Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 1Objective 5

Participate in the Technology Procurement Management ISSEP Practice Questions (Page 3)

Part of the Systems Security Engineering Foundations domain, which accounts for 24% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 3–5 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
24%of the exam

Questions 11–15

  1. 11application · medium

    A hospital is procuring a new patient monitoring system. The security team has defined requirements for encryption of patient data in transit and at rest, and for audit logging. The vendor proposes a solution that uses a proprietary encryption algorithm. What should the security team do?

    Select an answer first
  2. 12application · medium

    A logistics company is procuring GPS tracking devices for its fleet. The devices rely on a third-party cloud service for data processing. The security team is concerned about the third-party service's data retention practices. What should the security team do during the procurement process?

    Select an answer first
  3. 13foundation · easy

    Which of the following is an example of a supply chain risk that should be assessed during technology procurement?

    Select an answer first
  4. 14application · medium

    A government agency is selecting a new endpoint detection and response (EDR) tool. The security team has defined mandatory requirements: support for Windows and Linux, integration with the existing SIEM, and on-premises deployment. Three vendors meet these requirements. What should the agency do next in the structured selection process?

    Select an answer first
  5. 15application · medium

    A defense contractor is procuring a new cloud-based collaboration suite. The security team has documented requirements for data-at-rest encryption, multi-factor authentication, and audit logging. During the selection process, two vendors meet these baseline requirements. Vendor A offers a lower price but stores data in a country with different data protection laws. Vendor B is more expensive but offers a dedicated region in the contractor's home country. Which additional security requirement should the contractor prioritize in the selection decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.