Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 3Objective 1

Analyze Organizational and Operational Environment ISSEP Practice Questions (Page 7)

Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
10concepts
22%of the exam

Questions 31–35

  1. 31foundation · easy

    Which of the following is an example of role definition in security planning?

    Select an answer first
  2. 32expert · hard

    A defense contractor is developing a new system for a military client. The client has specified that the system must be able to operate in a disconnected environment for extended periods. The contractor's security team has proposed implementing a public key infrastructure (PKI) for authentication. However, the PKI requires access to a certificate authority (CA) to validate certificates, which may not be available in a disconnected environment. The project manager is concerned about the feasibility of the PKI approach. What is the most appropriate way to address this conflict?

    Select an answer first
  3. 33foundation · easy

    Which of the following best describes the purpose of stakeholder identification in security engineering?

    Select an answer first
  4. 34application · medium

    A software startup is developing a new mobile payment application. The company's threat model assumes that the primary threat is malware on users' devices. The security team has implemented app sandboxing and code signing. However, the team has not documented the assumption that users will keep their devices updated with the latest security patches. During a security review, a team member points out that this assumption may not hold for all users. What is the most appropriate action?

    Select an answer first
  5. 35application · medium

    A manufacturing company is deploying a new industrial control system (ICS). The plant manager is the system owner. The IT security team is responsible for network security, and the OT (operational technology) team is responsible for the ICS itself. The company has a policy that all security incidents must be reported to the CISO within one hour. During a planning meeting, the systems security engineer must ensure that incident response responsibilities are clearly assigned. What is the most effective way to assign these responsibilities?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.