
Certified Information Systems Security Professional
Domain 3Objective 5
3.5 - Assess and Mitigate the Vulnerabilities of Security Architectures, Designs, and Solution Elements CISSP Practice Questions (Page 4)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
15concepts
13%of the exam
Questions 16–20
- 16
Which of the following is a common vulnerability in embedded systems?
Select an answer first - 17
Which of the following is a common vulnerability in serverless computing?
Select an answer first - 18
A company uses a serverless architecture with AWS Lambda. The security team is concerned about the risk of event injection, where an attacker crafts a malicious event to trigger unintended behavior. Which of the following is the most effective mitigation?
Select an answer first - 19
Which of the following is a common vulnerability in cryptographic systems?
Select an answer first - 20
A company uses AWS Lambda functions to process user-uploaded files. A security review finds that the Lambda function has overly broad IAM permissions, allowing it to delete objects in an S3 bucket. Which of the following is the most effective mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.