
Certified Information Systems Security Professional
Domain 3Objective 3
3.3 - Select Controls Based Upon Systems Security Requirements CISSP Practice Questions (Page 4)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
13%of the exam
Questions 16–20
- 16
A government contractor is required to implement security controls for a new system handling controlled unclassified information (CUI). The organization must follow a recognized framework to ensure compliance with federal regulations. Which approach should the security team take to select the appropriate controls?
Select an answer first - 17
A financial services company is deploying a new customer-facing web application that will process credit card transactions. The compliance team requires that cardholder data be protected both in transit and at rest. The security architect must select controls that satisfy the Payment Card Industry Data Security Standard (PCI DSS) while minimizing impact on application performance. Which control combination best meets the stated requirements?
Select an answer first - 18
Why is it important for security controls to work cohesively with each other?
Select an answer first - 19
A company has implemented a new security control to detect unauthorized changes to critical files. The control generates an alert when a file is modified without authorization. Which type of control is this?
Select an answer first - 20
A healthcare organization is implementing a new electronic health record (EHR) system. The security team has selected a set of controls, including encryption, access controls, and audit logging. During implementation, they realize that the audit logging system is not capturing events from the encryption module. What is the most appropriate action to ensure the controls work cohesively?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.