Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 1Objective 3

Integrate with System Development Methodology ISSEP Practice Questions (Page 1)

Part of the Systems Security Engineering Foundations domain, which accounts for 24% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts
24%of the exam

Questions 1–5

  1. 1foundation · easy

    Which assurance method provides confidence in the security properties of a software system by analyzing its source code?

    Select an answer first
  2. 2foundation · easy

    In MBSE, what is the role of simulation in supporting security engineering?

    Select an answer first
  3. 3expert · hard

    A large enterprise is transitioning from a waterfall SDLC to an agile approach. The security team is concerned that agile's iterative nature may weaken the traceability of security requirements, which is required by ISO/IEC 24641:2023. The team wants to maintain rigorous traceability while adopting agile. Which strategy best addresses this concern?

    Select an answer first
  4. 4application · medium

    A defense contractor is developing a new embedded system for a military platform. The program office mandates that security requirements be fully defined and frozen before any design work begins, and that each phase must be completed and formally reviewed before the next phase starts. The contractor must select a development approach that aligns with this mandate while ensuring security is integrated from the start. Which approach should the contractor use?

    Select an answer first
  5. 5expert · hard

    A software company is developing a new cloud-based application. The development team wants to release features quickly, but the security team requires that all security requirements be verified before each release. The company also has a regulatory requirement to produce evidence of security verification for audits. Which approach best balances the need for speed and the need for verifiable security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.