
Certified Information Systems Security Professional
Domain 6Objective 3
6.3 - Collect Security Process Data (e.g., Technical and Administrative) CISSP Practice Questions (Page 3)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
12%of the exam
Questions 11–15
- 11
A security analyst is monitoring key risk indicators (KRIs) and notices that the number of failed backup jobs has increased by 50% over the past week. What is the MOST appropriate immediate action?
Select an answer first - 12
After a disaster recovery (DR) test, the recovery team reports that the critical application was restored in 6 hours, but the business had set a recovery time objective (RTO) of 4 hours. The data loss was within the recovery point objective (RPO). What should the security team do with this data?
Select an answer first - 13
Which of the following is an example of a security KRI?
Select an answer first - 14
A security team wants to measure the effectiveness of its access control process. Which metric would be the BEST key performance indicator (KPI) for this purpose?
Select an answer first - 15
Which of the following is an example of an access privilege change that should be collected as part of Account Management Data Collection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.