
Certified Information Systems Security Professional
Domain 6Objective 5
6.5 - Conduct or Facilitate Security Audits CISSP Practice Questions (Page 2)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
12%of the exam
Questions 6–10
- 6
A company is preparing for both an external financial audit and a third-party ISO 27001 surveillance audit. The external auditor requires access to the company's financial systems, while the ISO auditor requires access to the company's information security management system (ISMS) documentation. The company's audit coordinator has limited resources and must schedule both audits within the same month. Which approach is most effective for managing these concurrent audits?
Select an answer first - 7
What is the primary role of an external audit?
Select an answer first - 8
An organization's internal audit team is planning an audit of its cloud-based email system. The audit objective is to verify that data retention policies are correctly implemented. The team has read-only access to the cloud admin console. The team discovers that the retention policy for a specific mailbox is set to 'indefinite', which contradicts the organization's policy of 7 years. The mailbox belongs to a former employee who is involved in ongoing litigation. Which action should the audit team take?
Select an answer first - 9
A company is undergoing a third-party audit for SOC 2. The auditor needs to verify the company's backup and recovery procedures. The company's IT infrastructure is hybrid: critical data is stored on-premises, and a backup copy is stored in the cloud. The auditor has requested evidence of backup testing. The company's IT team has performed a backup restoration test six months ago and has documented the results. Which evidence is most appropriate to provide to the auditor?
Select an answer first - 10
A financial services firm is required to undergo a regulatory audit by a government agency. The agency has announced an unannounced on-site audit to review the firm's compliance with data protection regulations. The firm's management is concerned about the audit's impact on daily operations. Which action should the firm take to best prepare for this regulatory audit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.