Answering technique · Understand
How to eliminate the wrong answers on CISSP questions
Two options out of four can be eliminated on the first reading because they use an invented term, an absolute, or answer a different phase from the one being asked about. The two that remain are separated by the explicit criteria in the stem, not by the most-encompassing-answer rule — that rule is itself a documented trap.
Two options out of four can often be ruled out on the first reading: an absolute, an invented term, or an answer belonging to a different phase from the one being asked about. The typology below is reconstructed from 138 practice questions shared by candidates between 2023 and 2026 and from the justifications given for ruling out each option — candidate opinions, never official ISC2 corrections, and no question stem is reproduced here.
How do you eliminate two answers in a single reading?
By looking for formal defects before judging substance. Three signals are often enough to rule out half the options, and none of them requires deep domain knowledge.
The first is the absolute. An option containing all, always or never is almost always wrong — the candidate reports make this a first-pass elimination rule. The reason is conceptual: security manages risk, it does not eliminate it. Any option promising a total guarantee, exhaustive coverage or a ban without exception clashes with that principle, and most universal claims about real systems can be refuted with a counter-example. A question asking for the minimum requirements to protect a communication channel therefore mechanically eliminates the option proposing to encrypt everything indiscriminately.
Two precautions come with this rule. It serves to rule out quickly, never to designate the right answer: an eliminated absolute option says nothing about the other three. And it has legitimate exceptions, which the candidate reports flag themselves — some obligations, particularly ethical and legal ones, really are without nuance, and an option stating them in absolute terms is then accurate.
The second is the term that does not exist. The candidate reports document an option built on an expression very close to a fundamental principle but nowhere to be found in the CBK: it sounds right and is attached to nothing.
The third is the wrong phase. An option describing notification when the question is about containment, or response when the question is about detection, is correct in itself and wrong here. This is in fact the only use of the famous managerial mantra that the candidate reports still endorse:
"I coach my study group that 'think like a manager' is a way to eliminate 2 out of the 4 answer choices."
A fourth signal is self-cancelling: applying a vendor patch to a vulnerability the vendor does not know about, or detecting by signature an attack that has none.
Which distractors are the most frequent?
The candidate reports reveal about ten recurring families. They are easy to recognise once named.
| Family | How it presents | How to rule it out |
|---|---|---|
| The invented term | An expression close to a known principle, absent from the CBK | Check that the exact term appears in a source |
| The absolute | all, always, never | Test against "minimum", "proportionate", "without missing deadlines" |
| The off-topic best practice | A true statement that does not address the stated risk | Restate the risk and check that it responds to it |
| The wrong phase | Detection when response is asked for, reporting when containment is asked for | Name the phase before reading the options |
| Outside the role's remit | An action that does not belong to the persona in the stem | Check the persona's actual authority |
| The violated criterion | Technically superior, but contrary to a written constraint | Reread every explicit criterion |
| The category reflex | "Policy first", "human life first", "escalate" | Check that the question asks for that level of decision |
| The impossible option | Fixing the unfixable, detecting the undetectable | Test feasibility within the written scenario |
| The category duplicate | Two controls of the same type presented as complementary | Count the genuinely distinct categories |
| The hollow umbrella | The general goal instead of the mechanism asked for | Distinguish objective from means |
One family deserves a further word, the most elegant of them: outside the role's remit. A question places the respondent as a security professional facing a request for access to a document classified above the requester's level. Two options are technically feasible — reclassify the document, raise the access level — and both are wrong, because neither belongs to that role. The distractor is not testing access control, it is testing responsibilities.
How do you spot an option that answers a different question?
By restating the request in one short sentence, then testing each option against that sentence alone. Options that miss the point are often the most appealing, because they are true.
A clear example from the candidate reports, about sending sensitive data to an external partner: the risk written into the stem is interception during transfer. One option proposes strengthening classification and labelling — an excellent practice, with no effect on interception, and already achieved since the stem describes the data as sensitive. Another proposes protecting storage: a good answer to a different question. Only one addresses data in transit.
The same trap applies to the verb. A question asking how to avoid an exposure does not call for the same options as one asking how to reduce it: monitoring and training reduce, only data minimisation avoids.
The quick test is to reread the last sentence of the stem with the option inserted into it: if the resulting sentence is true but no longer speaks to the problem posed, the option is a distractor.
What should you do when two answers both remain defensible?
This is the normal situation, not the exception. It is also where time is won or lost, since these judgement calls consume most of the available minutes — see time management on the exam.
First check that no explicit criterion is violated. This is the most reliable tie-breaker and the most often ignored: lowest cost, minimum requirement, keeping to deadlines, no recurring costs. An option that is superior on substance but contrary to a written criterion is wrong.
Then apply two projection tests. The first is inversion: state the option in the negative and ask yourself whether you would still choose it. On a question about selecting a hosting site, inverting the "acceptable level of risk" option is enough to show that this criterion governs all the others. The second is exclusivity:
"Assume the other good answers will never be done — what if this is the only action taken?"
Only then, and only as a last resort, fall back on the tie-breakers inherited from management reasoning — priority hierarchy, the people, process, technology order — for which our article on the manager mindset gives the full formulation and the observed frequencies. These rules are not truths, they are arbiters: they only come into play when the two remaining options equally satisfy every criterion in the stem, which is rare.
