Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 8Objective 2

8.2 - Identify and Apply Security Controls in Software Development Ecosystems CISSP Practice Questions (Page 3)

Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
12concepts
10%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is evaluating testing tools for a critical application. They need to identify vulnerabilities that are only visible during execution, such as business logic flaws, and they also need to know the exact code path that leads to the flaw. The team has a limited budget and cannot afford to run both a SAST and a DAST tool. Which approach best meets their needs?

    Select an answer first
  2. 12expert · hard

    A development team is using a SAST tool in their CI/CD pipeline. The tool is generating a large number of false positives, which is causing developers to ignore the results. The security team wants to reduce the noise while still catching real vulnerabilities. Which approach best balances these concerns?

    Select an answer first
  3. 13foundation · easy

    What is a key advantage of Interactive Application Security Testing (IAST) over traditional SAST and DAST?

    Select an answer first
  4. 14foundation · easy

    What is the most effective way to protect source code stored in a code repository from unauthorized access?

    Select an answer first
  5. 15expert · hard

    A company is deploying a Java application to a server. The application uses reflection to load classes dynamically. The security team is concerned about the risk of an attacker exploiting the reflection mechanism to execute arbitrary code. Which runtime control is most effective in mitigating this risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.