Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 8Objective 4

8.4 - Assess Security Impact of Acquired Software CISSP Practice Questions (Page 5)

Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
5concepts
10%of the exam

Questions 21–23

  1. 21application · medium

    A company is acquiring a commercial software product that will be integrated with its existing systems. The vendor has provided a security whitepaper, but the company's security team wants to verify the vendor's security posture. Which of the following is the MOST effective way to verify the vendor's security posture?

    Select an answer first
  2. 22application · medium

    A company is evaluating a commercial software product for use in a regulated industry. The vendor has a strong reputation and provides a detailed security whitepaper. However, the company's security team has identified that the product has not been updated in over a year. Which of the following is the MOST significant security risk associated with this acquisition?

    Select an answer first
  3. 23application · medium

    A developer wants to use an open source library that has a large user base but a small maintainer team. The library has not had a release in six months, and there are several open issues reporting potential security vulnerabilities. Which of the following is the MOST appropriate security assessment action?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISSP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.