Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 3Objective 4

3.4 Manage Risk Controls ISSMP Practice Questions (Page 3)

Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
5concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    A financial services firm has implemented a compensating control for a missing segregation of duties in its payment processing system. The compensating control requires a manager to review and approve all transactions above $10,000. The compliance team wants to monitor the effectiveness of this control. Which metric would most directly indicate whether the compensating control is operating as intended?

    Select an answer first
  2. 12expert · hard

    A company has implemented multiple controls for a single high-risk process: a preventive control (input validation), a detective control (audit logging), and a corrective control (automated rollback). During a coverage analysis, the security team finds that the detective control is not generating logs for certain edge cases. What is the most significant impact of this gap?

    Select an answer first
  3. 13foundation · easy

    A company implements a compensating control to satisfy a security requirement because the primary control is not feasible in its current environment. What is the defining characteristic of a compensating control?

    Select an answer first
  4. 14expert · hard

    A bank has implemented a control to detect fraudulent transactions by analyzing patterns. The control was initially effective, but over the past six months, the number of false positives has increased significantly, causing the fraud team to ignore alerts. The security manager needs to address this issue. Which action would best improve the control's ongoing effectiveness?

    Select an answer first
  5. 15application · medium

    A company's security team has completed a control effectiveness assessment. The results show that a critical control is only 60% effective, meaning it fails to prevent a significant number of incidents. The CISO needs to communicate this to the IT operations team, which is responsible for implementing fixes. Which communication approach would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.