
Information Systems Security Architecture Professional
Domain 4Objective 4
4.4 Architect Identity Accounting ISSAP Practice Questions (Page 2)
Part of the Identity and Access Management (IAM) Architecture domain, which accounts for 25% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 5–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
25%of the exam
Questions 6–10
- 6
Which of the following is a specific audit event that should be logged for identity and access management?
Select an answer first - 7
A financial institution is required to retain IAM audit logs for seven years to meet regulatory requirements. The logs are stored in a log management system that uses standard storage. The institution is concerned about the cost of storing logs for seven years. Which approach is most cost-effective while maintaining log integrity?
Select an answer first - 8
What is the primary purpose of establishing alerting and notification mechanisms for audit log events?
Select an answer first - 9
What is the primary purpose of log analysis and reporting in identity and access management?
Select an answer first - 10
A multinational corporation must retain IAM audit logs for five years to comply with GDPR data protection requirements. The logs contain personal data of EU citizens. The organization uses a cloud-based IAM service that stores logs in a single region. To ensure data residency and protect log integrity, which strategy should the organization implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.