Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 6Objective 1

6.1 - Design and Validate Assessment, Test, and Audit Strategies CISSP Practice Questions (Page 5)

Part of the Security Assessment and Testing domain, which accounts for 12% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts
12%of the exam

Questions 21–24

  1. 21application · medium

    A healthcare organization is required by its insurance carrier to have an independent security assessment of its patient portal. The organization's internal team has already performed vulnerability scans and penetration tests. What is the most appropriate next step?

    Select an answer first
  2. 22foundation · easy

    What is a key characteristic of an external assessment strategy?

    Select an answer first
  3. 23application · medium

    A university's IT department wants to assess the security of its student information system, which is hosted on-premises. The department has a dedicated security team. What is the most effective way to conduct this assessment?

    Select an answer first
  4. 24foundation · easy

    Which of the following is an implication of conducting an assessment in a hybrid environment?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISSP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.