
Certified Information Systems Security Professional
Domain 7Objective 3
7.3 - Perform Configuration Management (CM) (e.g., Provisioning, Baselining, Automation) CISSP Practice Questions (Page 3)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
13%of the exam
Questions 11–15
- 11
An organization is required to demonstrate to auditors that its servers are configured according to a documented security baseline. The security team needs to provide evidence that the baseline is being maintained. Which of the following is the most effective way to provide this evidence?
Select an answer first - 12
A company is implementing a configuration management process for its application servers. The process must ensure that changes are made in a controlled manner and that the configuration baseline is updated when approved changes are made. Which of the following is the most appropriate sequence of activities?
Select an answer first - 13
A security team wants to automate the provisioning of new user workstations. Each workstation must be configured with the organization's standard security settings, including disk encryption, antivirus, and firewall rules. Which of the following is the most effective way to achieve this?
Select an answer first - 14
A company is deploying a new application server and needs to ensure it is configured consistently with the organization's security policy. The security team has defined a standard configuration that includes specific registry settings, service configurations, and firewall rules. They want to automate the initial setup so that any new server is provisioned with this exact configuration. Which approach best meets this requirement?
Select an answer first - 15
A security analyst is responsible for ensuring that all web servers in an organization are configured according to a security baseline. The analyst wants to automate the process of checking for compliance and generating reports. Which of the following is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.