Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 6Objective 3

6.3 - Collect Security Process Data (e.g., Technical and Administrative) CISSP Practice Questions (Page 2)

Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
8concepts
12%of the exam

Questions 6–10

  1. 6expert · medium

    A security manager is designing a dashboard to present security metrics to the board. The board wants to see both the effectiveness of security controls and the level of risk exposure. Which combination of metrics would BEST serve this purpose?

    Select an answer first
  2. 7foundation · easy

    Which type of data is most directly associated with Account Management Data Collection for security monitoring?

    Select an answer first
  3. 8application · medium

    A system administrator is asked to grant a contractor temporary access to a sensitive project repository. The organization's policy requires management approval for such access. What evidence should the administrator collect and retain to demonstrate compliance with this policy?

    Select an answer first
  4. 9application · medium

    A multinational company's security team is implementing a new identity governance tool. The compliance officer requires evidence that access reviews are conducted regularly and that any discrepancies are resolved. The team wants to automate the collection of this evidence. Which data source should be the PRIMARY input for this automation?

    Select an answer first
  5. 10application · medium

    An organization's backup policy requires that all backups be verified for recoverability on a quarterly basis. The backup administrator has been performing test restores, but the security team wants to automate the collection of this verification data. Which approach would BEST automate this process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.