
Information Systems Security Management Professional
Domain 1Objective 2
1.2 Align Security Program with Organizational Governance ISSMP Practice Questions (Page 2)
Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
8concepts
21%of the exam
Questions 6–10
- 6
A company is implementing a new security awareness training program. The training will include simulated phishing emails sent to employees. Which stakeholders must be consulted before launching the simulation?
Select an answer first - 7
A security architect wants to replace the company's legacy VPN with a zero-trust network access (ZTNA) solution. The CEO is supportive but the IT operations team is concerned about the complexity of managing a new system. Which approach would best address the IT team's concerns and secure their support?
Select an answer first - 8
A CISO has been given authority by the CEO to 'take all necessary actions' to protect the company from cyber threats. The CISO plans to deploy a network monitoring tool that captures employee communications, citing this broad delegation. Legal and HR have not been consulted. What is the most appropriate action for the CISO?
Select an answer first - 9
What is the primary purpose of engaging stakeholders in the security program?
Select an answer first - 10
A security manager wants to implement a new identity and access management (IAM) system. The CFO is concerned about the cost, and the COO is worried about potential disruption to operations. Which approach would most effectively gain their support?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.