
Certified Information Systems Security Professional
Domain 6Objective 5
6.5 - Conduct or Facilitate Security Audits CISSP Practice Questions (Page 1)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
12%of the exam
Questions 1–5
- 1
A publicly traded company is preparing for its annual financial statement audit. The external auditor has requested access to the company's IT general controls (ITGC) documentation, including user access reviews, change management logs, and backup testing results. The company's internal audit team has already performed a comprehensive review of these areas and found no significant deficiencies. What is the primary reason the external auditor still needs to perform their own testing rather than relying solely on the internal audit team's work?
Select an answer first - 2
A healthcare organization is required to undergo a certification audit to maintain its HITRUST certification. The certification body has scheduled an on-site audit of the organization's primary data center and a remote audit of its cloud-based patient portal. The organization's IT team is responsible for facilitating the audit. Which action is most critical for the organization to take to ensure a smooth and successful certification audit?
Select an answer first - 3
A software development company is required to undergo a third-party audit to maintain its PCI DSS compliance. The auditor has scheduled a remote audit and will need to review the company's network architecture diagrams, firewall configurations, and vulnerability scan reports. The company's security team is responsible for facilitating the audit. Which action is most important for the security team to take?
Select an answer first - 4
How does audit location affect the audit process?
Select an answer first - 5
An organization is undergoing a third-party audit for ISO 27001 certification. The organization's IT infrastructure is fully cloud-based, with no on-premises servers. The auditor needs to verify the organization's access control policies and their implementation. Which evidence would be most appropriate for the organization to provide to the auditor for this cloud environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.