Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Engineering Professional

Domain 4Objective 2

Verify Successful Implementation ISSEP Practice Questions (Page 4)

Part of the Systems Security Implementation, Verification and Validation domain, which accounts for 20% of the ISSEP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 7–12 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
4concepts
20%of the exam

Questions 16–20

  1. 16expert · hard

    A security engineer is developing a security test plan for a system that will process highly sensitive data. The system has a tight deadline, and the test budget is limited. The engineer must decide how to allocate testing effort between automated vulnerability scanning and manual penetration testing. What is the most balanced approach?

    Select an answer first
  2. 17expert · hard

    A system has completed security verification, and the test report shows that all high-risk findings are resolved, but several medium-risk findings remain. The system owner is ready to accept the system, but the security officer is hesitant because the medium risks are not fully mitigated. What should the security engineer do to facilitate acceptance?

    Select an answer first
  3. 18application · medium

    A defense contractor is deploying a new secure messaging system that must pass a security test plan before going live. The project manager wants to minimize schedule impact while ensuring that all security requirements are verified. The security engineer has limited test resources and must prioritize which controls to test first. What should the security engineer do?

    Select an answer first
  4. 19application · medium

    A software development team is using an agile methodology to build a new customer relationship management (CRM) system. The security engineer must integrate security testing into the agile process. What is the most effective approach?

    Select an answer first
  5. 20foundation · easy

    What is the purpose of reassessing existing risks after security verification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSEP” is a trademark of its owner, used for identification only.