
Certified Information Systems Security Professional
Domain 1Objective 3
1.3 - Evaluate and Apply Security Governance Principles CISSP Practice Questions (Page 4)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
16%of the exam
Questions 16–20
- 16
An organization implements security controls and practices to protect its assets. This action is an example of which concept?
Select an answer first - 17
Which of the following best demonstrates that the security function is aligned with business strategy?
Select an answer first - 18
A regional bank is expanding into a new market with a strategic goal of reducing time-to-market for new digital products. The CISO proposes a security architecture that uses a cloud-based, automated security testing pipeline integrated into the development lifecycle. Which action best demonstrates alignment of security with the business strategy?
Select an answer first - 19
A U.S. federal agency must procure a cloud service that processes controlled unclassified information. The agency needs a standardized security assessment and authorization process. Which framework is most appropriate to guide this procurement?
Select an answer first - 20
A large enterprise is establishing a security governance committee. Which group should have the authority to approve major security policies and allocate resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.