
Certified Information Systems Security Professional
Domain 7Objective 4
7.4 - Apply Foundational Security Operations Concepts CISSP Practice Questions (Page 1)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
13%of the exam
Questions 1–5
- 1
A security administrator is reviewing the use of a privileged account that is shared among five IT staff members. The administrator wants to improve accountability and reduce the risk of misuse. Which action should be taken?
Select an answer first - 2
A company's IT team manages a legacy application that requires a single shared administrator account because the application does not support individual accounts. The security team wants to improve accountability and reduce the risk of misuse. The company also has an SLA with internal business units that requires 99.9% availability for the application. Which approach best addresses the security concern without violating the SLA?
Select an answer first - 3
Which principle states that users should be granted only the minimum access necessary to perform their job duties?
Select an answer first - 4
In a security operations context, what does the 'need-to-know' principle specifically restrict?
Select an answer first - 5
A database administrator (DBA) has full access to the production database, including the ability to modify data. The security team wants to reduce the risk of unauthorized changes while still allowing the DBA to perform necessary maintenance. Which approach best balances access and control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.