
Information Systems Security Management Professional
Domain 2Objective 3
2.3 Define and Manage Comprehensive Vulnerability Management Programs (e.g., Vulnerabilities, Scanning, Penetration Testing, Threat Analysis) ISSMP Practice Questions (Page 5)
Part of the Systems Lifecycle Management domain, which accounts for 15% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
15%of the exam
Questions 21–25
- 21
What is the primary difference between vulnerability scanning and penetration testing?
Select an answer first - 22
A vulnerability scan has identified a critical vulnerability in a legacy application that cannot be patched because the vendor no longer provides updates. The application is essential to business operations. Which remediation approach should the security team take?
Select an answer first - 23
Which factor is most directly used to prioritize assets for vulnerability management?
Select an answer first - 24
A security manager is planning a penetration test for a critical application. The test must not disrupt production services, but the organization wants a realistic assessment of its security posture. Which testing approach best meets these requirements?
Select an answer first - 25
Which of the following best describes the purpose of a risk-based approach to vulnerability prioritization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.