
Certified Information Systems Security Professional
Domain 5Objective 2
5.2 - Design Identification and Authentication Strategy (e.g., People, Devices, and Services) CISSP Practice Questions (Page 5)
Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
13%of the exam
Questions 21–25
- 21
Which action is part of secure session management?
Select an answer first - 22
What is the primary benefit of Single Sign-On (SSO) for users?
Select an answer first - 23
A company is deploying a new internal application that requires users to authenticate, then be granted access based on their department, and finally have their actions logged for audit. The application currently uses a local database for user accounts. The security team wants to centralize this process. Which technology should they implement?
Select an answer first - 24
A company wants to reduce the risk of phishing attacks that target passwords. They are considering implementing password-less authentication using FIDO2 security keys. The security team wants to ensure that the solution is resistant to phishing and provides a good user experience. Which implementation should they choose?
Select an answer first - 25
What is the primary purpose of a password vault?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.