
Information Systems Security Engineering Professional
Domain 2Objective 2
Manage Risk to System ISSEP Practice Questions (Page 1)
Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
20%of the exam
Questions 1–5
- 1
What is the primary purpose of identifying risk events and their impacts?
Select an answer first - 2
Which of the following is an example of a vulnerability that would be identified during the 'identify threats and vulnerabilities' step?
Select an answer first - 3
A cloud service provider is monitoring its risk posture for a multi-tenant infrastructure. The provider has identified a new vulnerability in the hypervisor that could allow cross-tenant data access. The vulnerability is not yet exploited, but the provider must decide how to respond. The provider has a risk appetite that accepts low-likelihood risks but requires immediate action for high-impact risks. What should the provider do?
Select an answer first - 4
What is the purpose of monitoring and evaluating risk posture changes?
Select an answer first - 5
A government agency has implemented a risk treatment plan for its citizen services portal. Six months later, the security team discovers that a new vulnerability has been disclosed that affects the portal's underlying framework. The vulnerability is not yet exploited, but it increases the likelihood of a data breach. What is the most appropriate action for the team to take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.