
Information Systems Security Management Professional
Domain 6Objective 5
6.5 Document and Manage Compliance Exceptions ISSMP Practice Questions (Page 1)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
14%of the exam
Questions 1–5
- 1
An organization discovers that a legacy system cannot meet a new encryption standard. The security team finds that a network segmentation control already in place limits access to the system. What is this segmentation control an example of in the context of compliance exceptions?
Select an answer first - 2
Which of the following elements is typically included in a formal compliance exception request?
Select an answer first - 3
To whom should a risk waiver request be reported for formal approval?
Select an answer first - 4
What is the primary purpose of documenting controls and workarounds in a formal compliance exception request?
Select an answer first - 5
A hospital's legacy patient-monitoring system cannot be patched to meet the latest security baseline, but it is isolated on a separate VLAN with strict firewall rules and monitored by a 24/7 SOC. The compliance officer wants to document this as a compliance exception. What should the security manager do FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.