Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 2Objective 3

2.3 Define and Manage Comprehensive Vulnerability Management Programs (e.g., Vulnerabilities, Scanning, Penetration Testing, Threat Analysis) ISSMP Practice Questions (Page 5)

Part of the Systems Lifecycle Management domain, which accounts for 15% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts
15%of the exam

Questions 21–25

  1. 21foundation · easy

    What is the primary difference between vulnerability scanning and penetration testing?

    Select an answer first
  2. 22application · medium

    A vulnerability scan has identified a critical vulnerability in a legacy application that cannot be patched because the vendor no longer provides updates. The application is essential to business operations. Which remediation approach should the security team take?

    Select an answer first
  3. 23foundation · easy

    Which factor is most directly used to prioritize assets for vulnerability management?

    Select an answer first
  4. 24expert · hard

    A security manager is planning a penetration test for a critical application. The test must not disrupt production services, but the organization wants a realistic assessment of its security posture. Which testing approach best meets these requirements?

    Select an answer first
  5. 25foundation · easy

    Which of the following best describes the purpose of a risk-based approach to vulnerability prioritization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.