
Information Systems Security Engineering Professional
Domain 2Objective 1
Apply Security Risk Management Principles ISSEP Practice Questions (Page 4)
Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
2concepts
20%of the exam
Questions 16–20
- 16
A large financial institution is adopting an enterprise risk management (ERM) framework aligned with ISO 31000. The CISO wants to ensure that security risk decisions are consistently prioritized alongside operational, credit, and market risks across business units. Which approach best achieves this alignment?
Select an answer first - 17
A security manager wants to ensure that security risk management decisions are aligned with the organization's broader business objectives. Which approach best supports this alignment?
Select an answer first - 18
A software company is developing a new cloud-based application. The development team wants to use a third-party library that has a known critical vulnerability, but it significantly speeds up development. The security team has identified the risk. The project manager is under pressure to meet a deadline. What is the most balanced approach to managing this risk?
Select an answer first - 19
A manufacturing company is implementing a new industrial control system (ICS) for its production line. The ERM framework focuses on operational continuity and safety. The security team identifies a risk that a cyberattack could disrupt production. What is the most effective way to communicate this risk to the ERM committee?
Select an answer first - 20
A university is implementing a new student information system. The ERM framework categorizes risks into strategic, operational, financial, and compliance. The security team identifies a risk that a data breach could expose student records, leading to regulatory fines. How should this risk be categorized in the ERM framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.