
Certified Information Systems Security Professional
Domain 8Objective 3
8.3 - Assess the Effectiveness of Software Security CISSP Practice Questions (Page 2)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
10%of the exam
Questions 6–10
- 6
In quantitative risk analysis, the Annualized Loss Expectancy (ALE) is calculated by which formula?
Select an answer first - 7
In the context of software security, what does risk assessment primarily involve?
Select an answer first - 8
A security team is designing the audit logging strategy for a new e-commerce platform. Which of the following events should be logged to support security monitoring and incident response? (Select all that apply.)
Select an answer first - 9
A development team is implementing a new audit logging system for a critical financial application. The compliance team requires that logs be available for forensic analysis for at least one year and that they cannot be altered by an attacker who compromises an application server. Which solution best meets these requirements?
Select an answer first - 10
Which of the following is an example of a change that should be logged and monitored for security purposes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.