Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Architecture Professional

Domain 1Objective 1

1.1 Identify Legal, Regulatory, Organizational, and Industry Requirements ISSAP Practice Questions (Page 8)

Part of the Governance, Risk, and Compliance (GRC) domain, which accounts for 21% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
12concepts
21%of the exam

Questions 36–40

  1. 36application · medium

    A multinational healthcare organization headquartered in the EU stores patient records in a US-based cloud provider. The organization must comply with GDPR for EU residents and HIPAA for its US operations. The security architect is designing a data classification and handling scheme. Which combination of actions best addresses the regulatory overlap?

    Select an answer first
  2. 37expert · hard

    A manufacturing company uses a third-party supplier for critical components. The supplier's software update mechanism was compromised, leading to a malware infection in the company's production network. The company is reviewing its supply chain security. Which improvement is MOST directly aligned with a recognized standard to prevent a recurrence?

    Select an answer first
  3. 38application · medium

    A multinational corporation wants to implement a privacy information management system (PIMS) to demonstrate compliance with GDPR and other privacy regulations. The architect is looking for a certifiable standard that provides requirements for establishing, implementing, maintaining, and improving a PIMS. Which standard should be used?

    Select an answer first
  4. 39foundation · easy

    Which standard provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS)?

    Select an answer first
  5. 40foundation · easy

    Which framework from NIST is designed to help organizations manage privacy risk and improve privacy outcomes?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ISSAP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.