Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 11

1.11 - Apply Supply Chain Risk Management (SCRM) Concepts CISSP Practice Questions (Page 6)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
7concepts
16%of the exam

Questions 26–29

  1. 26expert · hard

    A security architect is designing a system that requires both hardware-level assurance of the boot process and protection against counterfeit components. The architect has a limited budget and must choose between a silicon root of trust and physically unclonable functions (PUFs). Which choice best meets both requirements?

    Select an answer first
  2. 27foundation · easy

    What is the primary role of service level requirements (SLRs) in supply chain risk management?

    Select an answer first
  3. 28expert · hard

    A hardware vendor wants to ensure that its products are not counterfeited. The vendor is considering using PUFs, but is concerned about the cost of implementing them. The vendor also wants to ensure that its suppliers meet minimum security requirements. What is the most cost-effective approach?

    Select an answer first
  4. 29expert · hard

    A government agency is procuring network equipment from a foreign supplier. The agency is concerned about the risk of malicious implants and espionage. The supplier has agreed to a third-party assessment, but the agency wants additional assurance. What should the agency do?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISSP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.