
Certified Information Systems Security Professional
Domain 7Objective 2
7.2 - Conduct Logging and Monitoring Activities CISSP Practice Questions (Page 2)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
13%of the exam
Questions 6–10
- 6
Which type of threat intelligence feed is typically free and publicly available, such as those provided by government agencies or community groups?
Select an answer first - 7
What is the goal of tuning security alerts to reduce false positives?
Select an answer first - 8
When analyzing logs, what is the primary purpose of correlating events from multiple sources?
Select an answer first - 9
A defense contractor suspects that an employee is exfiltrating sensitive design documents by uploading them to a personal cloud storage account. The company has a data loss prevention (DLP) system that monitors outbound web traffic. What additional monitoring technique would best help confirm the exfiltration and identify the data involved?
Select an answer first - 10
A financial institution is required by regulation to retain audit logs for seven years. The security team is concerned about the cost of storing this data and the risk of tampering. What is the most appropriate strategy for log management that balances compliance, cost, and security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.