
Certified Information Systems Security Professional
Domain 3Objective 3
3.3 - Select Controls Based Upon Systems Security Requirements CISSP Practice Questions (Page 1)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
13%of the exam
Questions 1–5
- 1
When evaluating candidate security controls, which factor is most important to consider alongside cost?
Select an answer first - 2
A government agency is required to comply with FISMA and is using NIST SP 800-53 as its control framework. The agency has a system with a moderate impact level. The security team is selecting controls and must balance compliance with budget constraints. Which approach is most appropriate?
Select an answer first - 3
A security team has implemented a new data classification policy and associated controls. To validate that the controls are effective, they plan to conduct a review. Which validation activity would provide the most reliable evidence that the controls meet the intended security requirements?
Select an answer first - 4
What is the difference between verification and validation of security controls?
Select an answer first - 5
A global company is deploying a new application that processes personal data of EU citizens. The company must comply with GDPR, which requires data protection by design and by default. The application will be hosted in a public cloud with data residency in the EU. The security architect must select controls that meet GDPR requirements while balancing cost and performance. Which control set is the most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.