
Certified Information Systems Security Professional
Domain 8Objective 2
8.2 - Identify and Apply Security Controls in Software Development Ecosystems CISSP Practice Questions (Page 6)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
10%of the exam
Questions 26–30
- 26
Which of the following is a security control that should be applied to software configuration management processes?
Select an answer first - 27
What is the primary purpose of a build automation tool in a secure software development environment?
Select an answer first - 28
A developer wants to use a popular open-source library in a new project. The security team has a policy that all third-party code must be vetted before it is used. Which action should the developer take to comply with this policy?
Select an answer first - 29
A company's application uses a third-party library that has a known critical vulnerability. The library is used in a non-network-facing component of the application. The security team must decide how to handle this issue. The team wants to minimize the risk while also avoiding an unnecessary emergency release. Which action is most appropriate?
Select an answer first - 30
Which programming language characteristic is most directly associated with memory safety vulnerabilities such as buffer overflows?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.