
Information Systems Security Architecture Professional
Domain 1Objective 1
1.1 Identify Legal, Regulatory, Organizational, and Industry Requirements ISSAP Practice Questions (Page 4)
Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
12concepts
21%of the exam
Questions 16–20
- 16
Which design principle is essential for achieving high availability in a resilient solution?
Select an answer first - 17
Which Canadian federal privacy law governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities?
Select an answer first - 18
Which privacy regulation grants California residents the right to request that a business delete their personal information?
Select an answer first - 19
In an outsourcing agreement, what is the primary purpose of a service level agreement (SLA)?
Select an answer first - 20
A US-based investment advisor is subject to the Gramm-Leach-Bliley Act (GLBA). The firm collects nonpublic personal information (NPI) from clients. The security architect must ensure the firm's data handling practices comply with GLBA's Safeguards Rule. Which requirement is a direct obligation under the Safeguards Rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.