
Certified Information Systems Security Professional
Domain 1Objective 6
1.6 - Develop, Document, and Implement Security Policy, Standards, Procedures, and Guidelines CISSP Practice Questions (Page 2)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
16%of the exam
Questions 6–10
- 6
A security analyst is reviewing the company's documentation and notices that the procedure for incident response contradicts the incident response standard. What should the analyst do?
Select an answer first - 7
A security manager is organizing the company's security documentation. The documentation includes a policy on data classification, a standard specifying encryption algorithms, and a procedure for handling classified data. How should these documents be structured to maintain a clear hierarchy?
Select an answer first - 8
A large healthcare organization is developing a security policy for patient data. The policy must comply with HIPAA, but the organization also operates in a country with stricter data protection laws. The legal team wants to avoid conflicting requirements. What is the best approach?
Select an answer first - 9
In a hierarchical security documentation structure, which document sits at the top?
Select an answer first - 10
What is the key characteristic of security guidelines?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.