Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 8Objective 3

8.3 - Assess the Effectiveness of Software Security CISSP Practice Questions (Page 6)

Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
8concepts
10%of the exam

Questions 26–30

  1. 26expert · hard

    A security manager is evaluating the effectiveness of a new security control that was implemented to reduce the risk of data exfiltration from a web application. The control is a data loss prevention (DLP) system that monitors outbound network traffic. After three months, the manager reviews the metrics and finds that the DLP system has blocked 50 potential exfiltration attempts. However, a subsequent penetration test successfully exfiltrated a sample dataset. What is the MOST appropriate conclusion about the control's effectiveness?

    Select an answer first
  2. 27expert · hard

    A company is developing a new customer-facing web application that will store payment card data. The risk assessment team has identified a critical vulnerability in a third-party library used for input validation. The library is widely used and a patch is not yet available. The team must decide on a mitigation strategy. Which approach is the most appropriate risk mitigation strategy in this situation?

    Select an answer first
  3. 28foundation · easy

    Which activity is MOST directly associated with assessing the effectiveness of a security control?

    Select an answer first
  4. 29application · medium

    An analyst is reviewing audit logs and notices that a user's account was used to log in from a new location at 2:00 AM. The user then accessed a large number of sensitive documents that they have never accessed before. This activity occurred over a 10-minute period. Which type of security incident does this pattern MOST likely indicate?

    Select an answer first
  5. 30expert · hard

    A security analyst is investigating a potential data breach. The analyst has access to the following audit logs: web server access logs, database query logs, and authentication logs. The analyst notices that a database query log shows a large number of SELECT statements from a single application user account. The web server logs show a corresponding spike in requests to a specific URL. The authentication logs show no failed login attempts for this account. What is the MOST likely explanation for this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.