Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 8Objective 1

8.1 - Understand and Integrate Security in the Software Development Life Cycle (SDLC) CISSP Practice Questions (Page 3)

Part of the Software Development Security domain, which accounts for 10% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
5concepts
10%of the exam

Questions 11–15

  1. 11expert · hard

    An organization is at SAMM Level 1 for its implementation practices. The security team wants to move to Level 2. They have limited budget and need to prioritize improvements. Which improvement would have the MOST impact on moving to Level 2?

    Select an answer first
  2. 12application · medium

    A critical application is in the operation and maintenance phase. A new vulnerability is disclosed in a third-party library used by the application. The security team needs to ensure the fix is applied without disrupting business operations. What is the FIRST step they should take?

    Select an answer first
  3. 13application · medium

    A large organization is starting a new software project. The project involves multiple departments: development, operations, security, legal, and customer support. To ensure security is integrated throughout the SDLC, what is the MOST effective organizational structure?

    Select an answer first
  4. 14expert · hard

    A company is migrating from a Waterfall to a DevSecOps model. The security team is concerned about losing control over security reviews. Which approach BEST addresses this concern while embracing DevSecOps?

    Select an answer first
  5. 15expert · hard

    A large organization is forming an Integrated Product Team (IPT) for a new software project. The team includes members from development, operations, security, and business units. However, the team is struggling with conflicting priorities, and security requirements are being deprioritized. What is the BEST way to resolve this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.