
Information Systems Security Management Professional
Domain 6Objective 1
6.1 Identify the Impact of Laws and Regulations That Relate to Information Security ISSMP Practice Questions (Page 3)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
14%of the exam
Questions 11–15
- 11
A multinational organization stores customer personal data in a data center located in Country A but processes that data in Country B. Which of the following is the primary legal concern regarding trans-border data flow?
Select an answer first - 12
A global company with offices in the EU, the U.S., and Asia collects personal data from users in all regions. The company's data is stored in a centralized data center in the U.S. The company is subject to GDPR for its EU users. Which of the following is a key consideration for the company's data flow architecture?
Select an answer first - 13
A global organization is subject to both the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The organization is updating its privacy program to comply with both laws. Which of the following is the most significant challenge in reconciling GDPR and CCPA requirements?
Select an answer first - 14
A multinational corporation with headquarters in the EU and a subsidiary in a country that is not recognized by the EU as having adequate data protection is planning to transfer employee personal data to that subsidiary for HR management. The company is considering using standard contractual clauses (SCCs) as the transfer mechanism. Which of the following is the most critical consideration when relying on SCCs?
Select an answer first - 15
A U.S. organization that provides health insurance is subject to the Health Insurance Portability and Accountability Act (HIPAA). The organization is implementing a new patient portal that will allow patients to access their health records online. Which of the following is a primary compliance requirement under HIPAA for the patient portal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.