Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 6Objective 2

6.2 Understand, Adhere to, and Promote Professional Ethics ISSMP Practice Questions (Page 2)

Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
5concepts
14%of the exam

Questions 6–10

  1. 6expert · hard

    A security director at a large corporation discovers that a senior executive has been using company resources to run a side business that competes with the company. The executive is also a CISSP holder. The director is unsure whether to report this because the executive is powerful and could retaliate. The company has a code of ethics that prohibits conflicts of interest. What is the director's most appropriate course of action?

    Select an answer first
  2. 7expert · hard

    A security manager is responsible for enforcing the organizational code of ethics in a company where a popular and high-performing sales executive has been found to be exaggerating the company's security capabilities in client proposals. The executive's sales numbers are critical to the company's quarterly earnings. The CEO is aware of the exaggeration but has not acted. What is the most appropriate action for the security manager?

    Select an answer first
  3. 8application · medium

    A CISSP-certified manager is asked by their employer to sign a compliance report that the manager knows contains inaccurate statements about the company's security posture. The employer says the report is only for internal use and will never be seen by regulators. What should the manager do?

    Select an answer first
  4. 9application · medium

    A senior security manager discovers that a vendor's product, which the company has already purchased and deployed, contains a critical vulnerability. The vendor has privately disclosed the flaw to the manager and asked for 90 days to develop a patch before public disclosure. The manager's CISO, under pressure from the board, instructs the manager to keep the vulnerability secret indefinitely to avoid reputational damage and potential stock impact. The manager holds the CISSP certification. What is the manager's most appropriate course of action under the ISC2 Code of Ethics?

    Select an answer first
  5. 10foundation · easy

    What is the primary role of an organizational code of ethics?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.