
Information Systems Security Management Professional
Domain 6Objective 5
6.5 Document and Manage Compliance Exceptions ISSMP Practice Questions (Page 3)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
14%of the exam
Questions 11–15
- 11
Who is typically the designated decision-maker authorized to approve a risk waiver?
Select an answer first - 12
A healthcare provider uses a legacy imaging system that does not comply with the latest security standard. The security team has implemented compensating controls and documented them in an exception request. The request has been submitted to the CISO. What is the final step to complete the exception management process?
Select an answer first - 13
A hospital uses a legacy patient-monitoring system that cannot be patched to meet the security baseline. The system is isolated on a separate VLAN with strict firewall rules and monitored by a 24/7 SOC. The compliance officer wants to document this as an exception. However, the hospital's policy requires that exceptions be approved by the CISO within 30 days. The security manager has identified the controls but has not yet documented them. What should the security manager do FIRST?
Select an answer first - 14
A retail company needs to maintain a legacy point-of-sale (POS) system that does not meet the current PCI DSS requirement for encryption. The security team has implemented network segmentation and monitoring as compensating controls. The exception request has been submitted. What is the final step to formally manage this exception?
Select an answer first - 15
A financial firm uses a legacy application that does not support multi-factor authentication (MFA). To mitigate the risk, the security team has implemented network-level access controls and enhanced logging. The compliance officer asks for a formal exception request. What must be included in the exception request?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.