
Certified Information Systems Security Professional
Domain 8Objective 1
8.1 - Understand and Integrate Security in the Software Development Life Cycle (SDLC) CISSP Practice Questions (Page 1)
Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
10%of the exam
Questions 1–5
- 1
A developer needs to make an urgent change to a production system to fix a critical bug. The organization has a formal change management process that requires a change advisory board (CAB) approval. What should the developer do?
Select an answer first - 2
What is the primary purpose of a formal change management process in the context of software and system modifications?
Select an answer first - 3
What is the primary purpose of a maturity model such as the Capability Maturity Model (CMM) in the context of software development?
Select an answer first - 4
A company is using the Waterfall model for a project with strict regulatory requirements. The security team wants to ensure that security requirements are captured early. At which phase should security requirements be defined?
Select an answer first - 5
A development team is transitioning from a Waterfall model to an Agile approach. The security team is concerned that security reviews, which were previously conducted as a distinct phase before release, will be lost. Which practice BEST integrates security into the new Agile workflow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.