
Certified Information Systems Security Professional
Domain 8Objective 3
8.3 - Assess the Effectiveness of Software Security CISSP Practice Questions (Page 3)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
10%of the exam
Questions 11–15
- 11
A risk manager is choosing between two risk analysis methods for a new software project. The project is in its early stages, and the team has limited historical data on the likelihood of specific vulnerabilities. The manager needs a method that can provide a quick, high-level understanding of the risks to prioritize initial security efforts. Which method is MOST appropriate?
Select an answer first - 12
Why is it critical to protect audit logs from tampering and unauthorized access?
Select an answer first - 13
A software company has identified a high-risk vulnerability in a web application that is currently in production. The vulnerability could allow an attacker to access the database. The company has decided to implement a web application firewall (WAF) to block the attack. This is an example of which risk mitigation strategy?
Select an answer first - 14
What is the purpose of applying secure coding practices as a risk mitigation strategy?
Select an answer first - 15
A system administrator is configuring audit logging for a Linux server that hosts a critical application. The administrator wants to detect unauthorized changes to the application's configuration files. Which logging configuration is most effective for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.