Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 2Objective 2

Manage Risk to System ISSEP Practice Questions (Page 2)

Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
7concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    Which of the following is typically included in risk posture documentation?

    Select an answer first
  2. 7application · medium

    A defense contractor is establishing a risk management program for a new weapon system. The system will operate in a coalition environment with allied nations, and the contractor must comply with both U.S. export control regulations and allied data-handling rules. During the initial risk context definition, which action is most critical to ensure the risk management process is scoped correctly?

    Select an answer first
  3. 8application · medium

    A hospital is assessing the risk of a ransomware attack on its electronic health records (EHR) system. The security team has identified that the system is vulnerable to phishing attacks and has no endpoint protection. They are now calculating the inherent risk by considering the likelihood of a successful attack and the potential impact on patient care. Which statement best describes what they are doing?

    Select an answer first
  4. 9expert · hard

    A manufacturing company is conducting a risk assessment for its industrial control systems (ICS). The team has identified that a cyber-physical attack could cause physical damage to equipment and endanger workers. They are now analyzing the risk events and impacts. Which approach best captures the full scope of impacts?

    Select an answer first
  5. 10application · medium

    A manufacturing company has completed an inherent risk analysis for its industrial control systems. The risks identified include a potential cyber-physical attack that could cause equipment damage and a data breach that could expose proprietary designs. The company's risk criteria state that any risk with a potential impact above $1 million requires treatment. The cyber-physical attack has a potential impact of $5 million, while the data breach has a potential impact of $500,000. Based on this information, what should the company do next?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.