
Information Systems Security Engineering Professional
Domain 3Objective 1
Analyze Organizational and Operational Environment ISSEP Practice Questions (Page 2)
Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
22%of the exam
Questions 6–10
- 6
A government agency is developing a new system for processing citizen benefits. The system must comply with federal information security standards. The agency has developed a set of security requirements, including that all access to the system must be logged and that the system must be able to detect and respond to unauthorized access. The project is nearing the end of the development phase. The systems security engineer is tasked with developing a validation plan. What is the primary purpose of this validation plan?
Select an answer first - 7
A defense contractor is developing a new secure messaging system for a government client. The system must handle classified information, and the client has mandated that all data be stored on-premises. The contractor has identified the program manager, the security officer, and the end users as stakeholders. However, during a design review, the security officer raises a concern that the system must also comply with export control regulations, which were not previously considered. What is the most appropriate action for the systems security engineer to take?
Select an answer first - 8
During the initial phase of a security engineering project, the team is compiling a list of parties who will be affected by or have an interest in the system's security posture. Which activity is being performed?
Select an answer first - 9
A software company is developing a new cloud-based collaboration tool. The company's threat model assumes that the primary threat is external attackers attempting to gain unauthorized access. The system will be used by employees and external contractors. The security team has implemented strong authentication and encryption. However, during a design review, a security engineer points out that the threat model does not account for insider threats, such as a contractor exfiltrating data. The project manager is concerned that expanding the threat model will delay the project. What is the most appropriate action?
Select an answer first - 10
Which of the following is an example of a constraint that could impact security architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.