
Certified Information Systems Security Professional
Domain 7Objective 8
7.8 - Implement and Support Patch and Vulnerability Management CISSP Practice Questions (Page 1)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
13%of the exam
Questions 1–5
- 1
Which metric is commonly used to measure the effectiveness of patch management?
Select an answer first - 2
Which patch deployment strategy involves applying a patch to a small group of systems first, then gradually expanding to the rest of the environment?
Select an answer first - 3
A security analyst is using a vulnerability scanner to assess a network. The scanner reports a high number of false positives. Which technique would most likely reduce false positives?
Select an answer first - 4
What is a key benefit of using a formal change management process for patch deployment?
Select an answer first - 5
In the vulnerability management lifecycle, which phase involves assigning a severity rating to a discovered vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.