Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 1Objective 2

Execute Systems Security Engineering Processes (e.g., Hardware, Software, Data) ISSEP Practice Questions (Page 1)

Part of the Systems Security Engineering Foundations domain, which accounts for 24% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 3–5 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts
24%of the exam

Questions 1–5

  1. 1application · medium

    A software company is developing a new encryption library that will be used by multiple government agencies. The lead engineer proposes making the source code publicly available for review. The systems security engineer supports this approach. Which security benefit is most directly achieved by this open design decision?

    Select an answer first
  2. 2application · medium

    A healthcare organization is developing a new patient portal that will handle protected health information (PHI). The system must comply with HIPAA. During the design phase, the systems security engineer is reviewing the authentication mechanism. The proposed design uses only a username and password. Which action should the engineer take to align with HIPAA's security requirements?

    Select an answer first
  3. 3expert · hard

    A systems security engineer is working on a project for a defense agency. The project involves a system that will be used by multiple departments, each with its own security authority. During a design review, the engineer identifies a security requirement that is mandated by one department but conflicts with the operational needs of another department. What is the most appropriate course of action?

    Select an answer first
  4. 4foundation · easy

    How do laws, regulations, and standards typically influence system security governance?

    Select an answer first
  5. 5application · medium

    A systems security engineer is working on a project for a federal agency. The project must comply with FISMA, and the agency's CISO has delegated authority to the program manager to accept residual risk. During a design review, the engineer identifies a moderate-risk vulnerability in the proposed architecture. The program manager wants to accept the risk to stay on schedule. What should the engineer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.