Courseiva

ISC · domain

Systems Lifecycle Management

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Systems Lifecycle Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

30 questions7 easy13 medium10 hard

Focused practice

Practice Systems Lifecycle Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Systems Lifecycle Management

Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Systems Lifecycle Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Systems Lifecycle Management questions (30)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE factors should an ISSMP consider when selecting security controls for a new system?

Medium
2

In the context of the SDLC, what is the primary purpose of a 'Software Bill of Materials' (SBOM)?

Easy
3

Which document defines the security requirements that must be met for a third-party vendor to integrate with the company's internal systems?

Easy
4

A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?

Medium
5

A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?

Medium
6

An organization uses a microservices architecture. How can the ISSMP ensure that inter-service communication is encrypted and that services are authenticated to one another?

Hard
7

What is the primary objective of a 'Security Gate' in an SDLC?

Easy
8

A company is integrating a Third-Party API into their application. What must the ISSMP ensure is included in the risk assessment process?

Hard
9

During a software audit, it is found that developers have administrative access to the production database to troubleshoot errors. What change should the ISSMP implement?

Medium
10

Which THREE actions are necessary when preparing to decommission a cloud-based Virtual Machine (VM)?

Hard
11

What is the primary role of a Change Advisory Board (CAB)?

Easy
12

When decommissioning an application, which action should the ISSMP prioritize to ensure data privacy requirements (e.g., GDPR) are satisfied?

Medium
13

An ISSMP is reviewing the 'Change Control' process for a critical system. Which of the following is an essential element for every change request?

Medium
14

During a waterfall-to-Agile transition, the development team wants to bypass formal Security Requirements Traceability Matrix (SRTM) documentation in favor of user stories. How should the ISSMP reconcile this?

Hard
15

Which TWO of the following are potential risks if an ISSMP fails to integrate security into the 'Requirements Management' phase?

Hard
16

Which document is primarily responsible for documenting the security controls applicable to a system during the SDLC's requirements phase?

Easy
17

Which TWO of the following are critical components of a secure SDLC (Software Development Life Cycle) implementation?

Medium
18

Which TWO mechanisms are effective for preventing 'insecure direct object references' (IDOR) in a web application during the development phase?

Hard
19

An ISSMP is performing a security assessment on an application using containerized microservices. The team uses Kubernetes. What is the most effective way to ensure security configurations are consistently applied across all clusters?

Hard
20

An organization is adopting Infrastructure-as-Code (IaC) using Terraform. The ISSMP wants to ensure no insecure configurations (e.g., S3 buckets with public read) are deployed. What should be integrated into the CI/CD pipeline?

Hard
21

An organization is deploying a globally distributed application. The ISSMP needs to ensure that code changes are signed to prevent tampering. Which process should be implemented in the build pipeline?

Hard
22

Which TWO techniques are effective for securing the software supply chain?

Hard
23

An ISSMP is overseeing the integration of security into a new DevOps pipeline using Jenkins. Which stage of the SDLC should the ISSMP enforce the execution of SAST tools to ensure security requirements are met early?

Easy
24

During the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?

Medium
25

Which THREE components should be included in an application security requirements document?

Medium
26

Which phase of the SDLC is most appropriate for conducting a formal Threat Modeling exercise?

Easy
27

Which THREE items are typically verified in a Security Gate check before a production deployment?

Medium
28

A project manager wants to bypass a security vulnerability finding because 'the patch will break the application'. What is the correct ISSMP response?

Medium
29

Which TWO items must be documented in a Change Control Log after a successful production change?

Medium
30

Which metric provides the best insight into the effectiveness of the security program within the SDLC?

Medium

Frequently asked questions

What does the Systems Lifecycle Management domain cover on the ISC exam?
Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 30 Systems Lifecycle Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Systems Lifecycle Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Systems Lifecycle Management Practice Questions