Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 3Objective 1

Analyze Organizational and Operational Environment ISSEP Practice Questions (Page 6)

Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
10concepts
22%of the exam

Questions 26–30

  1. 26expert · hard

    A multinational corporation is deploying a new HR system that will be used in multiple countries. The system must comply with the General Data Protection Regulation (GDPR) for EU employees and with local data residency laws in other countries. The security requirements include that all personal data must be encrypted and that access must be logged. The project has a limited budget for validation. The systems security engineer must develop a validation plan. What is the most important consideration when developing this plan?

    Select an answer first
  2. 27application · medium

    A state government agency is implementing a new case management system. The agency's IT director will serve as the system owner. The agency has a security team that will handle incident response, and a database administrator (DBA) who will manage the underlying database. The project is subject to state records retention laws. During the planning phase, the systems security engineer needs to define who is responsible for ensuring that audit logs are retained for the required period. What is the most appropriate assignment of responsibility?

    Select an answer first
  3. 28foundation · easy

    What is the primary outcome of requirements analysis and prioritization?

    Select an answer first
  4. 29application · medium

    A company has developed a new web application that handles customer payment information. The security requirements include that the application must be resistant to SQL injection attacks and that all payment data must be encrypted in transit. The development team has implemented parameterized queries and TLS. The systems security engineer is selecting validation methods to verify these requirements. Which combination of validation methods is most appropriate?

    Select an answer first
  5. 30foundation · easy

    After gathering security requirements from stakeholders, the team evaluates them for feasibility, conflicts, and priorities, and translates them into clear, testable requirements. Which activity is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.