
Certified Information Systems Security Professional
Domain 8Objective 4
8.4 - Assess Security Impact of Acquired Software CISSP Practice Questions (Page 2)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
10%of the exam
Questions 6–10
- 6
When acquiring commercial off-the-shelf (COTS) software, which of the following is a key security consideration that should be evaluated during the procurement process?
Select an answer first - 7
A company is evaluating a commercial software product that is critical to its operations. The vendor has a strong security reputation and provides a comprehensive security whitepaper. However, the product has a known vulnerability that the vendor has not yet patched. The company's security team has determined that the vulnerability is not exploitable in the company's environment due to compensating controls. Which of the following is the BEST course of action?
Select an answer first - 8
A company is deciding between using a SaaS application and building a custom application on IaaS. The company's security team is concerned about the security of customer data. Which of the following is the MOST important factor to consider when making this decision?
Select an answer first - 9
A company is acquiring a commercial customer relationship management (CRM) system delivered as SaaS. The vendor's security documentation states that they undergo annual SOC 2 audits and provide a detailed shared responsibility matrix. The company's compliance team requires that customer data be stored only in the United States. Which of the following is the MOST important additional factor to verify before signing the contract?
Select an answer first - 10
During vendor due diligence for third-party software, which of the following is a key security factor to evaluate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.