Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 6Objective 1

6.1 - Design and Validate Assessment, Test, and Audit Strategies CISSP Practice Questions (Page 1)

Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts
12%of the exam

Questions 1–5

  1. 1expert · hard

    A company is considering hiring an external penetration testing firm to assess its network. The company has strict data protection requirements and wants to ensure the testing does not expose sensitive data. What is the most important contractual element to include?

    Select an answer first
  2. 2application · medium

    A company runs a hybrid infrastructure with on-premises data centers and a public cloud environment. The security team needs to assess the security posture of both environments. What is the most important consideration when designing the assessment strategy?

    Select an answer first
  3. 3application · medium

    A software development company wants to assess the security of its new web application before launch. The application is hosted in a cloud environment, and the development team has staging access. The company wants to identify vulnerabilities early without affecting production. What is the best assessment approach?

    Select an answer first
  4. 4application · medium

    A financial services firm must validate its internal network segmentation controls before a regulatory audit. The security team has full access to the production environment and wants to minimize disruption to business operations. Which assessment strategy best meets these requirements?

    Select an answer first
  5. 5application · medium

    A government agency is required to have an annual security assessment of its systems by an independent third party. The agency has a strong internal security team. What is the most important reason for using an external assessor?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.