
Information Systems Security Management Professional
Domain 6Objective 4
6.4 Coordinate with Auditors and Regulators in Support of Internal and External Audit Processes ISSMP Practice Questions (Page 5)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
14%of the exam
Questions 21–25
- 21
An internal audit report identifies a finding that the company's firewall rules are overly permissive, allowing unnecessary inbound traffic. The security team disputes the finding, stating that the rules are required for a legacy application. As the compliance officer, what is your first step in evaluating this finding?
Select an answer first - 22
What is the purpose of determining the root cause of an audit finding?
Select an answer first - 23
During the planning phase of an external audit, which activity is the security manager primarily responsible for coordinating with the audit team?
Select an answer first - 24
An auditor reports a finding that the company's data retention policy is not being followed, citing examples of old data that should have been deleted. The data owner claims the data is still needed for an ongoing legal matter. What should the compliance officer do to validate the finding?
Select an answer first - 25
A company has remediated an audit finding by implementing a new data classification scheme. Before closing the finding, the compliance officer must validate the remediation. What is the most appropriate validation method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.