Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 6Objective 2

6.2 - Conduct Security Control Testing CISSP Practice Questions (Page 2)

Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
10concepts
12%of the exam

Questions 6–10

  1. 6application · medium

    An organization wants to continuously test its security controls against the latest attack techniques without requiring manual red team exercises. They want to automate the process and integrate it with their security operations center. Which approach is most suitable?

    Select an answer first
  2. 7application · medium

    A security operations team is reviewing logs from multiple sources, including firewalls, servers, and applications. They want to identify patterns that might indicate a coordinated attack. Which technique is most effective for this task?

    Select an answer first
  3. 8foundation · easy

    What is the purpose of misuse case testing?

    Select an answer first
  4. 9foundation · easy

    How does a vulnerability assessment differ from a penetration test?

    Select an answer first
  5. 10application · medium

    A security team has completed a series of tests on a web application, including SAST, DAST, and manual penetration testing. They want to ensure that all critical code paths and user roles have been tested. Which activity should they perform to assess the completeness of their testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.