Answering technique · Understand
When two CISSP answer keys contradict each other, who is right?
Conflicting answer keys come from editions, doctrinal sources and genuine errors, not from an unstable CBK: out of 138 questions debated by candidates, 13 leave the community persistently split. The useful approach is to distinguish genuinely disputed concepts, which must be learned through both of their definitions, from badly written questions that should be abandoned.
When two answer keys contradict each other, the cause is almost always one of these three: different editions, different doctrinal sources, or a genuine error — the CBK itself is stable. Disagreement is part of the landscape: out of the 138 practice questions shared by candidates between 2023 and 2026 and reviewed for this article, 13 leave the community persistently split, and a handful of debates remain genuinely open. No question stem is reproduced here, and the positions quoted are candidate opinions, never official ISC2 corrections.
Why do two official answer keys give different answers?
Because "official" covers several things: the same publisher issues a study guide, test collections, a mobile app and review questions, written by different authors, at different dates, from different doctrinal sources.
The candidate reports give a textbook case on a business continuity question: which of these actions belongs to a continuity plan? A test collection assigns the answer to a fault tolerance measure, on the grounds that continuity is proactive and recovery reactive; the official ISC2 app assigns the answer to failing over to an alternate site, on the grounds that a permanent preventive measure does not belong in a plan you activate. Both lines of reasoning are defensible: they start from two definitions of the boundary between continuity and recovery.
Three other causes recur. Edition drift first: a question about the messages exchanged when a network address is assigned is judged badly written by the community, which sees its answer key as an editing slip carried over from one edition to the next — while acknowledging that the book's answer would remain defensible under a different reading of the stem.
Doctrinal shift next. A question about the systematic replacement of a fleet of equipment that still works and still receives updates gets an answer key invoking end of support; commenters reply that hardware still receiving patches is not at end of support but in planned obsolescence. The thread's conclusion: even well-regarded resources get things wrong.
Framework divergence, finally. A question asking on what basis to justify purchasing a control pits an annualised risk metric against a profitability metric: one camp reasons in terms of risk management, the other in terms of investment decisions. Both frameworks are taught, and the question does not say which one it is invoking.
Due care or due diligence: does the question have a stable answer?
No. This is the most instructive case in the candidate reports: the same stem comes up five times in three years, almost word for word, and the published answer keys are split between the two concepts. The principle being tested is always the same: what do you call a person's obligation to carry out their responsibilities accurately and on time?
Three sources assign the answer to due diligence, only one to due care, and each time part of the community disputes the answer key. The mnemonics in circulation are themselves contradictory:
"Due Diligence = Do Detect; Due Care = Do Correct"
is the most widespread, and it points to due care for an execution action. But the explanation that carries the day in the best-argued threads reverses the perspective: due care would be the broad reasonable person standard, and due diligence its specific component, the one consisting of discharging an assigned responsibility accurately and punctually — wording taken almost literally from the stem.
The right approach is therefore not to memorise one answer, but to know the axis of the disagreement: a general standard of prudence on one side, the verifiable execution of an assigned responsibility on the other. Both camps agree on one point: when a question repeats a textbook definition word for word, it is that textbook that is right, not common professional usage.
What should you do when the community disputes an official answer key?
Distinguish two very different situations: the answer key is wrong, or the answer key is right for a reason the reader refuses to accept.
The candidate reports contain a case of widespread dispute, on a software supply chain question. A person carrying out a documentation review finds serious shortcomings at a supplier, and the answer key expects them to revoke the component's authorisation to operate. The highest-rated commenters find it absurd that an assessor would unilaterally revoke a critical authorisation without an impact analysis; most of them would have produced a report. The question was asked again seven months later, with the same verdict: the disagreement concerns the separation between the assessor role and the decision-maker role, and it is never settled.
Conversely, several answer keys first judged wrong turn out to be sound once the explanation is read. One candidate disputes an answer on disaster recovery readiness testing, until he is reminded that a scripted exercise in a non-production environment does not disrupt production. Another disputes an answer on administrative privileges, rightly pointing out that it describes bad practice — but the question set a specific constraint, and the answer meets it.
The test that settles the matter comes down to two checks. Does the official explanation rely on a definition attributable to a reference source? If so, adopt it for the exam, even if you would not apply it at the office. Does it ignore an explicit criterion in the stem, or contradict itself from one question to the next in the same chapter? Then note it as a probable error and move on.
Two contributors presenting themselves as ISC2 question writers take the opportunity to restate what is actually being tested:
"As an exam writer for the CISSP, I can absolutely say that is NOT what we are looking for. Understanding the concepts and how to apply them, is."
How do you recognise an AI-generated question or a brain dump?
