
Information Systems Security Architecture Professional
Domain 1Objective 2
1.2 Architecting for Governance, Risk, and Compliance (GRC) ISSAP Practice Questions (Page 5)
Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
21%of the exam
Questions 21–25
- 21
What is the primary purpose of compliance audit reporting?
Select an answer first - 22
A manufacturing company is adopting a new IoT platform. The risk assessment has identified a high likelihood of device compromise. The business is risk-averse and wants to minimize operational disruption. Which risk treatment option is most appropriate?
Select an answer first - 23
What is the primary purpose of designing monitoring mechanisms in a GRC architecture?
Select an answer first - 24
A software company wants to improve its vulnerability management reporting. The goal is to help executives understand risk and prioritize remediation. Which reporting approach is most effective?
Select an answer first - 25
A hospital is implementing a new telehealth platform. The risk assessment shows a high likelihood of patient data breaches due to remote access. The hospital is risk-averse and must comply with HIPAA. The CFO is concerned about the cost of security controls. Which risk treatment strategy best balances these concerns?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.