
Information Systems Security Management Professional
Domain 1Objective 4
1.4 Define and Maintain Security Policy Framework ISSMP Practice Questions (Page 5)
Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
21%of the exam
Questions 21–25
- 21
Why is it important to periodically review and update the security policy framework?
Select an answer first - 22
A data asset is classified as 'Confidential' and is subject to a regulatory requirement for encryption at rest. Which protection requirement is most directly associated with this classification?
Select an answer first - 23
A security manager is developing a new security policy that will require significant changes to employee workflows. The policy is necessary to comply with new regulations, but it is likely to face resistance from employees and some managers. What is the most effective way to ensure successful implementation?
Select an answer first - 24
An organization is creating a new security policy for remote access. Which step is most important to ensure the policy aligns with external requirements?
Select an answer first - 25
A company's security policy framework is due for its annual review. The review team has identified several areas where the policies are no longer aligned with the organization's strategic direction. What should you do to ensure the framework remains relevant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.