
Certified Information Systems Security Professional
Domain 7Objective 6
7.6 - Conduct Incident Management CISSP Practice Questions (Page 4)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
13%of the exam
Questions 16–20
- 16
An organization experienced a phishing attack that led to the compromise of several email accounts. The incident response team has contained the incident and removed the malicious emails. What is the NEXT step to prevent a similar incident from recurring?
Select an answer first - 17
A security analyst notices a sudden spike in outbound traffic from a single workstation to an external IP address known for command-and-control activity. The workstation is part of a research department that handles proprietary data. The analyst suspects a malware infection. What is the FIRST action the analyst should take?
Select an answer first - 18
A web application was compromised through a SQL injection vulnerability. The incident response team has contained the incident and restored the application. What is the MOST important remediation step to prevent recurrence?
Select an answer first - 19
What is the main purpose of a lessons learned review after an incident?
Select an answer first - 20
An employee notices unusual system behavior and reports it to the security team. This is an example of which incident detection method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.