
Information Systems Security Management Professional
Domain 2Objective 3
2.3 Define and Manage Comprehensive Vulnerability Management Programs (e.g., Vulnerabilities, Scanning, Penetration Testing, Threat Analysis) ISSMP Practice Questions (Page 2)
Part of the Systems Lifecycle Management domain, which accounts for 15% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
15%of the exam
Questions 6–10
- 6
Which of the following is the primary purpose of classifying assets in a vulnerability management program?
Select an answer first - 7
In a vulnerability management program, what is the primary purpose of asset prioritization?
Select an answer first - 8
A financial services firm is deploying a new customer-facing web application. The security team must integrate vulnerability management into the deployment pipeline. The application will be hosted on a mix of cloud and on-premises infrastructure. The team has limited resources and needs to focus scanning efforts on the most critical components. Which approach should the security team take first?
Select an answer first - 9
A security team is implementing a vulnerability management program for a large organization with many assets. The team has limited resources and must decide how to prioritize scanning and remediation. Which approach is most effective?
Select an answer first - 10
A security team is planning a comprehensive security testing program. The team must decide between conducting more frequent vulnerability scans or more frequent penetration tests. The organization has a limited budget. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.