Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 6

1.6 - Develop, Document, and Implement Security Policy, Standards, Procedures, and Guidelines CISSP Practice Questions (Page 2)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
16%of the exam

Questions 6–10

  1. 6application · medium

    A security analyst is reviewing the company's documentation and notices that the procedure for incident response contradicts the incident response standard. What should the analyst do?

    Select an answer first
  2. 7application · medium

    A security manager is organizing the company's security documentation. The documentation includes a policy on data classification, a standard specifying encryption algorithms, and a procedure for handling classified data. How should these documents be structured to maintain a clear hierarchy?

    Select an answer first
  3. 8expert · hard

    A large healthcare organization is developing a security policy for patient data. The policy must comply with HIPAA, but the organization also operates in a country with stricter data protection laws. The legal team wants to avoid conflicting requirements. What is the best approach?

    Select an answer first
  4. 9foundation · easy

    In a hierarchical security documentation structure, which document sits at the top?

    Select an answer first
  5. 10foundation · easy

    What is the key characteristic of security guidelines?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.