Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 7Objective 8

7.8 - Implement and Support Patch and Vulnerability Management CISSP Practice Questions (Page 4)

Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
9concepts
13%of the exam

Questions 16–20

  1. 16application · medium

    A security team needs to identify vulnerabilities in a new web application before it goes live. The application is hosted in a cloud environment and uses a mix of open-source and custom components. Which scanning approach provides the most comprehensive coverage?

    Select an answer first
  2. 17foundation · easy

    What is the primary purpose of documenting patch and vulnerability management activities?

    Select an answer first
  3. 18foundation · easy

    Which type of vulnerability scan is performed with valid credentials to provide a more accurate assessment of vulnerabilities?

    Select an answer first
  4. 19foundation · easy

    How can metrics be used to drive continuous improvement in patch management?

    Select an answer first
  5. 20application · medium

    A vulnerability management team has completed the remediation of a critical vulnerability. What should the team do to close the vulnerability ticket?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.