← All Study Guides

D7: Security Operations

CISSP (ISC2) study guide

CISSP D7: Security Operations

Domain 7 carries 13% of the exam weight and covers incident response, investigations and digital forensics, disaster recovery, business continuity, physical security, and day-to-day logging and monitoring. In our experience much of it is about sequencing and judgment, so practice reasoning through "what should you do first, and what next" in realistic scenarios rather than memorizing definitions alone.

Key Concepts
  • Incident response lifecycle

    NIST SP 800-61 Rev. 3 (April 2025) superseded Rev. 2, whose lifecycle was Preparation, then Detection & Analysis, then Containment, Eradication & Recovery, then Post-Incident Activity, with lessons learned feeding back into preparation. Rev. 3 maps those phases to the CSF 2.0 Functions and says lessons learned should often be shared as soon as they are identified. Sequencing still matters: containment stops an incident from expanding, and eradication follows it.

  • RTO vs. RPO

    Recovery Time Objective is the maximum time a system resource can stay unavailable before the impact becomes unacceptable. Recovery Point Objective is the point in time to which data can be recovered, which reflects how much data loss the business can tolerate. Because data can only be recovered to the most recent backup, RPO drives backup frequency, and RTO drives which recovery technologies and sites can meet it.

  • Backup types

    Full (all selected files), differential (everything changed since the last full backup; it grows each day but restores from just the full plus the latest differential), and incremental (everything changed since the last backup of any type; smaller and faster to create, but a restore needs the full plus every incremental since then).

  • Disaster recovery site types

    Hot site (fully configured with hardware, infrastructure, and personnel; fastest recovery), warm site (partially equipped, in the middle on cost and readiness), and cold site (space and infrastructure only; least expensive but slowest to bring up). A mirrored site, fully redundant with real-time mirroring, is the most expensive option. The choice depends on the organization's RTO.

  • Order of volatility

    In digital forensics, collect evidence from most to least volatile. RFC 3227's example order: registers and cache; then routing table, ARP cache, process table, kernel statistics, and memory; then temporary file systems; then disk; then remote logging and monitoring data; then physical configuration and network topology; then archival media.

Confusable Pairs
  • Differential vs. incremental backup

    Differential backs up everything changed since the last full backup (restore needs only the full plus the latest differential). Incremental backs up everything changed since the last backup of any kind (restore needs the full plus every incremental in sequence). Differential is faster to restore, incremental is faster to create.

  • Business continuity plan (BCP) vs. disaster recovery plan (DRP)

    The BCP is the broader plan for sustaining mission and business processes (such as payroll or customer service) during and after a disruption. The DRP is narrower and information system focused: it restores a system, application, or computing facility at an alternate site after a major, usually physical disruption.

Sources
  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]
  6. [6]
  7. [7]
  8. [8]
  9. [9]
  10. [10]
  11. [11]
  12. [12]
  13. [13]
  14. [14]
  15. [15]
  16. [16]

Practice D7 questions with instant feedback, free to start, no card required.

Start Free
Your cookie choices
We use essential cookies to run this site, and, only with your consent, advertising cookies from Google, LinkedIn, and Reddit to measure ad performance. See our for details.