Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 3Objective 4

Create System Security Design ISSEP Practice Questions (Page 3)

Part of the Security Planning and Engineering domain, which accounts for 22% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
5concepts
22%of the exam

Questions 11–15

  1. 11application · medium

    A defense contractor is designing a new ground control station for an unmanned aerial vehicle. The system must provide secure remote access for operators, but the initial functional decomposition only allocated 'user authentication' to the operator workstation component. During a design review, the security engineer notes that the requirement 'all remote sessions must be encrypted' has not been allocated to any component. Which action best addresses this gap?

    Select an answer first
  2. 12foundation · easy

    In system security design, what is the role of audit mechanisms?

    Select an answer first
  3. 13foundation · easy

    In the systems engineering process, what is the primary purpose of functional analysis and allocation?

    Select an answer first
  4. 14application · medium

    A security engineer is updating the traceability matrix for a system that is being modified to add a new encryption algorithm. The matrix currently links the requirement 'data must be encrypted' to the design element 'crypto module'. The engineer plans to replace the crypto module with a new one that supports the new algorithm. What is the most important action to maintain traceability?

    Select an answer first
  5. 15application · medium

    A security architect is designing a new intrusion detection system (IDS) for a corporate network. The design uses a machine learning algorithm to detect anomalies. The architect wants to validate that the algorithm can accurately detect known attack patterns without excessive false positives. Which validation method is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.