
Certified Information Systems Security Professional
Domain 7Objective 2
7.2 - Conduct Logging and Monitoring Activities CISSP Practice Questions (Page 5)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
13%of the exam
Questions 21–25
- 21
A security operations team has been running a SIEM for six months. The team notices that a particular correlation rule has not generated any alerts in the past three months, despite being triggered frequently in the first three months. The team suspects the rule may be broken or the threat has been mitigated. What is the most appropriate action?
Select an answer first - 22
A security analyst is reviewing logs after a suspected breach. The analyst finds that a user account was used to log in from the corporate office at 10:00 AM and from a foreign country at 10:05 AM. The analyst also sees that the same account was used to access a file share containing sensitive data at 10:06 AM. What is the most likely conclusion?
Select an answer first - 23
A security team has completed a thorough review of its SIEM alerts and found no indicators of compromise. However, the team suspects that a sophisticated attacker may have evaded detection. The team decides to conduct a threat hunting exercise. What is the most effective first step in this process?
Select an answer first - 24
What is the primary difference between threat hunting and traditional security monitoring?
Select an answer first - 25
Which IDPS response action is considered the most disruptive to an ongoing attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.