Courseiva

ISC · topic practice

Systems Lifecycle Management practice questions

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Systems Lifecycle Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Systems Lifecycle Management

What the exam tests

What to know about Systems Lifecycle Management

Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Systems Lifecycle Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Systems Lifecycle Management questions

20 questions · select your answer, then reveal the explanation

During the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?

A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?

What is the primary objective of a 'Security Gate' in an SDLC?

Which document is primarily responsible for documenting the security controls applicable to a system during the SDLC's requirements phase?

A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?

During a waterfall-to-Agile transition, the development team wants to bypass formal Security Requirements Traceability Matrix (SRTM) documentation in favor of user stories. How should the ISSMP reconcile this?

An ISSMP is overseeing the integration of security into a new DevOps pipeline using Jenkins. Which stage of the SDLC should the ISSMP enforce the execution of SAST tools to ensure security requirements are met early?

An ISSMP is performing a security assessment on an application using containerized microservices. The team uses Kubernetes. What is the most effective way to ensure security configurations are consistently applied across all clusters?

An organization is adopting Infrastructure-as-Code (IaC) using Terraform. The ISSMP wants to ensure no insecure configurations (e.g., S3 buckets with public read) are deployed. What should be integrated into the CI/CD pipeline?

An organization uses a microservices architecture. How can the ISSMP ensure that inter-service communication is encrypted and that services are authenticated to one another?

When decommissioning an application, which action should the ISSMP prioritize to ensure data privacy requirements (e.g., GDPR) are satisfied?

A project manager wants to bypass a security vulnerability finding because 'the patch will break the application'. What is the correct ISSMP response?

Which document defines the security requirements that must be met for a third-party vendor to integrate with the company's internal systems?

Which phase of the SDLC is most appropriate for conducting a formal Threat Modeling exercise?

During a software audit, it is found that developers have administrative access to the production database to troubleshoot errors. What change should the ISSMP implement?

An organization is deploying a globally distributed application. The ISSMP needs to ensure that code changes are signed to prevent tampering. Which process should be implemented in the build pipeline?

In the context of the SDLC, what is the primary purpose of a 'Software Bill of Materials' (SBOM)?

Which metric provides the best insight into the effectiveness of the security program within the SDLC?

What is the primary role of a Change Advisory Board (CAB)?

A company is integrating a Third-Party API into their application. What must the ISSMP ensure is included in the risk assessment process?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Systems Lifecycle Management sessions

Start a Systems Lifecycle Management only practice session

Every question in these sessions is drawn from the Systems Lifecycle Management domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Systems Lifecycle Management?
Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Systems Lifecycle Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Systems Lifecycle Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.