Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Architecture Professional

Domain 4Objective 4

4.4 Architect Identity Accounting ISSAP Practice Questions (Page 3)

Part of the Identity and Access Management (IAM) Architecture domain, which accounts for 25% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 5–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
25%of the exam

Questions 11–15

  1. 11application · medium

    An organization is designing its IAM accounting architecture and needs to define audit events for compliance with GDPR. The organization processes personal data of EU citizens and must be able to demonstrate that access to this data is logged. Which audit events are essential to meet GDPR requirements?

    Select an answer first
  2. 12foundation · easy

    During the requirements-gathering phase for a new identity and access management (IAM) system, an architect must document accounting, analysis, and forensic requirements. Which input is most directly used to determine these requirements?

    Select an answer first
  3. 13application · medium

    A government agency is subject to FISMA requirements and must ensure that its IAM audit logs are protected against unauthorized modification. The agency uses a SIEM system to collect logs from various sources. Which control is most important to maintain log integrity?

    Select an answer first
  4. 14application · medium

    A payment card processing company is subject to PCI-DSS requirements. The company must demonstrate that access to cardholder data is logged and monitored. The IAM system logs authentication and authorization events, but the logs are stored in a centralized log management system that is accessible to all system administrators. What additional control is required to meet PCI-DSS logging requirements?

    Select an answer first
  5. 15foundation · easy

    Which regulation specifically includes requirements for logging and monitoring of access to cardholder data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.