
Certified Information Systems Security Professional
Domain 7Objective 8
7.8 - Implement and Support Patch and Vulnerability Management CISSP Practice Questions (Page 6)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
13%of the exam
Questions 26–30
- 26
A company has a critical patch for a vulnerability in a core business application. The patch is known to cause a brief service interruption during installation. The application is used 24/7 by customers, and the change management policy requires a change window for any service interruption. What is the best approach to deploy the patch?
Select an answer first - 27
A large organization has 10,000 servers and needs to apply a critical security patch within 48 hours. The patch is known to be stable and does not require application testing. Which approach is most efficient and effective?
Select an answer first - 28
In the patch management process, which step involves identifying all systems and software that may require patches?
Select an answer first - 29
What is the primary purpose of a change window in patch deployment?
Select an answer first - 30
An organization has a vulnerability in a legacy system that cannot be patched because the vendor no longer provides updates. The system is critical to operations. What is the best risk-based approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.