
Information Systems Security Management Professional
Domain 6Objective 1
6.1 Identify the Impact of Laws and Regulations That Relate to Information Security ISSMP Practice Questions (Page 1)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
14%of the exam
Questions 1–5
- 1
Which of the following is the primary purpose of security and privacy laws, regulations, and standards?
Select an answer first - 2
A security manager is reviewing the organization's policy on employee-created intellectual property. The organization has an employment agreement that assigns all intellectual property created by employees during their employment to the organization. An employee has developed a new software tool on their own time using their own equipment, but the tool is related to the organization's business. Which of the following is the most important factor in determining whether the organization owns the tool?
Select an answer first - 3
A company discovers that a competitor is using a logo that is confusingly similar to its registered trademark. The competitor's logo appears on its website and marketing materials. Which of the following is the most appropriate legal action to protect the company's trademark?
Select an answer first - 4
A security manager is reviewing the organization's intellectual property protection strategy. The organization has developed a unique algorithm that provides a competitive advantage and is not publicly known. The algorithm is implemented in software and the company has not filed for any patents. Which of the following is the most appropriate protection strategy for the algorithm?
Select an answer first - 5
A multinational company with headquarters in the United States processes customer data for its European Union (EU) subsidiary. The EU subsidiary's data is stored in a cloud provider's data center located in Ireland. The company's security team is asked to ensure compliance with the EU General Data Protection Regulation (GDPR). Which action is most directly required to address GDPR's trans-border data flow requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.