Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 5Objective 2

5.2 - Design Identification and Authentication Strategy (e.g., People, Devices, and Services) CISSP Practice Questions (Page 2)

Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
10concepts
13%of the exam

Questions 6–10

  1. 6foundation · easy

    How does Just-In-Time (JIT) provisioning help reduce security risks?

    Select an answer first
  2. 7application · medium

    A multinational company uses an on-premises Active Directory for employee authentication. They are adopting a cloud-based HR system and a SaaS CRM. They want employees to sign in once with their corporate credentials and access all three systems without being prompted again. The company also wants to enforce group-based access policies consistently across all systems. Which approach best achieves this?

    Select an answer first
  3. 8expert · hard

    A company is designing a web application that handles sensitive financial data. They want to implement session management to prevent session fixation and session hijacking. Which combination of controls is most effective?

    Select an answer first
  4. 9foundation · easy

    Which of the following is an example of a 'something you have' authentication factor?

    Select an answer first
  5. 10foundation · easy

    Why does multi-factor authentication (MFA) provide stronger security than single-factor authentication?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.