
Certified Information Systems Security Professional
Domain 6Objective 1
6.1 - Design and Validate Assessment, Test, and Audit Strategies CISSP Practice Questions (Page 4)
Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
12%of the exam
Questions 16–20
- 16
A global company must comply with data residency regulations that require personal data to remain within specific geographic boundaries. The company uses a third-party auditor to assess its cloud infrastructure. What is the most important consideration when designing the audit strategy?
Select an answer first - 17
A company's internal security team is planning a penetration test of a critical application. The application is hosted in a hybrid environment, and the team has limited time due to an upcoming audit. The team wants to maximize coverage while minimizing risk to production systems. What is the most effective approach?
Select an answer first - 18
Which of the following is a primary advantage of using an internal team for security assessments?
Select an answer first - 19
Which of the following is a common reason an organization would choose an external assessment over an internal one?
Select an answer first - 20
A company is moving its customer relationship management (CRM) system to a public cloud provider. The security team needs to assess the security of the CRM system in the cloud. What is the most important consideration for this assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.