
Certified Information Systems Security Professional
Domain 6Objective 2
6.2 - Conduct Security Control Testing CISSP Practice Questions (Page 4)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
12%of the exam
Questions 16–20
- 16
A security manager wants to evaluate the organization's incident detection and response capabilities against a realistic threat without causing disruption to production systems. The team has already completed a vulnerability assessment that identified several missing patches. Which activity best meets the manager's objective?
Select an answer first - 17
A security tester is validating that a banking application properly rejects unauthorized actions, such as a user attempting to transfer funds from an account they do not own. Which testing approach is most appropriate for this scenario?
Select an answer first - 18
Which of the following is an example of a compliance check?
Select an answer first - 19
In a red team exercise, what is the primary role of the red team?
Select an answer first - 20
A security analyst is asked to identify all known vulnerabilities in the organization's network without attempting to exploit them. The goal is to prioritize patching efforts. Which activity should the analyst perform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.