
Certified Information Systems Security Professional
Domain 3Objective 10
3.10 - Manage the Information System Lifecycle CISSP Practice Questions (Page 3)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
9concepts
13%of the exam
Questions 11–15
- 11
What is a primary objective of the operations and maintenance phase?
Select an answer first - 12
In the development and implementation phase, which activity involves turning the design into a working system?
Select an answer first - 13
A healthcare organization is replacing its legacy patient portal. The new system must support 24/7 access for patients, integrate with an existing EHR, and comply with HIPAA. During requirements gathering, the project manager collects input from clinicians, patients, and IT security. Which action best ensures the system's requirements are complete and testable?
Select an answer first - 14
Which activity is part of the retirement and disposal phase?
Select an answer first - 15
A company operates a legacy system that is still critical to daily operations but is no longer receiving vendor support. The system has known vulnerabilities that cannot be patched. What is the most appropriate risk management action during the operations and maintenance phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.