Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 5Objective 1

Develop Secure Operations Plan ISSEP Practice Questions (Page 2)

Part of the Secure Operations, Change Management and Disposal domain, which accounts for 14% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
3concepts
14%of the exam

Questions 6–10

  1. 6application · medium

    A government agency is hiring contractors to support its security operations center. The agency requires that all SOC personnel be able to handle sensitive information and have verifiable expertise in incident detection. Which two requirements should the agency specify in the contract?

    Select an answer first
  2. 7application · medium

    A secure operations plan is being developed for a financial institution. The plan must define the roles responsible for reviewing audit logs, managing user access, and responding to security incidents. Which set of roles should be assigned these responsibilities?

    Select an answer first
  3. 8application · medium

    A defense contractor is developing a secure operations plan for a new facility that will process controlled unclassified information. The plan must clearly define who is responsible for monitoring security alerts, conducting initial triage, and escalating incidents to the incident response team. Which role should be assigned these responsibilities in the plan?

    Select an answer first
  4. 9foundation · easy

    According to typical security event reporting requirements, which of the following events must be reported to the appropriate security incident response team?

    Select an answer first
  5. 10application · medium

    A security analyst notices repeated failed login attempts against a critical server from an internal IP address. The attempts have not yet succeeded. According to the organization's security event reporting requirements, which action should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.