
Certified Information Systems Security Professional
Domain 8Objective 4
8.4 - Assess Security Impact of Acquired Software CISSP Practice Questions (Page 1)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
10%of the exam
Questions 1–5
- 1
Which of the following is a security risk specifically associated with the licensing of commercial off-the-shelf (COTS) software?
Select an answer first - 2
When using a managed service provider, what is a key security consideration regarding data handling?
Select an answer first - 3
When assessing the security impact of using an open source component, which of the following is a primary security consideration?
Select an answer first - 4
In the shared responsibility model, which cloud service model places the most security responsibility on the customer?
Select an answer first - 5
A development team wants to integrate an open source library into a critical internal application. The library is widely used and has an active community, but the team has not yet reviewed its license. The security team is concerned about potential vulnerabilities. Which of the following actions should the team take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.