Is the most encompassing answer always the right one?
No, and this is the most important point in this article. The rule circulates in the candidate reports in an appealing form:
"If answer A looks right but answer A is a step in Answer C, choose answer C."
It genuinely works in one specific configuration: when the broad option contains the narrow one without adding anything false. The candidate reports give an example about service accounts, where the option "remove unnecessary rights" encompasses the option "disable interactive logon," the latter being just one right among others.
But the same rule produces errors in at least three configurations, and they are documented.
It fails when a single word in the broad option makes it wrong. On a question explaining why an organisation waits before deploying patches, the most encompassing option invokes reducing business impact — an objective that contains all the others. But it mentions the impact of the installation, and waiting changes nothing about that impact: the maintenance window is the same. What you gain by waiting is that the patch's defects are discovered elsewhere.
It fails when the question asks for a mechanism rather than an objective: on a question about reducing the risk from downloaded software, the most general option is judged correct but insufficiently specific compared with the one describing the expected assessment mechanism.
It fails, finally, when the encompassing option describes something other than what it appears to describe. On a question defining security governance, which came up three times in the candidate reports, the option about alignment with business objectives seems the broadest — and it is precisely the one the answer keys reject, because it describes a documented framework.
How do you test an option before committing to it?
With a short checklist, applied only to the option you are about to pick. Five checks are enough, and each takes a few seconds: is every word of the option accurate, given that a single wrong term is enough to invalidate it? Does the option assume something absent from the stem — budget, service level, implicit architecture? Does it fall within the persona's authority? Does it respect every explicit criterion, including the second one, the one people forget? Does it address the stated problem, and not an adjacent one?
This is the revision exercise the candidate reports recommend, and the one Cybridia has systematised: for each of its 4,298 questions, the explanation states why each wrong answer is wrong. Being able to state the three reasons for ruling options out is the only progress indicator the candidate reports endorse — far more than a percentage, whose limited predictive power is recalled in our benchmark on practice exam scores. The criterion for choosing study material follows directly from this: a bank that does not explain its answer keys is useless, and that is the yardstick applied in our comparison of CISSP resources.
Why can two twin question stems have opposite answers?
Because the discriminating criterion has changed, often by a single word. Candidates who discover these pairs first conclude that the question banks are inconsistent; that is rarely the case.
The clearest pair concerns bandwidth consumption. In the first scenario, saturation occurs outside business hours, at a services company, and the respondent is the security manager: the expected answer is an acceptable use policy combined with monitoring, because nothing yet proves which traffic is responsible and widening the pipe would reward the waste. In the second scenario, saturation occurs at peak hours in an establishment where a system outage affects people's safety: the expected answer is a capacity increase. Two different discriminating criteria — the timing and the stakes.
A second pair, taken from the same chapter of the same book, contrasts two physical access control questions. In one, a PIN added to the badge is judged insufficient to guarantee the holder's identity, because the question explicitly asks for the best guarantee of identity. In the other, the same combination is chosen, because the question adds a no-recurring-costs constraint that eliminates any solution relying on staff. Both answer keys are consistent: only the criteria differ.
The lesson serves as a conclusion. The candidate reports make the point with a completely different example — a mobile fleet management question where the managerial reflex pointed to a device administration solution that, in itself, encrypts nothing:
"Why are you 'thinking like a manager'? Just. Answer. The. Question."
Hence the final instruction: treat each question in its own vacuum, without looking for consistency with the previous one. For the reading of the stem that precedes this elimination, see the answering method; and when it is the answer keys themselves that diverge, see arbitrating between question banks.
Frequently asked questions
How do you quickly eliminate two answers on the CISSP?
By looking for three signals on the first reading: an absolute (all, always, never), a term that does not exist in the CBK, or an option belonging to a different phase from the one being asked about. The candidate reports describe this elimination as the real use of “think like a manager”: “a way to eliminate 2 out of the 4 answer choices.”
Is the most encompassing answer always the right one?
No, and it is a documented trap. It wins when the broad option genuinely contains the narrow one, but it fails as soon as the question asks for a specific mechanism, or when a single word in the broad option makes it wrong.
What should you do when two answers both remain defensible?
Reread the last sentence of the stem substituting each option into it, check that no explicit criterion is violated, then apply the two projection tests: inverting the option and assuming exclusivity. Tie-breakers inherited from management reasoning come only as a last resort.
Why do two almost identical questions have opposite answers?
Because a word of context changes the discriminating criterion: a sector where an outage puts lives at risk, a recurring cost constraint, a time of day. The candidate reports recommend treating each question in its own vacuum.
Should you be wary of the longest or most detailed options?
Not in themselves. But a detailed option multiplies the opportunities to be wrong: a single inaccurate or out-of-phase term is enough to rule it out, and that is a quick test to apply.
Where does this information come from?
This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.
- How to answer a CISSP question, step by stepRead the last sentence, identify the decision, follow the persona, respect the explicit criteria and assume nothing: the method for answering CISSP questions.
- When two CISSP answer keys contradict each other, who is right?Two CISSP question banks sometimes give opposite answers to the same stem. Why, how to decide, and when it is better to move on.