Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 2Objective 1

Apply Security Risk Management Principles ISSEP Practice Questions (Page 1)

Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
2concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    A defense contractor is beginning the concept development phase for a new weapons system. The program manager wants to ensure that security considerations are not an afterthought. What is the most effective way to integrate security risk management at this stage?

    Select an answer first
  2. 2application · medium

    A company is in the initiation phase of a new project to develop a customer-facing web portal. The project sponsor wants to ensure that security is considered from the start. What is the most important activity to perform during this phase?

    Select an answer first
  3. 3application · medium

    A retail company is using a qualitative risk assessment approach. The security team has identified a risk of a point-of-sale (POS) malware infection. The likelihood is assessed as 'high' and the impact as 'moderate'. According to the company's 4x4 risk matrix, this results in a 'high' risk rating. The ERM committee is deciding how to respond. Which response is most appropriate given the risk rating?

    Select an answer first
  4. 4expert · hard

    A multinational corporation is adopting a new ERM framework that uses a 5x5 risk matrix with likelihood and impact scales. The security team is mapping its existing security risk register to the new framework. A risk of a ransomware attack is currently rated as 'high' in the security team's own 4x4 matrix. In the new ERM matrix, the same risk is rated as 'medium' because the impact scale focuses on financial loss and the likelihood is assessed as 'possible'. What is the most appropriate action for the security team?

    Select an answer first
  5. 5expert · hard

    A hospital system is implementing a new electronic health record (EHR) system. The enterprise risk management (ERM) framework prioritizes risks based on patient safety impact. The security team identifies a risk that could allow unauthorized access to patient data, but the direct patient safety impact is low. The ERM committee is inclined to accept this risk. What is the most important consideration the security team should raise?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.