
Information Systems Security Engineering Professional
Domain 3Objective 1
Analyze Organizational and Operational Environment ISSEP Practice Questions (Page 4)
Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
22%of the exam
Questions 16–20
- 16
A city government is planning to deploy a new public Wi-Fi network in its downtown area. The network will be used by citizens and visitors. The city's IT department will manage the network. The city council has expressed concerns about the security of the network and the potential for misuse. The systems security engineer is beginning the security planning process. Which group of stakeholders is most likely to be overlooked but should be included in the requirements elicitation process?
Select an answer first - 17
A university is developing a new research data management system. The system will store sensitive research data, some of which is subject to federal regulations. The university's budget for the project is fixed, and the timeline is driven by the start of the next academic year. The research office requires that the system support multi-factor authentication (MFA) for all users. The IT department notes that implementing MFA will require additional hardware tokens, which are not in the budget. What is the most appropriate way to handle this constraint?
Select an answer first - 18
A hospital is implementing a new electronic health record (EHR) system. The hospital's CIO is the system owner. The clinical staff will be the primary users. The IT security team will manage access controls. The hospital is subject to HIPAA regulations, which require that access to patient data be logged and monitored. During the planning phase, the systems security engineer needs to define roles for the system. Which role is most appropriate for the clinical staff?
Select an answer first - 19
Which validation activity involves examining a security control to ensure it is implemented correctly?
Select an answer first - 20
Which technique is commonly used in requirements elicitation to gather security-related requirements from stakeholders?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.