Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 5Objective 2

5.2 - Design Identification and Authentication Strategy (e.g., People, Devices, and Services) CISSP Practice Questions (Page 7)

Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
10concepts
13%of the exam

Questions 31–35

  1. 31application · medium

    A small business has several administrators who manage different systems. They currently share passwords for administrative accounts, which creates a security risk. The business wants to eliminate password sharing while maintaining the ability to audit who accessed what. Which solution should they implement?

    Select an answer first
  2. 32expert · hard

    A cloud service provider wants to allow customers to access a support portal. They want to minimize the risk of standing privileges for support agents, but they also want to ensure that agents can access customer data only when a support ticket is assigned to them. Which approach best meets these requirements?

    Select an answer first
  3. 33foundation · easy

    What is a primary benefit of password-less authentication over traditional password-based authentication?

    Select an answer first
  4. 34application · medium

    A company is onboarding a new department of 50 employees. The IT team wants to grant them access to a shared file server, a project management tool, and a time-tracking system. They want to avoid configuring permissions for each employee individually. Which approach is most efficient and maintainable?

    Select an answer first
  5. 35application · medium

    A company is implementing MFA for remote access to its network. They want to use a method that is resistant to phishing and does not require users to carry a separate physical token. Which method should they choose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.