
Certified Information Systems Security Professional
Domain 8Objective 3
8.3 - Assess the Effectiveness of Software Security CISSP Practice Questions (Page 4)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
10%of the exam
Questions 16–20
- 16
What is the main objective of audit trail analysis?
Select an answer first - 17
Which of the following is a key input to a software security risk assessment?
Select an answer first - 18
A security administrator is configuring audit logging for a new application. The administrator wants to ensure that the logs can be used to reconstruct the sequence of events during a security incident. Which of the following is the MOST important attribute for the audit logs to have?
Select an answer first - 19
Which of the following is an example of a risk mitigation strategy in software security?
Select an answer first - 20
A security analyst is reviewing audit logs from a web application and notices a series of failed login attempts for a single user account, each occurring at 3-second intervals from the same source IP, followed by a successful login. The analyst then sees the same pattern repeated for three other accounts over the next hour. Which conclusion is best supported by this audit trail analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.