
Information Systems Security Architecture Professional
Domain 1Objective 2
1.2 Architecting for Governance, Risk, and Compliance (GRC) ISSAP Practice Questions (Page 2)
Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
21%of the exam
Questions 6–10
- 6
A financial services firm is implementing a new trade processing system. The system must prevent an individual from both initiating and approving a trade. The architecture team is designing the access control model. Which control should be implemented?
Select an answer first - 7
Which of the following is a key element of an effective vulnerability management report?
Select an answer first - 8
A defense contractor is designing a system to control nuclear launch codes. The system must have the highest level of assurance and be resistant to tampering. Which design principle is most critical?
Select an answer first - 9
Which risk treatment option involves purchasing an insurance policy to cover potential losses?
Select an answer first - 10
A retail company is launching an e-commerce platform. The business objective is to maximize customer trust and minimize fraud. The security architect is aligning security controls with business goals. Which approach best supports this objective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.