
Information Systems Security Management Professional
Domain 6Objective 3
6.3 Validate Compliance in Accordance with Applicable Laws, Regulations, and Industry Standards ISSMP Practice Questions (Page 3)
Part of the Law, Ethics and Security Compliance Management domain, which accounts for 14% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
14%of the exam
Questions 11–15
- 11
A compliance officer needs to brief the CEO on the organization's compliance status with the Sarbanes-Oxley Act (SOX). The CEO is not familiar with technical controls and prefers a high-level summary. Which communication approach is most effective for this audience?
Select an answer first - 12
What is the primary difference between a Key Performance Indicator (KPI) and a Key Risk Indicator (KRI) in compliance?
Select an answer first - 13
What is the first step in the compliance framework selection process?
Select an answer first - 14
Which activity is part of compliance framework implementation planning?
Select an answer first - 15
A compliance manager at a manufacturing company is responsible for monitoring adherence to the ISO/IEC 27001 framework. The company has a mature set of controls, but the compliance team is struggling to identify emerging risks before they become audit findings. Which monitoring approach would best address this challenge?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.