Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 7Objective 7

7.7 - Operate and Maintain Detection and Preventative Measures CISSP Practice Questions (Page 2)

Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
8concepts
13%of the exam

Questions 6–10

  1. 6foundation · easy

    An organization wants to allow only approved applications to run on its workstations. Which approach is most appropriate?

    Select an answer first
  2. 7application · medium

    A company is deploying a new web application that handles customer transactions. The security team wants to inspect HTTP/HTTPS traffic for SQL injection and cross-site scripting attempts, and also block traffic from known malicious IP addresses before it reaches the application servers. Which solution should they implement?

    Select an answer first
  3. 8application · medium

    A company's anti-malware solution has been missing new, previously unseen malware variants. The security team wants to improve detection of unknown threats without relying solely on signature updates. Which enhancement should they consider?

    Select an answer first
  4. 9application · medium

    A security analyst is concerned about a new zero-day exploit that may target internal servers. The team wants to detect the exploit if it occurs, but they are worried that an automated prevention system might block legitimate traffic due to false positives. They also want to learn about the attacker's methods without exposing production systems. Which approach best meets these needs?

    Select an answer first
  5. 10foundation · easy

    An anti-malware tool monitors the actions of running programs, such as attempts to modify system files or access the network, to detect malicious behavior. Which detection method is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.