Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 6Objective 4

6.4 - Analyze Test Output and Generate Report CISSP Practice Questions (Page 3)

Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)

19questions here
4free pages
3concepts
12%of the exam

Questions 11–15

  1. 11foundation · easy

    What is the primary principle of responsible disclosure of a vulnerability?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of a formal exception process in security assessment and testing?

    Select an answer first
  3. 13expert · hard

    A security team discovered a critical vulnerability in a system that is owned by a third-party vendor. The vendor has a contractual obligation to patch the system, but has not done so after 30 days. The system is internet-facing and contains sensitive customer data. What is the MOST appropriate action?

    Select an answer first
  4. 14application · medium

    A security team discovered a vulnerability in a system that is owned by a different department. The department has not responded to multiple requests to remediate the issue. What is the MOST appropriate action for the security team?

    Select an answer first
  5. 15foundation · easy

    During a vulnerability assessment, a security analyst identifies several findings. Which action best describes the purpose of remediation prioritization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.