
Certified Information Systems Security Professional
Domain 8Objective 5
8.5 - Define and Apply Secure Coding Guidelines and Standards CISSP Practice Questions (Page 2)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
10%of the exam
Questions 6–10
- 6
A company is adopting a policy-as-code approach to enforce security standards across its development teams. The security team wants to ensure that all new code is scanned for secrets before it is merged. Which tool integration is the most effective?
Select an answer first - 7
Which secure coding practice is most effective at preventing SQL injection vulnerabilities?
Select an answer first - 8
How does software-defined security integrate security controls into the software development lifecycle (SDLC)?
Select an answer first - 9
A security audit of a web application found that the application is vulnerable to command injection. The vulnerable code passes user input directly to a system shell command. The team must fix this while preserving the ability to perform the intended operation. Which remediation is the most secure?
Select an answer first - 10
An organization is adopting a DevOps model and wants to integrate security checks into its CI/CD pipeline. The goal is to catch common vulnerabilities early without slowing down developers. Which approach best exemplifies software-defined security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.