
Certified Information Systems Security Professional
Domain 8Objective 2
8.2 - Identify and Apply Security Controls in Software Development Ecosystems CISSP Practice Questions (Page 7)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
10%of the exam
Questions 31–35
- 31
A team develops a web application in Python. Management wants to catch common coding errors like SQL injection and hardcoded credentials as early as possible in the development lifecycle, ideally before code is committed. Which approach best meets this requirement?
Select an answer first - 32
Which testing approach combines elements of static and dynamic analysis to identify vulnerabilities in real-time during application execution?
Select an answer first - 33
What is a key advantage of DAST over SAST?
Select an answer first - 34
A security architect is reviewing a new application that will process untrusted user input. The application will be written in C and will run on a Linux server. Which security consideration is most important to address in this environment?
Select an answer first - 35
Which of the following is a security feature commonly found in modern Integrated Development Environments (IDEs)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.