Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 2Objective 1

Apply Security Risk Management Principles ISSEP Practice Questions (Page 3)

Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
2concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A company is developing a new product and is using a hybrid development approach with both in-house and outsourced teams. The outsourced team is responsible for a critical module. The security team has identified a risk that the outsourced team may not follow secure coding practices. What is the most effective way to manage this risk throughout the development lifecycle?

    Select an answer first
  2. 12application · medium

    A software development team is using a DevOps model with continuous integration and continuous deployment (CI/CD). They want to integrate security risk management without slowing down their release pipeline. Which practice best supports this goal?

    Select an answer first
  3. 13application · medium

    A company is in the operations and maintenance phase of a critical business application. A new critical vulnerability is discovered in the application's web server software. What is the most appropriate immediate action to manage this risk?

    Select an answer first
  4. 14application · medium

    A mid-sized company is implementing a new customer relationship management (CRM) system. The security team has identified a risk that customer data could be exposed due to misconfigured cloud storage. The ERM committee is reviewing the risk. What is the most appropriate risk response if the likelihood is low but the impact is high?

    Select an answer first
  5. 15application · medium

    A company is in the process of decommissioning a legacy application. The data from the application has been migrated to a new system. What is the most important step to ensure the legacy system does not pose a security risk after decommissioning?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.