
Certified Information Systems Security Professional
Domain 8Objective 5
8.5 - Define and Apply Secure Coding Guidelines and Standards CISSP Practice Questions (Page 6)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
10%of the exam
Questions 26–28
- 26
A company is designing a public API for a third-party integration. The API will handle sensitive customer data. The security team requires that the API authenticate callers and also ensure that each caller can only access their own data. Which combination of mechanisms is the most appropriate?
Select an answer first - 27
An organization wants to enforce a consistent security baseline across all its cloud workloads. The security team is considering using infrastructure as code (IaC) templates. How does this approach relate to software-defined security?
Select an answer first - 28
An organization is moving from a monolithic application to a microservices architecture. The security team wants to enforce consistent authentication and authorization across all services. They are considering a service mesh with sidecar proxies. What is the primary security benefit of this approach?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.