Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 1Objective 9

1.9 Manage Security Programs ISSMP Practice Questions (Page 4)

Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
6concepts
21%of the exam

Questions 16–20

  1. 16expert · hard

    A security manager is mediating a conflict between the data privacy officer (DPO) and the data analytics team. The analytics team wants to use a new dataset that contains personal data for a marketing analysis project. The DPO has stated that using the data for this purpose is not compliant with the organization's privacy policy. The analytics team argues that the project is critical for revenue growth. The security manager must resolve this conflict. What is the most appropriate action?

    Select an answer first
  2. 17application · medium

    An organization is implementing a new identity and access management (IAM) system. The security team is leading the project, but the human resources (HR) department is a key stakeholder because they manage the employee onboarding and offboarding processes. The security manager wants to ensure the new IAM system works well with HR's processes. What is the best way to build this cross-functional relationship?

    Select an answer first
  3. 18application · medium

    The sales department wants to use a new cloud-based file-sharing service to collaborate with external partners. The security team has identified that the service does not meet the organization's data encryption standards. The sales director is frustrated and demands the service be approved immediately. What is the best way for the security manager to resolve this conflict?

    Select an answer first
  4. 19foundation · easy

    In a typical organization, which role is primarily responsible for the day-to-day implementation and operation of security controls?

    Select an answer first
  5. 20application · medium

    An organization is updating its procurement process. The security team wants to ensure that all new software purchases are reviewed for security before they are acquired. The procurement team is concerned this will slow down the purchasing process. What is the best way to integrate the security review into the procurement workflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.