The candidate reports contain seven questions whose artificial origin is either announced by the poster or identified by commenters. Their signatures are consistent enough to be listed.
| Signal | What it indicates |
|---|---|
| A ten-line scenario listing a complete security stack | Generated scenery, unrelated to the request |
| A two-part question: the risk and the control to recommend | A format absent from the real exam |
| Options pairing a risk with a mismatched remedy | Automatic generation, never reviewed |
| Internal inconsistency in the stem | No expert review |
| No role indicated although the answer depends on it | Unanswerable question |
| Pure definition question, introductory level | Calibration far below the exam |
| No source cited, provenance questioned | Suspected brain dump |
The commenters' verdict is swift: one of these questions is called "AI slop," another is declared unanswerable for lack of an indicated role, a third recommends a hardware security module against side-channel attacks — a remedy that does not address the risk described.
The brain dump case is more serious, because it involves ethics as much as effectiveness. The candidate reports document at least one question that moderators flagged as most likely coming from a pirated bank, which ended the discussion. A bank distributing real exam questions violates the non-disclosure agreement, and its answer keys have no educational value.
That leaves an intermediate category: serious but unvalidated community banks, which commenters describe as "very hard and not fully validated." They are recognisable by answer keys that nobody can justify except by rewriting the question. Telling these sources apart is the subject of our comparison of CISSP resources, which applies the same criterion: a bank is worth what its explanations are worth.
Which questions cause the most disagreement?
The breakdown by domain is instructive: domain 1, security and risk management, accounts for 38 of the 138 questions, well ahead of security operations (24), identity management (21) and architecture (18). It is also the domain where the disagreements cluster, for a simple reason: its concepts are definitional and their boundaries are conventional.
Five areas account for most of the disputes. The due care / due diligence distinction, already described. The boundary between business continuity and disaster recovery. The accountability chain, where the right answer depends on the options offered: when the board of directors is not listed, you take the highest available level. The definition of security governance. And the vocabulary of hardware life cycles, end of sale versus end of support.
Conversely, some tricky concepts are perfectly stable: threat, vulnerability and risk; scoping and tailoring of a control baseline; incident response phases; need to know. When you get one of those wrong, the problem is a gap in knowledge, not a questionable answer key.
One last marker: several questions in the candidate reports are judged too detailed, with the recurring reminder that "CISSP is NOT a technical exam." A disputed answer key on a hyper-technical question is rarely a reason to open a textbook.
Should you study a disputed concept or move on?
The rule that emerges from the candidate reports depends on frequency, not difficulty.
If the concept comes up several times in your question banks — as is the case for the five areas above — it deserves revision, but not the kind you expect: it is not about retaining one answer, but about learning the two competing definitions and the criterion that tips the balance one way or the other.
If the question is isolated, badly written, automatically generated or of unknown origin, the answer is clear: move on. The real cost of these questions is not the lost point, it is the time and confidence they consume — two resources that the volume of questions to work through before the exam already puts under strain. Persisting with a questionable answer key is, in fact, listed among the most frequent revision mistakes. And treat each question in its own vacuum, without trying to reconcile sources.
That leaves the one move that makes any question bank useful: requiring it to explain. An answer key that merely names the right option does not even let you detect that it is wrong. That is the principle adopted by Cybridia, where each of its 4,298 questions comes with an explanation stating why the wrong answers are wrong — the only revision move this body of candidate reports recommends without reservation.
For reading the stem, see the answering method; for ruling out options, eliminating distractors. The limits of this body of candidate reports are detailed in our methodology.
Frequently asked questions
Why do two CISSP question banks give different answers?
Because they rely on different doctrinal sources, on different editions of the same book, and sometimes because an answer key contains an error. The candidate reports document a case where an official book and an official app give two opposite answers to the same stem.
Due care or due diligence: which is the right answer?
The same stem comes up five times in the candidate reports and the answer keys are split between the two. You need to know the axis of the disagreement — the general reasonable person standard on one side, the verifiable execution of an assigned responsibility on the other — rather than a single answer.
What should you do when the community disputes an official answer key?
Check whether the official explanation relies on a sourced definition. If it does, adopt it for the exam even if it clashes with field experience. If it ignores an explicit criterion in the stem or contradicts itself, note it as a probable error and move on.
How do you recognise an AI-generated question?
A very long scenario listing a complete security stack, a two-part question asking for both the risk and the remedy, options pairing a risk with a mismatched remedy, internal inconsistencies, no role indicated and no source given.
Should you study a disputed concept or move on?
It depends on frequency: concepts that come up several times in the candidate reports are worth learning with both of their readings; an isolated, badly written question deserves no extra time.
Where does this information come from?
This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.
- How to answer a CISSP question, step by stepRead the last sentence, identify the decision, follow the persona, respect the explicit criteria and assume nothing: the method for answering CISSP questions.
- How to eliminate the wrong answers on CISSP questionsA typology of CISSP distractors, a method for ruling out two options on the first reading and for choosing between the two that remain without walking into a.