ISC · domain
Systems Lifecycle Management
Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Systems Lifecycle Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Systems Lifecycle Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Systems Lifecycle Management
Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Systems Lifecycle Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Systems Lifecycle Management questions (30)
Click any question to see the full explanation, or start a practice session above.
Which THREE factors should an ISSMP consider when selecting security controls for a new system?
Medium2In the context of the SDLC, what is the primary purpose of a 'Software Bill of Materials' (SBOM)?
Easy3Which document defines the security requirements that must be met for a third-party vendor to integrate with the company's internal systems?
Easy4A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?
Medium5A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?
Medium6An organization uses a microservices architecture. How can the ISSMP ensure that inter-service communication is encrypted and that services are authenticated to one another?
Hard7What is the primary objective of a 'Security Gate' in an SDLC?
Easy8A company is integrating a Third-Party API into their application. What must the ISSMP ensure is included in the risk assessment process?
Hard9During a software audit, it is found that developers have administrative access to the production database to troubleshoot errors. What change should the ISSMP implement?
Medium10Which THREE actions are necessary when preparing to decommission a cloud-based Virtual Machine (VM)?
Hard11What is the primary role of a Change Advisory Board (CAB)?
Easy12When decommissioning an application, which action should the ISSMP prioritize to ensure data privacy requirements (e.g., GDPR) are satisfied?
Medium13An ISSMP is reviewing the 'Change Control' process for a critical system. Which of the following is an essential element for every change request?
Medium14During a waterfall-to-Agile transition, the development team wants to bypass formal Security Requirements Traceability Matrix (SRTM) documentation in favor of user stories. How should the ISSMP reconcile this?
Hard15Which TWO of the following are potential risks if an ISSMP fails to integrate security into the 'Requirements Management' phase?
Hard16Which document is primarily responsible for documenting the security controls applicable to a system during the SDLC's requirements phase?
Easy17Which TWO of the following are critical components of a secure SDLC (Software Development Life Cycle) implementation?
Medium18Which TWO mechanisms are effective for preventing 'insecure direct object references' (IDOR) in a web application during the development phase?
Hard19An ISSMP is performing a security assessment on an application using containerized microservices. The team uses Kubernetes. What is the most effective way to ensure security configurations are consistently applied across all clusters?
Hard20An organization is adopting Infrastructure-as-Code (IaC) using Terraform. The ISSMP wants to ensure no insecure configurations (e.g., S3 buckets with public read) are deployed. What should be integrated into the CI/CD pipeline?
Hard21An organization is deploying a globally distributed application. The ISSMP needs to ensure that code changes are signed to prevent tampering. Which process should be implemented in the build pipeline?
Hard22Which TWO techniques are effective for securing the software supply chain?
Hard23An ISSMP is overseeing the integration of security into a new DevOps pipeline using Jenkins. Which stage of the SDLC should the ISSMP enforce the execution of SAST tools to ensure security requirements are met early?
Easy24During the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?
Medium25Which THREE components should be included in an application security requirements document?
Medium26Which phase of the SDLC is most appropriate for conducting a formal Threat Modeling exercise?
Easy27Which THREE items are typically verified in a Security Gate check before a production deployment?
Medium28A project manager wants to bypass a security vulnerability finding because 'the patch will break the application'. What is the correct ISSMP response?
Medium29Which TWO items must be documented in a Change Control Log after a successful production change?
Medium30Which metric provides the best insight into the effectiveness of the security program within the SDLC?
MediumOther domains
All ISC exam domains
Frequently asked questions
- What does the Systems Lifecycle Management domain cover on the ISC exam?
- Systems Lifecycle Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 30 Systems Lifecycle Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Systems Lifecycle Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.