Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 3Objective 2

Apply System Security Principles ISSEP Practice Questions (Page 5)

Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
10concepts
22%of the exam

Questions 21–25

  1. 21application · medium

    A financial services company is deploying a new payment-processing application. The application runs as a single service that both reads customer account data and initiates fund transfers. The security team is concerned about the risk of a compromised service being able to perform both operations. Which approach best reduces the risk while maintaining operational efficiency?

    Select an answer first
  2. 22foundation · easy

    How does automation improve security operations?

    Select an answer first
  3. 23expert · hard

    A global financial institution operates a real-time trading platform. The platform is deployed across two data centers in different geographic regions. Each data center runs the full application stack, and traffic is load-balanced between them. The platform uses a single-vendor hardware security module (HSM) for cryptographic key operations. A recent firmware vulnerability in that HSM model was disclosed, and the vendor has not yet released a patch. The institution is concerned about a single point of failure and wants to reduce risk. Which action best addresses the concern?

    Select an answer first
  4. 24foundation · easy

    What does the principle of economy of mechanism advocate in security design?

    Select an answer first
  5. 25application · medium

    A software company is adopting a SecDevOps approach to improve the security of its continuous integration/continuous deployment (CI/CD) pipeline. The team wants to automatically block a build if a critical vulnerability is found in a new dependency. Which practice best supports this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.