
Certified Information Systems Security Professional
Domain 6Objective 5
6.5 - Conduct or Facilitate Security Audits CISSP Practice Questions (Page 3)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
12%of the exam
Questions 11–15
- 11
An internal audit team is conducting an audit of a cloud-based infrastructure that hosts a critical application. The team has read-only access to the cloud management console. The audit objective is to verify that the principle of least privilege is enforced for all user accounts. The team discovers that a service account has been granted 'Owner' role instead of a more limited role. However, the team cannot determine if this is a deliberate exception or an error. Which action should the audit team take?
Select an answer first - 12
What is a common objective of a third-party audit?
Select an answer first - 13
What is a primary benefit of conducting an internal audit?
Select an answer first - 14
An internal audit team is reviewing the security of a new cloud-based file sharing service adopted by the marketing department. The team has been granted read-only access to the service's admin console. The audit objective is to verify that external sharing links are properly controlled and expire as per policy. Which action should the audit team take to gather evidence?
Select an answer first - 15
A large enterprise is preparing for an external audit of its financial reporting controls. The external auditor has requested access to the company's change management system to review recent changes to the ERP system. The company's internal IT team is responsible for facilitating this request. What is the most appropriate way for the IT team to provide access to the auditor?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.