
Information Systems Security Engineering Professional
Domain 1Objective 3
Integrate with System Development Methodology ISSEP Practice Questions (Page 3)
Part of the Systems Security Engineering Foundations domain, which accounts for 24% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
24%of the exam
Questions 11–15
- 11
A systems engineering team is developing a new authentication service for a federal agency. The security requirements include mandatory use of multi-factor authentication (MFA) and a maximum session timeout of 15 minutes. The team needs to demonstrate to an independent assessor that each security requirement is implemented correctly in the final system. Which approach best supports this verification need?
Select an answer first - 12
A development team is using an agile methodology to build a new customer relationship management (CRM) system. The security requirements include encryption of customer data at rest and in transit. The team wants to ensure that these requirements are verified as the system evolves. Which practice is most effective in an agile environment?
Select an answer first - 13
A government agency is developing a new system with highly critical security requirements. The project manager wants to identify and mitigate security risks early in the development process, and is willing to accept multiple iterations of requirements and design. Which SDLC model is most suitable for this environment?
Select an answer first - 14
Which method is commonly used to validate that security requirements are correctly implemented in the final system?
Select an answer first - 15
A defense contractor is developing a new command and control system. The program requires that security requirements be verified at each stage of the SDLC, and that the verification evidence be auditable by an external assessor. The contractor is using ISO/IEC 24641:2023 as the process standard. Which combination of practices best satisfies the program's verification and auditability requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.