
Certified Information Systems Security Professional
Domain 3Objective 1
3.1 - Research, Implement and Manage Engineering Processes Using Secure Design Principles CISSP Practice Questions (Page 2)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
11concepts
13%of the exam
Questions 6–10
- 6
During threat modeling, which of the following is a key input used to identify potential threats?
Select an answer first - 7
Which of the following is an example of implementing secure defaults?
Select an answer first - 8
A financial institution is implementing a new wire transfer system. The system will allow employees to initiate and approve wire transfers. The company wants to prevent fraud and errors. The security architect is designing the workflow. Which workflow BEST implements segregation of duties?
Select an answer first - 9
What is the primary goal of defense in depth?
Select an answer first - 10
A company is implementing a new enterprise resource planning (ERP) system. The system will handle financial transactions and sensitive employee data. The security architect is designing the access control model. The company has a small IT team, and the same administrator currently manages both user accounts and financial data. The company wants to reduce the risk of fraud and errors. Which approach BEST balances least privilege and segregation of duties?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.