
Certified Information Systems Security Professional
Domain 8Objective 3
8.3 - Assess the Effectiveness of Software Security CISSP Practice Questions (Page 5)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
10%of the exam
Questions 21–25
- 21
A risk analyst is performing a quantitative risk analysis for a software vulnerability. The asset value of the affected system is $500,000. The exposure factor (EF) is 0.2, and the annualized rate of occurrence (ARO) is 4. What is the annualized loss expectancy (ALE)?
Select an answer first - 22
Which of the following is an effective measure to protect audit logs from tampering?
Select an answer first - 23
During an audit trail review, an analyst notices a large number of failed login attempts from a single IP address over a short period. This pattern is BEST described as:
Select an answer first - 24
A software development team has discovered a critical remote code execution vulnerability in a legacy application that is still in production. The application cannot be taken offline for an extended period. Which risk mitigation strategy should be implemented FIRST?
Select an answer first - 25
In the context of software security, what is the primary purpose of audit logging?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.