Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 6Objective 3

6.3 Validate Compliance in Accordance with Applicable Laws, Regulations, and Industry Standards ISSMP Practice Questions (Page 1)

Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
14%of the exam

Questions 1–5

  1. 1expert · hard

    A compliance officer needs to communicate the organization's compliance status with the Sarbanes-Oxley Act (SOX) to the audit committee. The committee is composed of financial experts who are not familiar with IT controls. The compliance officer has access to data on IT general controls (ITGCs), including the number of controls, the number of exceptions, and the remediation status. Which communication approach would be most effective for this audience?

    Select an answer first
  2. 2foundation · easy

    Which criterion is most important when evaluating a compliance framework for an organization?

    Select an answer first
  3. 3foundation · easy

    Which of the following is an example of a Key Risk Indicator (KRI) for compliance?

    Select an answer first
  4. 4application · medium

    A multinational retail company processes credit card payments in 12 countries and must demonstrate compliance to its acquiring banks. The CISO has been asked to select a compliance framework that provides the most direct path to satisfying the Payment Card Industry Data Security Standard (PCI DSS) while also supporting the company's existing ISO/IEC 27001 certification. Which framework selection approach best meets this need?

    Select an answer first
  5. 5application · medium

    A government contractor must comply with NIST SP 800-171 for controlled unclassified information (CUI). The company already uses COBIT 2019 for IT governance. The CISO wants to avoid duplicating efforts. What is the most effective approach to framework selection and implementation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.