
Certified Information Systems Security Professional
Domain 3Objective 3
3.3 - Select Controls Based Upon Systems Security Requirements CISSP Practice Questions (Page 5)
Part of the Security Architecture and Engineering domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
13%of the exam
Questions 21–25
- 21
An organization implements an intrusion detection system (IDS) to monitor network traffic for suspicious activity. This is an example of which control category and type?
Select an answer first - 22
In a cost-benefit analysis of security controls, what does the term 'safeguard value' refer to?
Select an answer first - 23
A small business is considering a new security control to protect its customer database. The control has a high upfront cost but is expected to reduce the likelihood of a data breach by 80%. The business has a limited budget and must justify the expense. Which analysis should the business perform to determine if the control is worth the cost?
Select an answer first - 24
Which activity is an example of validating a security control?
Select an answer first - 25
Which of the following best describes the initial step in the security control selection process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.