Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 4Objective 2

Verify Successful Implementation ISSEP Practice Questions (Page 3)

Part of the Systems Security Implementation, Verification and Validation domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
4concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A security engineer is updating the risk analysis for a system after verification testing. The test results show that a critical vulnerability was found in a third-party component, but the vendor has not yet released a patch. The system is currently in production and cannot be taken offline. What should the security engineer do?

    Select an answer first
  2. 12application · medium

    During a security verification test of a new web application, the test team discovers that the authentication mechanism fails to lock out accounts after multiple failed attempts, contrary to the security requirements. The test lead needs to document this finding and decide on the next step. What should the test lead do?

    Select an answer first
  3. 13expert · hard

    A security test team is executing a test plan for a new system. Midway through testing, a critical vulnerability is discovered that could allow unauthorized access to sensitive data. The test lead must decide whether to continue testing or halt the test. The system is not yet in production. What should the test lead do?

    Select an answer first
  4. 14expert · hard

    A security verification test for a new system is complete, and the test report shows that one high-risk finding was not fully resolved because the fix introduced a new issue. The system owner is under pressure to go live and asks the security engineer to sign off on the acceptance. What should the security engineer do?

    Select an answer first
  5. 15application · medium

    During a security verification test, a test engineer discovers that a new firewall rule is not blocking traffic as specified in the security requirements. The test engineer needs to collect data to support the finding. What should the test engineer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.