
Information Systems Security Engineering Professional
Domain 2Objective 2
Manage Risk to System ISSEP Practice Questions (Page 3)
Part of the Risk Management domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
20%of the exam
Questions 11–15
- 11
An e-commerce company has a risk management process in place. During a quarterly review, the security team notices that a new regulation has been enacted that imposes stricter data protection requirements. This regulation could affect the company's current risk treatment decisions. What is the most appropriate action?
Select an answer first - 12
When performing inherent risk analysis, which factors are considered?
Select an answer first - 13
During the risk management process, which activity is performed when the organization defines the system's operational boundaries, identifies the assets and processes in scope, and establishes the risk evaluation criteria?
Select an answer first - 14
A financial regulator is evaluating the risk management practices of a bank. The bank has identified a risk of insider trading by employees. The inherent risk analysis shows a high likelihood and high impact. The bank has implemented a monitoring system that detects suspicious trading patterns. However, the monitoring system has a known false positive rate that could lead to alert fatigue. The bank must decide whether to accept, mitigate, or transfer this risk. Which decision is most appropriate?
Select an answer first - 15
A defense contractor is conducting a risk assessment for a new military communication system. The system will be used in a coalition environment with allied forces. The team has identified a threat of electronic warfare (EW) attacks that could disrupt communications. They are now analyzing the inherent risk. Which factor is most critical to consider when analyzing the inherent risk of EW attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.