Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 7Objective 8

7.8 - Implement and Support Patch and Vulnerability Management CISSP Practice Questions (Page 2)

Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
9concepts
13%of the exam

Questions 6–10

  1. 6expert · hard

    An organization has discovered three vulnerabilities: (1) a critical vulnerability in a public-facing web server that is actively exploited, (2) a high vulnerability in an internal database that is not internet-accessible, and (3) a medium vulnerability in a legacy application that is scheduled for decommissioning in three months. The patch management team has limited resources and can only address one vulnerability this week. Which vulnerability should be prioritized?

    Select an answer first
  2. 7foundation · easy

    Which vulnerability scanning technique involves actively sending probes to systems to identify open ports and services?

    Select an answer first
  3. 8foundation · easy

    Which phase of the vulnerability management lifecycle involves applying fixes or compensating controls to address identified vulnerabilities?

    Select an answer first
  4. 9foundation · easy

    Which type of report is typically used to demonstrate the organization's compliance with patch management policies to management?

    Select an answer first
  5. 10foundation · easy

    Which phase of the patch management process involves confirming that a patch was applied correctly and did not introduce new issues?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.