
Certified Information Systems Security Professional
Domain 1Objective 11
1.11 - Apply Supply Chain Risk Management (SCRM) Concepts CISSP Practice Questions (Page 4)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
16%of the exam
Questions 16–20
- 16
A large enterprise is evaluating a new software vendor. The vendor has passed a third-party assessment, but the enterprise wants to ensure that the vendor's security posture remains acceptable over the life of the contract. What should the enterprise include in the contract?
Select an answer first - 17
A software company is acquiring a code library from a third-party developer. The library is widely used and has a known vulnerability that has not been patched. The company's legal team is concerned about liability, and the security team is concerned about the risk of exploitation. What is the most appropriate action?
Select an answer first - 18
A government agency is procuring hardware for a secure communications system. The agency is concerned about the risk of malicious implants or tampering during the manufacturing process. Which technology provides hardware-level assurance against such tampering?
Select an answer first - 19
Which of the following is an example of a minimum security requirement for a supplier?
Select an answer first - 20
A software development company uses many open-source libraries in its products. The security team wants to quickly identify which libraries are affected when a new vulnerability is disclosed. What should the team implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.