
Information Systems Security Architecture Professional
Domain 1Objective 1
1.1 Identify Legal, Regulatory, Organizational, and Industry Requirements ISSAP Practice Questions (Page 5)
Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
12concepts
21%of the exam
Questions 21–25
- 21
A US-based company that is not a financial institution or healthcare provider collects personal data from its customers. The company wants to ensure it is compliant with the California Consumer Privacy Act (CCPA). Which obligation is a direct requirement under CCPA?
Select an answer first - 22
Which data handling requirement is typically applied to data classified as 'confidential'?
Select an answer first - 23
What is the purpose of a data processing agreement (DPA) in a third-party contract?
Select an answer first - 24
What is the purpose of RAID (Redundant Array of Independent Disks) in a server?
Select an answer first - 25
Which regulatory framework is primarily focused on protecting the privacy and security of personal data of individuals in the European Union?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.