatility?
From module 7.2 · Logging & monitoring
1. Why must logs be forwarded off the generating host promptly?
From module 7.3 · Configuration management
1. What is the relationship between configuration management and change management?
117 more questions like these are waiting inside.
What's inside
- 59 in-depth topics across 15 modules, mapped to objectives 7.1–7.15
- 120 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Order of volatility, chain of custody and cloud forensics
- The five DR exercise types, and what each one cannot prove
- Complete CISSP acronym & key-term reference
- 165-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 7.18 Qs
Investigations & forensics
Understand and comply with investigations
Order of volatilityChain of custodyWrite blockers & hashingLive vs. dead acquisitionArtifacts: host, network, mobile, cloudEvidence admissibility - 7.28 Qs
Logging & monitoring
Conduct logging and monitoring activities
Log lifecycle & retentionTime synchronisation & correlationSIEM tuning & alert fatigueEgress monitoringThreat intelligence & huntingUEBA - 7.38 Qs
Configuration management
Perform configuration management (CM) (e.g., provisioning, baselining, automation)
Secure provisioning & golden imagesBaselines from benchmarksDrift detectionAutomation & infrastructure as codeImmutable infrastructureCMDB accuracy - 7.48 Qs
Foundational operations concepts
Apply foundational security operations concepts
Need-to-know vs. least privilegeSegregation of duties & collusionCompensating controls in small teamsPrivileged account managementJob rotation & mandatory vacationSLAs, SLOs & operational reality - 7.58 Qs
Resource protection
Apply resource protection
Media lifecycle & inventoryMedia protection techniquesBackup media as concentrated riskData at rest controlsData in transit controlsKey separation - 7.68 Qs
Incident management
Conduct incident management
Seven phases in orderPreparation & the planDeclaration & escalation criteriaContainment vs. evidenceEradication of persistenceLessons learned - 7.78 Qs
Detection & preventative measures
Operate and maintain detection and preventative measures
Firewall & IPS operationAllow-listing vs. deny-listingSandboxing & evasionHoneypots & honeynetsManaged security servicesML/AI-based detection - 7.88 Qs
Patch & vulnerability management
Implement and support patch and vulnerability management
Vulnerability lifecycleRisk-based prioritisationAuthenticated scanning & coveragePatch testing & ringsEmergency patchingExceptions & compensating controls - 7.98 Qs
Change management
Understand and participate in change management processes
Request, assess, approve, implement, verifyStandard, normal & emergency changesChange advisory boardSecurity impact assessmentRollback planningUnauthorised change detection - 7.108 Qs
Recovery strategies
Implement recovery strategies
Full, incremental & differential3-2-1 and immutable copiesCold, warm, hot & mirrored sitesMultiple processing sitesHigh availability & clusteringRAID is not backup - 7.118 Qs
Disaster recovery processes
Implement Disaster Recovery (DR) processes
Declaration & responseNamed roles & deputiesOut-of-band communicationsDamage assessmentRestoration priority orderTraining & lessons learned - 7.128 Qs
Testing disaster recovery plans
Test Disaster Recovery Plans (DRP)
Read-through & tabletopWalkthrough & simulationParallel testFull interruptionCommunications exercisesFindings tracked to closure - 7.138 Qs
Business continuity planning
Participate in Business Continuity (BC) planning and exercises
BC vs. DR vs. crisis managementNon-technology disruptionsManual workarounds & enduranceMinimum resource requirementsPlan maintenance triggersBC exercises - 7.148 Qs
Managing physical security
Implement and manage physical security
Perimeter barriers & standoffLighting & surveillance coverageGuards & responseBadge zones & anti-passbackMantraps & visitor managementOperational review & testing - 7.158 Qs
Personnel safety & security
Address personnel safety and security concerns
Life safety precedenceTravel risk & clean devicesInsider threat awarenessSocial media exposureMFA fatigue / push bombingDuress codes & emergency management

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CISSP Collection.
Every domain of the exam, including this guide, for $129, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CISSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (7.1–7.15), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 120 practice questions, plus a 165-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 7.0 (13% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 13% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide