Practice ISC Systems Lifecycle Management questions with full explanations on every answer.
Start practicing
Systems Lifecycle Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?
2A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?
3What is the primary objective of a 'Security Gate' in an SDLC?
4Which document is primarily responsible for documenting the security controls applicable to a system during the SDLC's requirements phase?
5A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?
6During a waterfall-to-Agile transition, the development team wants to bypass formal Security Requirements Traceability Matrix (SRTM) documentation in favor of user stories. How should the ISSMP reconcile this?
7An ISSMP is overseeing the integration of security into a new DevOps pipeline using Jenkins. Which stage of the SDLC should the ISSMP enforce the execution of SAST tools to ensure security requirements are met early?
8An ISSMP is performing a security assessment on an application using containerized microservices. The team uses Kubernetes. What is the most effective way to ensure security configurations are consistently applied across all clusters?
9An organization is adopting Infrastructure-as-Code (IaC) using Terraform. The ISSMP wants to ensure no insecure configurations (e.g., S3 buckets with public read) are deployed. What should be integrated into the CI/CD pipeline?
10An organization uses a microservices architecture. How can the ISSMP ensure that inter-service communication is encrypted and that services are authenticated to one another?
11When decommissioning an application, which action should the ISSMP prioritize to ensure data privacy requirements (e.g., GDPR) are satisfied?
12A project manager wants to bypass a security vulnerability finding because 'the patch will break the application'. What is the correct ISSMP response?
13Which document defines the security requirements that must be met for a third-party vendor to integrate with the company's internal systems?
14Which phase of the SDLC is most appropriate for conducting a formal Threat Modeling exercise?
15During a software audit, it is found that developers have administrative access to the production database to troubleshoot errors. What change should the ISSMP implement?
16An organization is deploying a globally distributed application. The ISSMP needs to ensure that code changes are signed to prevent tampering. Which process should be implemented in the build pipeline?
17In the context of the SDLC, what is the primary purpose of a 'Software Bill of Materials' (SBOM)?
18Which metric provides the best insight into the effectiveness of the security program within the SDLC?
19What is the primary role of a Change Advisory Board (CAB)?
20A company is integrating a Third-Party API into their application. What must the ISSMP ensure is included in the risk assessment process?
21Which TWO of the following are critical components of a secure SDLC (Software Development Life Cycle) implementation?
22Which THREE factors should an ISSMP consider when selecting security controls for a new system?
23An ISSMP is reviewing the 'Change Control' process for a critical system. Which of the following is an essential element for every change request?
24Which TWO mechanisms are effective for preventing 'insecure direct object references' (IDOR) in a web application during the development phase?
25Which THREE actions are necessary when preparing to decommission a cloud-based Virtual Machine (VM)?
26Which TWO items must be documented in a Change Control Log after a successful production change?
27Which THREE components should be included in an application security requirements document?
28Which THREE items are typically verified in a Security Gate check before a production deployment?
29Which TWO techniques are effective for securing the software supply chain?
30Which TWO of the following are potential risks if an ISSMP fails to integrate security into the 'Requirements Management' phase?
The Systems Lifecycle Management domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 30 questions in the Systems Lifecycle Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Systems Lifecycle Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included