Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 1Objective 2

Execute Systems Security Engineering Processes (e.g., Hardware, Software, Data) ISSEP Practice Questions (Page 4)

Part of the Systems Security Engineering Foundations domain, which accounts for 24% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 3–5 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts
24%of the exam

Questions 16–20

  1. 16application · medium

    A systems security engineer is working on a project that processes credit card data. The project must comply with PCI DSS. During a design review, the engineer notices that the proposed architecture stores cardholder data in a way that may not meet PCI DSS requirements. Who is the most appropriate authority to consult for guidance on PCI DSS compliance?

    Select an answer first
  2. 17application · medium

    A defense contractor is developing a new avionics subsystem for a U.S. government program. The program office requires the system to comply with NIST SP 800-171 for controlled unclassified information (CUI) and the contractor's internal security policy. During a design review, the systems security engineer identifies that the proposed data-at-rest encryption algorithm does not meet the NIST-approved list. Which action best aligns with the systems security engineering process?

    Select an answer first
  3. 18application · medium

    A multinational corporation is deploying a new HR system that will process personal data of employees in the European Union and the United States. The systems security engineer must ensure the system complies with GDPR and relevant U.S. state laws. During the design phase, the engineer is deciding where to store the data. Which approach best supports compliance with GDPR's data transfer requirements?

    Select an answer first
  4. 19foundation · easy

    What is a key security consideration when using a proprietary design approach in system engineering?

    Select an answer first
  5. 20expert · hard

    A systems security engineer is designing a new payment processing system. The design uses a modular architecture with separate modules for cardholder data processing, tokenization, and transaction logging. The engineer is considering the security implications of this modularity. Which trade-off is most important to address?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.