
Certified Information Systems Security Professional
Domain 6Objective 2
6.2 - Conduct Security Control Testing CISSP Practice Questions (Page 3)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
12%of the exam
Questions 11–15
- 11
Which of the following is a common metric used in coverage analysis?
Select an answer first - 12
A development team is about to release a web application. They want to identify vulnerabilities in the source code early in the development lifecycle, before the application is deployed. The team has a limited budget and needs a method that can be integrated into the CI/CD pipeline. Which approach should they choose?
Select an answer first - 13
What is a key characteristic of manual code review?
Select an answer first - 14
What is the primary purpose of a compliance check?
Select an answer first - 15
A financial institution must verify that its systems are configured according to PCI DSS requirements. The compliance team needs to check that all firewalls are properly configured and that encryption is enabled for cardholder data. Which activity is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.