
Certified in Cybersecurity
Domain 5Objective 3
5.3 - Understand Best Practice Security Policies CC Practice Questions (Page 5)
Part of the Security Operations domain, which accounts for 18% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
18%of the exam
Questions 21–25
- 21
A company's change management policy requires that all changes be approved by a change advisory board (CAB). A critical vulnerability is discovered in a production system, and the security team wants to apply a patch immediately. The CAB is not scheduled to meet for another week. What is the best course of action?
Select an answer first - 22
What is the primary scope of an acceptable use policy (AUP)?
Select an answer first - 23
A healthcare organization stores patient records in a cloud storage service. The compliance team requires that patient data be encrypted both at rest and in transit, and that access to the data be logged. The organization also needs to inform patients about how their data is used. Which combination of policy elements should the organization implement to meet these requirements?
Select an answer first - 24
What is the purpose of a change management policy?
Select an answer first - 25
What is a key security control in a BYOD policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.