Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Architecture Professional

Domain 1Objective 1

1.1 Identify Legal, Regulatory, Organizational, and Industry Requirements ISSAP Practice Questions (Page 7)

Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
12concepts
21%of the exam

Questions 31–35

  1. 31expert · hard

    A defense contractor uses a complex supply chain for its products. A recent audit revealed that a sub-tier supplier's components were counterfeit, potentially compromising the integrity of the final product. The contractor wants to implement a supply chain risk management (SCRM) program. Which action is MOST aligned with NIST SP 800-161 guidance?

    Select an answer first
  2. 32application · medium

    A government contractor is required to implement a risk management framework that is mandatory for US federal agencies. The contractor must select a standard that provides a structured process for categorizing information systems, selecting controls, and authorizing systems. Which standard should the architect reference?

    Select an answer first
  3. 33expert · hard

    A bank outsources its customer identity verification to a third-party vendor. The vendor's API is integrated into the bank's mobile app. A recent security assessment found that the vendor's API has a critical vulnerability that could expose customer PII. The bank's contract with the vendor has no explicit security requirements or right to audit. What is the bank's BEST course of action?

    Select an answer first
  4. 34foundation · easy

    Which clause in a partnership agreement specifies how sensitive data must be protected when shared between the parties?

    Select an answer first
  5. 35foundation · easy

    Which U.S. regulation requires publicly traded companies to implement internal controls over financial reporting, including IT general controls, to ensure the accuracy of financial statements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.