
Certified Information Systems Security Professional
Domain 7Objective 8
7.8 - Implement and Support Patch and Vulnerability Management CISSP Practice Questions (Page 5)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
13%of the exam
Questions 21–25
- 21
A company needs to deploy a patch that requires a system reboot. The patch is for a low-severity issue. The company has a policy that all changes must be approved by the change advisory board (CAB). What is the most appropriate action?
Select an answer first - 22
A patch management team wants to deploy a non-critical patch to a production server. The change management policy requires all changes to be approved by a change advisory board (CAB). What should the team do to comply with the policy?
Select an answer first - 23
Which vulnerability should be patched first according to risk-based prioritization?
Select an answer first - 24
What is the primary benefit of using automation in patch management?
Select an answer first - 25
A security manager wants to measure the effectiveness of the patch management program. Which metric best indicates how quickly the organization responds to newly discovered vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.