Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 5Objective 4

5.4 - Implement and Manage Authorization Mechanisms CISSP Practice Questions (Page 1)

Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts
13%of the exam

Questions 1–5

  1. 1expert · hard

    A company is implementing a new authorization system. The security team wants to ensure that access decisions are made consistently across all applications, and that policy changes can be made without modifying each application. Which architecture should be used?

    Select an answer first
  2. 2application · medium

    A government agency handles classified documents. The security policy requires that access be determined by comparing the user's security clearance to the classification level of the document, and that users cannot change the classification of documents. Which access control model enforces this requirement?

    Select an answer first
  3. 3foundation · easy

    In risk-based access control, what is the primary factor that influences the access decision?

    Select an answer first
  4. 4foundation · easy

    Which of the following is an example of an environment attribute in ABAC?

    Select an answer first
  5. 5foundation · easy

    In rule-based access control, what is the basis for making an access decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.