
Information Systems Security Engineering Professional
Domain 2Objective 3
Manage Risk to Operations ISSEP Practice Questions (Page 2)
Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
8concepts
20%of the exam
Questions 6–10
- 6
A defense contractor is assessing a new system that will process controlled unclassified information (CUI) for a government client. The system will be hosted in a commercial cloud environment. The contractor's risk management team is defining the risk context. Which action is most appropriate when establishing the risk context for this system?
Select an answer first - 7
What is the purpose of performing risk evaluation?
Select an answer first - 8
A retail company has implemented a risk treatment plan for its e-commerce platform. Six months later, the company introduces a new payment processing feature that uses a third-party service. Which action is most appropriate for monitoring risk posture changes?
Select an answer first - 9
A utility company is assessing the risk of a cyberattack on its industrial control system (ICS) that manages the power grid. The risk team is determining the impact of a successful attack. Which impact consideration is most critical for this system?
Select an answer first - 10
What is the primary purpose of documenting the risk posture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.