
Certified Information Systems Security Professional
Domain 5Objective 2
5.2 - Design Identification and Authentication Strategy (e.g., People, Devices, and Services) CISSP Practice Questions (Page 4)
Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
13%of the exam
Questions 16–20
- 16
A financial trading firm has a web application that handles sensitive transactions. They want to enforce a session timeout after 10 minutes of inactivity, but traders often leave their desks for longer periods. The security team is concerned about session hijacking. Which combination of controls would best balance security and usability?
Select an answer first - 17
What is the purpose of identity proofing during the registration process?
Select an answer first - 18
A financial services firm is migrating to a cloud-based platform. The security team wants to reduce standing privileges for contractors who need temporary access to a project management tool. They also need to ensure that when a contractor's contract ends, their access is automatically revoked. The firm has an existing HR system that triggers workflows on employee status changes. Which solution best meets these requirements?
Select an answer first - 19
Which component of the AAA framework is responsible for verifying the identity of a user or device?
Select an answer first - 20
How does Single Sign-On (SSO) typically work?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.