
Certified Information Systems Security Professional
Domain 3Objective 1
3.1 - Research, Implement and Manage Engineering Processes Using Secure Design Principles CISSP Practice Questions (Page 5)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
11concepts
13%of the exam
Questions 21–24
- 21
A healthcare startup is developing a mobile app that collects patient health data. The product team wants to ensure that the app complies with privacy regulations. Which approach BEST demonstrates privacy by design?
Select an answer first - 22
Which of the following is an example of defense in depth?
Select an answer first - 23
What is the 'trust but verify' approach?
Select an answer first - 24
A company is deploying a new web application that will be accessible from the internet. The application will store sensitive customer data. The security architect is designing the network architecture. The company has a limited budget and must choose between two options: (1) a single firewall with an intrusion prevention system (IPS) and a web application firewall (WAF), or (2) a DMZ with a firewall, a separate application server, and a database server on a separate network segment. Which option provides BETTER defense in depth?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.