
Information Systems Security Engineering Professional
Domain 2Objective 3
Manage Risk to Operations ISSEP Practice Questions (Page 3)
Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
8concepts
20%of the exam
Questions 11–15
- 11
Which of the following is an example of an impact that would be considered when determining the impact of a risk?
Select an answer first - 12
A manufacturing company has completed a risk assessment for its new IoT sensor network. The risk team needs to communicate the risk posture to the plant manager, who is not a security expert. Which documentation approach is most effective?
Select an answer first - 13
A software company is performing an inherent risk analysis for its new online code repository service. The team has identified that the service will store proprietary source code and will be accessible over the internet. Which factor is most important to consider when assessing the likelihood of a data breach?
Select an answer first - 14
In risk evaluation, what is the primary outcome of comparing inherent risk levels against risk criteria?
Select an answer first - 15
In the risk management process, which element is part of establishing the risk context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.