
Information Systems Security Architecture Professional
Domain 1Objective 2
1.2 Architecting for Governance, Risk, and Compliance (GRC) ISSAP Practice Questions (Page 4)
Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
21%of the exam
Questions 16–20
- 16
Which of the following is an example of a data asset that would be identified during asset identification?
Select an answer first - 17
In stakeholder analysis for GRC decisions, what is the primary reason for identifying stakeholders and their interests?
Select an answer first - 18
Which of the following is an example of a risk assessment artifact?
Select an answer first - 19
What is the primary purpose of segregation of duties (SoD) in an organization?
Select an answer first - 20
A financial institution is implementing a new payment processing system. The system must enforce segregation of duties to prevent fraud. Which of the following controls are essential? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.